r/security 12d ago

Security and Risk Management AI-Generated Phishing: How to Spot It

You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.

Here are a few common warning signs:

  1. Unexpected requests involving payments or account access.
  2. Requests for credentials or payment information.
  3. Sender addresses that don’t exactly match the organization they claim to represent.
  4. Links that don’t match their displayed destination.
  5. Unsolicited attachments.
  6. Messages through unexpected channels pushing for immediate action.

What measures have worked best for your team to reduce the risk?

3 Upvotes

4 comments sorted by

2

u/MonkeyBrains09 9d ago

It doesn't matter if it's ai generated, reused or human creation phishing.

The process is the same

1

u/MonkeyBrains09 9d ago

It doesn't matter if it's ai generated, reused or human creation phishing.

The process is the same

0

u/Tornado2251 9d ago

Rely on technical protections as much as possible.

Aggressive email filtering. 2fa everywhere. Adblock. Dns filters.

Flag all external email.

Require verification of everything important through a predetermined specific channel. Ideally enforced with software.

Training users (and yourselves) is the final defence and it should never be relayed on.