Phishing is a well-known threat in the field of cybersecurity. Traditionally, it has been relatively easy to spot these malicious messages thanks to glaring errors such as spelling mistakes, poor layout or an alarmist tone; however, with the advent of artificial intelligence (AI), these fraud attempts have become much more sophisticated. So how do you recognize a phishing email in this new technological context?
Clues before AI
Before the use of AI, phishing scams were usually identified by:
- grammatical and spelling errors. Typos were plentiful, and poorly constructed sentences were commonplace.
- unnatural language. Wording seemed awkward, often due to poorly performing machine translation.
- suspicious sender addresses. Emails originated from non-professional sources or sources that were very different from those of legitimate companies.
- urgent calls to action. The criminals used a tone of panic to encourage a quick click on a link or download an attachment.
- inconsistent visual elements. The dubious layout featured misaligned logos, pixelated images and inappropriate colours.
Reality after AI
Fluid, typo-free text, natural, contextual language, fake sender addresses that appear reliable, more subtle calls to action, professional visuals… In short, the use of artificial intelligence now makes it much easier to create fraudulent communications in several languages without grammatical errors, appearing to come from legitimate sources. This considerably reduces the work required to produce effective phishing emails, while at the same time multiplying their volume. In 2023, malicious messages increased by 1,265%, while attacks targeting credentials jumped by 967%. What’s more, according to email security provider Egress, 71% of AI-created email threats go undetected.
How can you protect yourself against this new generation of phishing?
- Check the sender’s address: Even if it seems legitimate, examine it carefully. Even the smallest detail can reveal fraud. You can also compare the email with any previous communications you have received from the supposed sender. If there are inconsistencies in tone, style or vocabulary, this may indicate that the message is a phishing attempt.
- Be alert to unusual requests: Legitimate companies never ask to share critical information by email. In addition, AI-generated phishing emails generally use generic greetings, such as ‘Dear User’ or ‘Dear Customer’. You can also look for signatures that don’t match the sender’s typical signature.
- Use advanced security tools: Implement email filtering solutions and anti-phishing software that incorporate AI, and promote ongoing employee training.
By understanding the new signs of phishing and adopting rigorous cybersecurity practices, you can significantly reduce the risk of falling victim to these sophisticated attacks. At MicroAge, we offer comprehensive solutions to protect your business from cyber threats. Contact our experts today to find out more about our cybersecurity services.
Share