Phishing 3.0: The Fight Moves to Agent Versus Agent
Most email defenses still do the job they did a decade ago. Scan the message, look for something ma 2026-8-19 11:30:0 Author: thehackernews.com(查看原文) 阅读量:10 收藏

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person.

From Bad Content to Bad Intent to AI on Both Sides

Phishing 1.0 was bad content. Malicious links, infected attachments, spam. Secure email gateways were built for this. Scan the message, match the signature, drop the bad stuff. That era is largely handled.

Phishing 2.0 is bad intent. Business email compromise, executive impersonation, fake invoices, wire fraud. There is no malicious payload to scan, only social engineering that reads as a normal request from a person you trust. Gateways are blind to it because there is nothing in the content to flag. Behavioral analysis is the only thing that catches it, which is why some of us have spent the better part of a decade building AI that learns how your people actually communicate.

Phishing 3.0 is AI-powered and multi-channel. GenAI writes the lure. Deepfakes carry it into voice and video. The campaign spans email, collaboration tools, and live calls. The attacker is no longer a person typing. It is increasingly an agent that researches, drafts, sends, and adapts on its own.

The third stage changed the economics of attacking you.

The Attacker Now Runs an Agent

Reconnaissance used to cost an attacker time. A human had to read your website, scrape job postings, map your suppliers, and study a few executives on social media before writing something believable. Agentic AI removes that cost. An agent can summarize your public footprint, pull from GitHub and cloud documentation, identify who reports to whom, and generate a target-specific pretext in seconds, then do it again for the next 10,000 organizations.

The quality of the lure goes up. The clumsy, misspelled phish is retiring, replaced by interactive lures that hold a conversation. Microsoft has tracked phishing platforms that generate tens of millions of messages a month [3], and in a 2026 Dark Reading readership poll, 48% of security professionals ranked agentic AI as the top attack vector for the year, ahead of deepfakes and every other option [4].

The blast radius widens too. You no longer have to be a high-value target to get a tailored attack. When reconnaissance is free, every organization is worth personalizing, and the small teams that assumed they were too minor to bother with get swept into automated campaigns that arrive looking hand-crafted.

The worst of it lands when the lure leaves the inbox altogether. In one widely reported case at engineering firm Arup, the attack opened with a phishing email impersonating the company's UK-based CFO. When the employee hesitated, a deepfake video call with what looked like several familiar colleagues closed the deal. Every other face on the call was synthetic. The employee approved 15 transfers worth about $25 million [5]. No amount of email hygiene would have caught that. The attack went after trust in what employees could see and hear, and that trust is exactly what attackers have learned to exploit.

The Data Says Trust Is Already Broken

One incident, however expensive, is still an anecdote. The pattern shows up when you ask the people who run security for a living. In January 2026, Osterman Research published a study, commissioned by IRONSCALES, of 128 security and IT leaders at US organizations of 1,000 to 5,000 employees [1]. The findings are blunt.

  • 88% experienced at least one incident that undermined trust in their digital communications over the prior year.
  • 82% said they see heightened threat actor interest in their specific industry.
  • 60% lack confidence in their ability to counter deepfake attacks, even with the training they run today.
  • 55% said a failed response to a trust-based attack raises the likelihood of a full breach.
  • More than a third saw attackers masquerade as a trusted vendor or partner.

The tools most organizations run assume a threat they can find inside a message. The modern attack impersonates trust across channels where there is nothing to scan, so those tools never get their shot.

The gateway math reinforces it. IRONSCALES analysis of production email traffic shows Microsoft 365 EOP missing 293 phishing messages per 100 mailboxes every 30 days, and Google Workspace missing 350, in both cases well above what a well-tuned gateway catches [2]. Those numbers are the daily baseline of what reaches employees after the perimeter has had its say.

Why the Old Response Model Breaks

The traditional model runs block, then detect and respond. Block what you recognize, and when something gets through, investigate and clean up after. Against a human attacker sending a few hundred emails, that cadence held. Against an agent generating personalized, conversational, multi-channel attacks faster than a person can read them, detect and respond is always one step behind.

The volume alone makes the point. In a 2026 study by Crogl and the Ponemon Institute, enterprise SOCs reported an average of 4,330 alerts a day and investigated just 37% of them [6]. You cannot out-hire an agent. You can only out-automate it.

So the response model has to add a third posture in front of the other two. Preempt. Anticipate the attack that is being built for you, harden detection before the first message lands, and let automation handle the routine so humans spend their time on the decisions that need judgment.

The Defender Needs an Agent Too

Phishing 3.0 forces a symmetry. If the attacker is running agents, the defender has to run them too, or accept a permanent speed disadvantage.

That shift is already underway. In the same Crogl study, security teams with the strongest postures had adopted AI in the SOC at a far higher rate than their peers, 68% against a 46% average[6]. Microsoft reports that its autonomous alert triage agent identified 6.5 times more malicious emails than manual review and saved one health network, St. Luke's University Health Network, more than 200 analyst hours a month [7][8]. The agent stops being a chatbot bolted onto a dashboard and becomes a teammate that investigates end to end and hands a human a verdict instead of a ticket.

At IRONSCALES we build for this. One anticipates. One investigates. One educates.

Our Red Teaming Agent runs the same open-source reconnaissance an attacker would, studying your organization across social media, code repositories, and public filings, then hardens and personalizes detection before an attack is ever sent. Our Phishing SOC Agent investigates threats at the level of an L2 analyst, compressing forensics that take hours into minutes. Our Phishing Simulation Agent trains employees against reconnaissance-based attacks modeled on the tactics actually aimed at them, rather than generic templates. Underneath all three, our Adaptive AI learns each organization's communication patterns and sharpens on real-world signal from a network of tens of thousands of security professionals.

The product names matter less than the principle. Preemption requires an agent on the defensive side that thinks the way the offensive one does. A defense that only reacts to what already arrived is bringing yesterday's model to a fight that has moved on.

What This Means for Practitioners

Stop measuring email security only by what it blocks at the perimeter. The meaningful number is what still reaches the inbox after the gateway, because that is where the modern attack lives. Ask any vendor for their post-delivery miss rate and treat vagueness as an answer.

Extend the threat model past email into voice and video. The Arup case was a video call, not a message. If your identity verification stops at the inbox, the most expensive attacks will route around it.

Judge automation by autonomy, not dashboards. A tool that surfaces more alerts for a human to read is adding to the daily alert pile. A tool that investigates and resolves is subtracting from it. Ask what percentage of incidents get handled without a human touching them.

Treat employee training as reconnaissance-aware. Generic simulations teach people to spot generic phish. The attacks aimed at them are personalized, so the practice should be too.

Phishing 3.0 is not a forecast. Attackers are already running agents, the deepfake losses are already being counted, and the data shows trust is already being exploited faster than most defenses can respond. The organizations that come through it well will be the ones that stopped trying to win a speed race against software with human hands alone, and put an agent of their own on the field.

References

  1. Osterman Research, "Rebuilding Trust in Digital Communications," commissioned by IRONSCALES, January 2026. Survey of 128 security and IT leaders at US organizations of 1,000 to 5,000 employees, fielded September to October 2025. https://ironscales.com/rebuilding-trust-in-digital-communications-report-download
  2. IRONSCALES, analysis of production email traffic across its customer base (post-delivery miss rates for Microsoft 365 EOP and Google Workspace, per 100 mailboxes per 30 days). Internal data; figures available on request.
  3. Microsoft Security, "Threat actor abuse of AI accelerates from tool to cyberattack surface," Microsoft Security Blog, April 2, 2026. https://www.microsoft.com/en-us/security/blog/2026/04/02/threat-actor-abuse-of-ai-accelerates-from-tool-to-cyberattack-surface/
  4. Dark Reading, "2026: The Year Agentic AI Becomes the Attack-Surface Poster Child," 2026. https://www.darkreading.com/threat-intelligence/2026-agentic-ai-attack-surface-poster-child
  5. CNN Business, "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee," May 16, 2024. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
  6. Crogl and Ponemon Institute, "The State of SecOps and the Deployment of AI in the SOC," 2026. Survey of 649 North American IT and security practitioners. https://www.crogl.com/newsroom/state-of-secops-ai
  7. Microsoft, "St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents," Microsoft Customer Stories, 2026. https://www.microsoft.com/en/customers/story/25330-st-lukes-university-health-network-microsoft-security-copilot
  8. Microsoft, "From alert overload to decisive action: How Security Copilot agents are transforming security and IT," Microsoft Community Hub, 2026. https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213

Note: This article has been expertly written and contributed by Steve Malone, Chief Product and Strategy Officer, IRONSCALES.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus.html
如有侵权请联系:admin#unsafe.sh