TL;DR: AI-generated phishing can rewrite sender infrastructure, phrasing, and payloads for every target, making signature-based rules increasingly fragile, according to Abnormal AI. The practical shift is from cataloguing known-bad indicators to detecting deviations from identity-specific behavioural baselines that attackers have to imitate in real time.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “There's No Signature for an Attack That Never Repeats”.
Key questions
Q: Why do signature-based phishing rules keep missing AI-generated attacks?
A: Because the attacker can regenerate sender infrastructure, wording and payloads for each target, so there is no stable artifact to match.
A: Security teams should place detections higher on the Pyramid of Pain, where they target generic attacker behavior instead of easy to change artifacts like URLs, IPs, or page titles.
Q: What are the signs that phishing detection is relying too much on signatures?
A: Common signs include frequent misses on new variants, heavy dependence on known malicious domains or hashes, and weak detection when wording changes but intent stays the same.
Practitioner guidance
- Prioritise behavioural baselines over static signatures Tune phishing detection around normal writing patterns, contact relationships and access timing so each identity has a behavioural reference point.
- Fuse weak signals before escalation Score combinations of sender novelty, tone drift and relationship anomalies together, because any single indicator may be too ambiguous to act on.
- Review identity-linked communication patterns Map which users, service desks and systems are commonly impersonated, then watch for requests that break established communication paths.
Bottom line: AI-generated phishing weakens the value of known-bad signatures because every campaign can be rewritten before defenders catalogue it.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Signature-based phishing detection is now structurally incomplete. The hidden assumption behind signatures is that malicious infrastructure, payloads or phrasing will recur in recognisable form. AI-generated phishing breaks that premise by regenerating each instance to avoid reuse. The implication is that defenders cannot rely on stable artifacts as the centre of gravity for detection any longer.
A question worth separating out:
Q: What is the difference between phishing detection and behavioural email security?
A: Phishing detection usually looks for malicious content or known indicators, while behavioural email security evaluates how senders, messages, and accounts behave over time. That shift matters because AI-generated attacks can appear clean at the content layer while still looking suspicious in context. Behavioural approaches better fit identity-led abuse patterns.
👉 Read our full editorial: Signature-based detection fails when AI-generated phishing mutates