Hacking News All articles
Opinion

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Hacking News
Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Photo: User:Vichoko, CC BY-SA 4.0, via Wikimedia Commons

Let's be honest — for a long time, phishing was kind of easy to spot. Weird grammar. Generic greetings. That unmistakable smell of something translated through three languages before landing in your inbox. Security awareness training built entire programs around those tells. Employees got pretty good at sniffing out the obvious stuff.

Then large language models got good. Really good. And now we're in a different situation entirely.

I've been watching the shift play out in incident reports, threat intelligence feeds, and conversations with security teams across the country, and the consensus is pretty clear: AI-powered phishing isn't a future problem. It's a right-now problem, and most organizations are fighting it with tools designed for a threat that no longer exists in its original form.

The Old Playbook Is Dead

Traditional phishing detection relied heavily on pattern recognition — flagging emails that matched known malicious templates, contained suspicious links, or tripped on linguistic markers associated with non-native English speakers running bulk campaigns. That approach worked reasonably well when attackers were blasting millions of identical or near-identical emails and hoping a percentage would stick.

Generative AI blows that model up. Tools built on top of publicly available LLMs — and increasingly, fine-tuned models specifically designed for offensive social engineering — can produce phishing emails that are grammatically flawless, contextually appropriate, and personalized to a degree that would have required hours of manual research per target just a few years ago.

We're not talking about swapping out a name in a template. We're talking about emails that reference a target's recent LinkedIn posts, congratulate them on a company announcement from last week, mention a colleague by name, and mirror the writing style of internal communications — all generated in seconds at scale.

How the Automation Actually Works

The attack pipeline for an AI-assisted phishing campaign looks something like this: an attacker starts with open-source intelligence gathering, pulling data from LinkedIn, company websites, press releases, GitHub profiles, and public social media. This used to be a manual, time-intensive process that limited how many high-quality targets an attacker could pursue.

Now, OSINT aggregation tools can scrape and structure that data automatically, feeding it into an LLM prompt that generates a personalized lure. The model produces a draft, a human attacker reviews and tweaks it (or doesn't bother), and the email goes out. The whole cycle from target selection to sent email can take minutes.

Some of the more sophisticated toolkits circulating in underground communities go further, integrating real-time context — pulling in news about a target company, recent earnings reports, or even monitoring a target's public social activity to time the attack when they're most likely to be distracted or emotionally primed to click.

There have been documented cases in the US financial sector where employees received emails that accurately referenced internal project names — information that was technically public but buried in regulatory filings that no human attacker would have bothered to dig through. The AI found it. The employee clicked.

The Voice and Video Problem

Email is just the most familiar vector. The same generative AI capabilities that are transforming written phishing are being applied to voice and video in ways that are genuinely unsettling.

Vishing — voice phishing — has gotten dramatically more convincing with AI voice cloning. Several US companies have reported incidents where employees received calls from what sounded exactly like their CEO or CFO instructing them to authorize wire transfers or share credentials. In a few high-profile cases, the voice clone was good enough to fool people who spoke with the executive regularly.

Deepfake video is following the same trajectory. It's not yet at the point of real-time video calls that are undetectable, but it's close enough that security teams need to be thinking about it now rather than waiting for the first wave of incidents to hit.

Why Traditional Email Security Is Struggling

Legacy secure email gateways and even many modern cloud-based solutions are fundamentally built around detecting known-bad content — malicious links, suspicious attachments, spoofed domains, and signature-matched templates. AI-generated phishing can sidestep almost all of those controls.

A well-crafted AI phishing email might contain no links at all, relying instead on a pretextual conversation that eventually leads the target to initiate contact with the attacker, visit a URL they find themselves, or take an action that doesn't trigger any automated alert. The email itself looks completely clean because it is clean by every technical measure the gateway is checking.

Some vendors are responding by building AI-based detection into their platforms — using behavioral analysis, communication graph anomalies, and writing style inconsistencies to flag suspicious messages. It's a genuine arms race, and right now the offense has some structural advantages.

What Actually Works for Defense

Okay, so what can you realistically do? A few things, and none of them are magic bullets, but combined they make a meaningful difference.

Rethink your security awareness training. The "spot the typo" curriculum is obsolete. Modern training needs to focus on behavioral red flags — urgency, unusual requests for credential sharing or wire transfers, pressure to bypass normal processes — rather than linguistic tells that AI has already eliminated. Employees need to understand that a perfectly written, highly personalized email is no longer a sign of legitimacy.

Implement out-of-band verification for high-stakes requests. Any request involving financial transactions, credential changes, or sensitive data access should require a secondary verification step through a channel completely separate from email. A phone call to a known number. A Slack message. Anything that doesn't rely on the potentially compromised communication channel.

Invest in communication behavior analytics. Tools that establish a baseline for how employees communicate — who they talk to, what they typically discuss, what their writing patterns look like — can flag anomalies that content-based filters miss. An email that looks perfect but comes from a sender who has never communicated with this employee before, at an unusual time, requesting an unusual action, should surface as suspicious even if the content is flawless.

Reduce your OSINT footprint where possible. You can't eliminate it, but you can limit how much actionable context is publicly available for attackers to feed into their models. Audit what's on your company website, what employees are sharing on LinkedIn, and what's buried in public filings that could be weaponized.

Take phishing simulations seriously, and make them harder. If your simulated phishing campaigns are still using the old-school templates, you're training people for the wrong threat. Run simulations that use AI-generated, personalized lures. It's uncomfortable, but it's the only way to build real muscle memory for the current threat landscape.

The Uncomfortable Bottom Line

Generative AI has handed attackers a capability that fundamentally changes the economics and effectiveness of social engineering. What used to require a skilled human operator with hours to invest can now be replicated at scale by anyone with access to the right tools and a willingness to use them.

The security industry will catch up — it always does, eventually. But in the meantime, the gap between what attackers can do and what most organizations are defended against is real and widening. The teams that acknowledge that gap and adapt their defenses accordingly are the ones that are going to come out of this period with their data intact.

Everyone else is going to have a very bad day when the machine decides to introduce itself.

All Articles

Related Articles

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder

Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder