How MSPs can catch phishing attacks email filters miss

Phishing Attacks Just Got a Whole Lot Smarter – And It’s Up to MSPs to Catch Them

Cybersecurity professionals have long warned about the dangers of phishing emails, but recent advancements in artificial intelligence (AI) have made these attacks more convincing and harder to detect than ever. Managed Service Providers (MSPs), who are often responsible for protecting their clients’ online security, must be aware of this evolving threat landscape and take proactive steps to prevent AI-assisted phishing campaigns from slipping through the cracks.

The problem is that traditional email filters, which rely on signatures and known indicators of compromise, can no longer keep pace with the speed and sophistication of modern phishing attacks. These emails are now generated in minutes using publicly available language models and LinkedIn profiles, making them almost indistinguishable from legitimate business communication. In fact, research has shown that AI-generated spear-phishing campaigns have achieved a staggering 54% click-through rate, matching those of human experts at a fraction of the cost.

So how do these attacks work? Every AI-powered phishing campaign follows a basic path: reconnaissance, content generation, delivery and evasion, and post-compromise activity. During the reconnaissance phase, AI scans public sources to build a profile of a specific employee, including their colleagues, projects, and communication habits. This information is then used to create a personalized email that appears to come from a trusted colleague or vendor. The email may even use contextual language and formatting to make it look like legitimate business communication.

But here’s the thing: traditional filters can’t keep up with these rapidly changing emails. AI also helps attackers evade detection by creating unique versions of every email, using techniques such as polymorphic phishing, which continuously changes subject lines, sender details, formatting, and content. And if a user clicks on a malicious link or enters their credentials, the attack escalates quickly, allowing attackers to steal session tokens, create mailbox rules, and move through the client’s environment in minutes.

Phishing is now the leading cause of data breaches, accounting for 16% of incidents and costing organizations an average of $4.8 million per breach. By the time a phishing email reaches the inbox, prevention alone is no longer enough. Protecting clients requires visibility beyond email, with endpoint detection, identity monitoring, and rapid response working together to stop attackers before they can expand their access.

So what can MSPs do to catch these AI-generated attacks? It’s not about relying on traditional filters or signatures; it’s about monitoring behavior, not just emails. Every successful phishing attack leaves signs that something isn’t right. Look for unusual account and user activity, such as new forwarding or mailbox rules, impossible travel (logging in from two different countries within minutes), or unfamiliar login locations.

By being proactive and staying ahead of the curve, MSPs can help protect their clients from these sophisticated attacks and prevent costly breaches. As the threat landscape continues to evolve, it’s essential for security professionals to stay vigilant and adapt their strategies to keep pace with the latest phishing trends.


Source: Bleeping Computer — 2026-08-20