Posts

Showing posts with the label phishing attacks

How to Prepare for Next-Gen, AI-Powered Phishing Attacks

Image
Phishing Attacks ​Phishing attacks are nothing new, and we’ve probably published 10+ blog posts over the years warning against them in one form or another. Now it’s time to get ready for yet another evolution in AI-powered phishing attacks. Here’s what you need to know for 2026. Catching Up: Current State of Phishing Attacks We’ve already warned about how generative AI is making it easier for scammers to create convincing, legitimate-looking content at scale. 10 years ago, phishing emails almost always had tell-tale signs like weird writing, typos, and graphic design that just looked off. But today those red flags are much harder to spot. The grammar is as good as your favorite genAI model’s, and it’s easier than ever to spin up a fake website thanks to those same tools. So we’ve already shifted our guidance away from looking for visual evidence. Now we warn businesses to look for directional evidence instead. Things like: Urgent calls to do things: “Click now to login or your accou...

Successful Phishing Attempts TRIPLED in 2024

Image
Phishing Attacks Are Increasing...Are Your Employees Educated On What To Look For? We’re frequently warning our customers and readers about the risks of phishing scams and attacks, and it looks like we won’t be stopping anytime soon. A new report in Infosecurity Magazine reveals that the rate at which business users clicked on phishing links was up in 2024, nearly triple the rate from 2023. That’s what we in the industry like to call, well, really bad news. Before we get into why things are getting worse instead of better (and what you should do to limit risk), let’s quickly review how these scams are built. The Anatomy of a Phishing Scam A phishing scam starts with a message of some sort: traditionally it was an email, but it could also be a text message, online ad, or even a search result (though this is less common than other methods). The message appears to come from a legitimate source (in recent business attacks, Microsoft 365 and Docusign were the top companies the scammers pos...