Join our Newsletter — 33% off our NHI Course

AI-generated phishing and BEC in public agencies: are controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI-generated phishing, business email compromise, and other social engineering tactics are increasing in scale and realism across state and local agencies, according to Abnormal AI. Email remains the primary entry point, and behavioural detection is becoming more important because static defences cannot keep pace with rapidly adapting attack content.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The AI Threat: Protecting State and Local Agencies from AI-Generated Email Attacks”.

Key questions

Q: How should public agencies respond to AI-generated phishing and BEC in email?

A: They should assume that message quality is no longer a reliable indicator of legitimacy and shift to controls that verify sender behaviour, conversation context, and the business process behind the request.

Q: Why do generative AI phishing campaigns bypass traditional email controls?

A: Because traditional controls often depend on patterns that attackers can now imitate or vary cheaply at scale.

Practitioner guidance

  • Harden high-risk email workflows Require stronger verification for payment changes, credential resets, vendor banking updates, and other requests that attackers commonly exploit in public-sector inboxes.
  • Deploy behavioural email detection Look for sender, thread, and interaction anomalies that indicate impersonation even when the email text appears credible and polished.
  • Separate communication from approval Move sensitive authorisations out of reply-based email threads and into a separately governed approval path where possible.

Bottom line: Generative AI is making email phishing and BEC more convincing and more scalable, which weakens controls that rely on obvious textual flaws.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21501
 

Email identity is now being attacked as a behaviour problem, not a content problem. Generative AI has made wording quality cheap, which means the old assumption that bad grammar and obvious tells expose malicious email is eroding. The practical consequence is that email security has to inspect interaction patterns, sender behaviour, and conversation drift, because the message itself is no longer a dependable trust signal.

A question worth separating out:

Q: What should teams do when email is used for approvals and handoffs?

A: They should treat the inbox as a risky trust boundary and move high-impact approvals into a separate verification flow whenever possible. Email can still notify and coordinate, but it should not be the only place where a sensitive request is both delivered and authorised.

👉 Read our full editorial: Generative AI is reshaping email attacks against public agencies


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.