LIVE · cybersecurity feed
Live wire
phishing

How MSPs can catch phishing attacks email filters miss

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]

zeroday.news ·

AI-powered phishing campaigns are increasingly sophisticated, making them harder for traditional email filters to detect and significantly increasing the risk of successful breaches. Attackers are leveraging artificial intelligence to automate and enhance every stage of a phishing operation, from reconnaissance to content generation and delivery.

The process typically begins with AI-driven reconnaissance, where attackers scan public sources like LinkedIn and company websites to build detailed profiles of specific employees. This information allows them to understand an individual's professional relationships, projects, and communication style. Subsequently, AI generates highly personalized and contextually relevant phishing emails that mimic legitimate business communications, often appearing to originate from trusted colleagues, customers, or vendors. These AI-crafted messages are largely free of the spelling errors or awkward phrasing that once served as common indicators of phishing attempts.

To bypass traditional email gateways, AI also facilitates polymorphic phishing, where each email is unique. This involves continuously altering subject lines, sender details, formatting, and content. Attackers further evade detection by utilizing trusted cloud services, QR codes, and redirect chains, which are designed to circumvent signature-based filters and known indicators of compromise. The result is that more convincing phishing emails are reaching inboxes, increasing the likelihood of user interaction.

If a user clicks a malicious link or enters credentials, the attack escalates rapidly. Attackers can steal session tokens, create mailbox rules to conceal their activities, and begin moving laterally within an environment within minutes. Phishing is a leading cause of data breaches, accounting for 16% of incidents and costing organizations an average of $4.8 million per breach, according to IBM's 2024 Cost of a Data Breach Report.

Given the evolving nature of these threats, modern defenses must extend beyond mere email filtering to encompass comprehensive behavioral monitoring. Key indicators of compromise that often follow a successful phishing attempt include the creation of new forwarding or mailbox rules, especially after a login from an unfamiliar location; "impossible travel" scenarios where an account logs in from geographically distant locations within a short timeframe; and repeated, uninitiated multifactor authentication prompts, indicative of MFA fatigue or push bombing attacks.

Effective defense strategies involve correlating activity across identity, email, and endpoint systems. For instance, a user logging in from a trusted device but immediately launching unusual PowerShell scripts, or attempting to access systems or data they've never used before, could signal a compromise. Similarly, a sudden surge in outbound emails from an account that typically sends few internal messages warrants investigation. Automated threat correlation helps connect these disparate signals, enabling faster identification of active phishing attacks and reducing alert fatigue.

Rapid detection and response are crucial for limiting damage. Once credentials are compromised, every minute counts. Security measures should include automatically flagging and investigating suspicious account activity, isolating compromised endpoints to prevent malware spread, and disabling compromised accounts or terminating active sessions to prevent further data access. Faster response times reduce attacker dwell time, improve incident response efficiency, and help contain phishing attacks before they escalate into costly breaches.

Organizations should also modernize security awareness training to reflect current AI-generated phishing tactics, moving beyond outdated examples. Implementing verification protocols for high-risk requests, such as wire transfers or credential resets, through a separate communication channel like a phone call, can effectively thwart business email compromise attempts. Continuous monitoring of account activity post-delivery, including suspicious mailbox rules, logins from unfamiliar locations, impossible travel, and repeated MFA prompts, provides early indications of compromise. Finally, measuring response time—how long it takes to detect and contain a suspected compromise—is as critical as measuring ticket resolution time, as a faster response window directly limits the potential damage.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

patch

Nearly half of enterprises have no one leading PQC migration

Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon