Agentic phishing is social engineering executed by an AI system that can research targets, generate messages, handle replies, and escalate the conversation. The risk is not just better text, but autonomous campaign execution across multiple channels and decision points.
Expanded Definition
Agentic phishing is a form of social engineering in which an AI system does more than draft convincing text. It can research targets, adapt messages to context, manage responses, and decide when to continue, pause, or escalate the interaction. That makes it materially different from conventional phishing kits or one-shot AI spam, because the campaign can operate across multiple touchpoints with limited human steering.
Definitions vary across vendors on where phishing ends and autonomous fraud begins, but the operational boundary is clear: if the system is choosing next actions based on replies, signals, or live target behaviour, it is functioning as an agent. In NHI security, that matters because the attacker may be using stolen credentials, API keys, or connected tools to run the campaign at scale. For a broader view of this attack surface, see the OWASP Agentic AI Top 10. The most common misapplication is treating agentic phishing as “better phishing text,” which occurs when defenders ignore autonomous reply handling and multi-channel escalation.
Examples and Use Cases
Implementing detection and response rigorously often introduces more review overhead, requiring organisations to balance faster engagement with tighter verification of sender intent, channel provenance, and tool access.
- An attacker uses an agent to profile employees from public sources, then sends tailored email lures that shift tone after each reply.
- A malicious AI assistant monitors responses, answers basic trust-building questions, and hands off to a human only when the target is ready to click or share credentials.
- A compromised NHI behind a sales or support workflow is repurposed to send believable messages through approved business channels, making the fraud harder to spot.
- Multi-step campaigns combine email, chat, and calendar invitations so the agent can keep pressure on the target across different environments.
NHIMG research on CoPhish OAuth Token Theft via Copilot Studio shows how agent-style workflows can be abused to support credential theft, while the NIST AI Risk Management Framework helps teams think about managing those risks as part of governance rather than just email filtering.
Why It Matters in NHI Security
Agentic phishing matters because the threat is no longer limited to message quality. It creates a living attack workflow that can exploit compromised NHIs, abuse delegated access, and keep adapting until the target yields. That raises the stakes for secrets management, tool authorization, monitoring, and least privilege, especially where agentic systems can reach inboxes, chat platforms, ticketing systems, or identity workflows. NHI Management Group reporting on AI agents found that 80% of organisations say their AI agents have already performed actions beyond intended scope, and 52% can track and audit the data those agents access, leaving a large compliance and investigation blind spot.
Practitioners should treat agentic phishing as both a social engineering problem and an access-control problem. Guidance from the MITRE ATLAS adversarial AI threat matrix and CSA MAESTRO agentic AI threat modeling framework is useful when modelling how autonomous systems are trained, prompted, or hijacked into abuse. Organisationally, the key failure is assuming human phishing playbooks are sufficient when the adversary can iterate in real time and pivot between channels. Organisations typically encounter the damage only after a reply thread becomes a compromise, at which point agentic phishing is operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | NHI-02 | Covers agent-driven abuse patterns and phishing-like autonomous workflows. |
| NIST AI RMF | Addresses AI governance, harm identification, and risk treatment for autonomous systems. | |
| NIST Zero Trust (SP 800-207) | PR.AC | Least privilege and continuous verification limit an agent's ability to pivot after compromise. |
| NIST CSF 2.0 | DE.CM | Detection and monitoring are needed for adaptive social engineering and reply-loop abuse. |
| CSA MAESTRO | Provides threat modeling guidance for autonomous agents and their tool-use boundaries. |
Monitor agent communications for anomalies and investigate suspicious escalation patterns.
Related resources from NHI Mgmt Group
- What breaks when security teams rely on traditional tools to handle AI-driven phishing, misinformation, and agentic attacker workflows?
- What is phishing-resistant authentication and how does it relate to NHI security?
- What is Agentic AI and how does it differ from traditional generative AI?
- What NHI types do Agentic AI systems typically use?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org