Fighting GenAI with GenAI: The New Email Security Landscape
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s.
Although almost as old as the Internet, it remains the instrument of choice for threat actors wanting to pose as trusted organizations or individuals for the purposes of corporate infiltration.
In fact its use is on the rise: according to the most recent figures from the Federal Bureau of Investigation (FBI), some 26 percent of all cybercrime complaints filed with them are now phishing-related.
The bad news doesn’t stop there.
Phishing is mutating in alarming new ways, raising all sorts of difficult questions for defenders and placing email security at a tricky inflection point.
AI has for years been a useful tool in the hands of the cybercriminal.
But the advent of Generative AI (GenAI) is proving a cyber game changer, transforming phishing from a widespread but easily identifiable nuisance into a lethal precision instrument.
Aspiring phishers have historically been hindered by various constraints.
Their attempts at chummy authenticity have often been undermined by easy-to-spot mistakes and amateurish formatting – blemishes that traditional email security is good at picking up.
Personalised attacks have also been hard to launch at any kind of scale.
GenAI sweeps all technical, linguistic, and operational restrictions aside by automating sophistication.
Attackers no longer have to choose between individually targeted “spear phishing” which takes much effort to coordinate, and large-scale attacks that lack finesse.
Now, with minimal expertise and at low cost, they can hit thousands of victims with minutely tailored phishes at the press of a button.
Today’s Large Language Models (LLMs) generate polished and contextual text in any language, backing it with realistic brand graphics and convincing web addresses.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.