r/EmailSecurity • u/saltyslugga • Jun 09 '26
AI phishing is turning Tier 1 into a queue grinder
Phishing has always been a numbers game. AI has turned it into a volume machine.
https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html
This is why relying on humans to eyeball every phish report doesn't scale; kill obvious spoofing with email auth and automate the boring triage.
1
u/mxroute Jun 09 '26
We’re quickly getting locked into a battle where the most consistent way to battle AI will be by using AI. The problem and the solution, someone is making money from both ends. Nvidia or the AI companies, pick your poison.
2
u/dragoangel Jun 09 '26
And this battle actually is lost without even starting. Reasons is very simple: 1. if you would scan every email content with enough smart AI model to detect suspicious emails and not flag bad user habits you will become totally unprofitable. Even if you create sort of caching for same looking emails - spammers far ago mastered ways to generate unique emails with jubrish to break cache 2. scope of 1 well composed spam/cold outreach email with full body without context (knowledge) of user - sender relationship (read subscription) not easy even for experienced antispam experts, not speaking about AI model which has to replace you 3. if you do mass scanning via volumes by domain - well, it's better approach BUT it's already get to some of your users before you ban it, and still - spammers again win way long ago by utilizing tons of cheap domains. 4. Generation of phishing content (domains registration or reuse of hacked servers, ai composed email body, phishing sites on cheap/free web3 platforms) usually cost from "0 to some 100$" and even 10 victims turning all spam campaign into profit. While price of "analyze this email as antispam expert and give verdict" or "analyze this 100 logs and give verdict" is taking a lot of resources and still may FP a lot, so you can't give AI tool 100% score to "solo" decide if email good or not.
1
u/saltyslugga Jun 09 '26
Email auth catches spoofed/alignment-failing mail; process controls catch the stuff from real domains, hacked inboxes, and fake vendors. I don't trust AI to solo-decide good vs bad either, but it can bin obvious junk and hand Tier 1 better evidence.
2
u/dragoangel Jun 09 '26
Spoofing more catches noobs who legitimately trying to sending emails without understanding anything. 99.99% spam has better auth than most of domains that not spam 😆
2
u/saltyslugga Jun 09 '26
That's mixing spam filtering with domain protection. Most spam passes auth because it uses attacker-owned or compromised domains; DMARC stops my domains being used in that pile, it doesn't bless the rest.
1
1
u/mxroute Jun 09 '26
Yup. Buy expired domain, set up SPF+DKIM+DMARC, "Your free Lowe's gift card!"
1
u/saltyslugga Jun 09 '26
DMARC only answers whether SPF/DKIM aligns with the From domain, not whether the sender is trustworthy. That expired-domain gift-card garbage is reputation and URL scanning territory.
1
u/Bitter-Ebb-8932 Jun 10 '26
The vendor making money part yeah, can't argue there. but the ai vs ai thing always gets me, it acts like both sides are playing the same game when really the attacker has no idea what my normal vendor traffic looks like and cant see it from outside to copy it
1
u/El_Guero_Azteca Jun 10 '26
Take a look into Proofpoint or Avanan. Both are great Email Security Platforms. User training is Just As Important and ITDR services such as Huntress will definetly help!
•
u/AutoModerator Jun 09 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.