Cybersecurity

AI-Powered Phishing: Cybercriminals Generate One Million Targeted Scams in Days

FORTSECURE GLOBAL· 2026-09-13🛰 Dark Reading
#AI Security#Cybersecurity#Data Breach#Incident Response
AI-Powered Phishing: Cybercriminals Generate One Million Targeted Scams in Days

Cybercriminals are leveraging generative AI to automate the creation of over a million highly personalized phishing emails in just days, eliminating the historical trade-off between scale and sophistication.

The Industrialization of Hyper-Personalized Phishing\n\nIn a major shift within the threat landscape, modern adversaries are turning to advanced generative AI tools to break the historical bottleneck of email fraud. Traditionally, attackers faced a fundamental choice: launch high-volume, generic spam campaigns that were easily filtered out, or spend extensive time crafting targeted, credible spear-phishing lures for specific individuals. Recent threat intelligence reveals that this operational compromise is effectively over, with malicious actors now capable of generating over one million context-rich, bespoke phishing emails in under 72 hours.\n\nBy ingesting open-source intelligence (OSINT), leaked breach data, and public social media records, these automated engines synthesize tailored messaging that mimics corporate communication patterns, trusted service providers, and colleagues. The resulting lures show remarkably high linguistic fidelity, devoid of typical grammatical errors or obvious flags, making standard rule-based detection significantly less effective.\n\n## Strategic Defense and Recommended Actions\n\nAs traditional indicators of compromise in email bodies become harder to detect, security operations teams must adapt their defenses to counter machine-speed social engineering:\n\n* Adopt Behavioral and Contextual AI Defense: Replace legacy static email gateways with modern integrated cloud email security (ICES) platforms that utilize machine learning to establish baseline communication norms and detect subtle anomalies in relationship patterns.\n* Enforce Resilient MFA: Mandate FIDO2-compliant, hardware-backed multi-factor authentication (MFA) to minimize the risk of credential harvesting attacks.\n* Revamp Security Awareness Programs: Update employee training to emphasize process verification—such as out-of-band verification for fund transfers or sensitive credential requests—rather than relying solely on identifying typos or suspicious phrasing.


แหล่งที่มา: Dark Reading เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 19:21:08 GMT บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: Dark Reading

เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 19:21:08 GMT

บทความต้นฉบับ: https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog