It’s Official – Generative AI Has Made Phishing Emails Foolproof

Stu Sjouwerman | Sep 28, 2023

It’s Official – Generative AI Has Made Phishing Emails FoolproofThe most basic use of tools like ChatGPT to script out professional-looking emails has all but eliminated improperly written content as an indicator of a potential phishing scam.

A recent article interviewing Brian Schnese, a senior risk consultant at insurance broker Hub International highlighted the transition from the misuse of generative AI as a means of crafting well-written phishing emails as a hypothetical to one that is now fully commonplace. “We’re already seeing it," Schnese commented.

“We’re in a world today where I can go to ChatGPT and type in, ‘please craft a request to my vendor asking them to change my wiring instructions,’ and it spits out a perfect request. [I can then go] back to ChatGPT and say, ‘please add a sense of urgency and stress the confidential nature of this transaction’ –and again, instantly, it’s perfect.”

This matched with the use of no-code automation to craft content means that cybercriminals can easily create spear phishing campaigns based on industry, victim role, and more, fine-tuning an attack without the need to do any manual work.

In other words, you can no longer assume the emails used for spear phishing attacks will have telltale signs – such as misspellings, poor grammar, etc. – that they are fake.

It also means that organizations are going to need to work to specifically elevate the vigilance of those users that interact with the company’s financials – something accomplished through continual security awareness training - so they are less likely to gloss over a phishing email and treat it as legitimate.

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.