Скопировано

AI Makes Phishing Attacks More Precise

06.02.2025 16:57:00
Дата публикации
Large companies are seeing an increase in personalized phishing attacks created with the help of AI, Ars Technica reports. New technologies allow cybercriminals to precisely tailor fraudulent emails to specific executives and organizations.

Insurance company Beazley and eBay warn that scammers are using AI to analyze online profiles and social networks, collecting data on potential victims.

“Attacks are becoming more and more individualized, and we suspect that AI is behind this,” said Kirsty Kelly, Beazley’s chief information security officer.

Modern AI tools can study employees’ communication styles, as well as their preferences and interests, to create the most persuasive emails. According to eBay researcher Nadezhda Demidova, this lowers the barrier to complex attacks.

According to Check Point Software, AI allows scammers to create perfectly designed emails with visual and personalized information that are difficult to distinguish from legitimate ones. Such attacks bypass basic filtering systems, since each email can be unique.

According to the US Cybersecurity and Infrastructure Agency, more than 90% of successful cyberattacks begin with phishing. In 2024, the average cost of a data breach has grown to $4.9 million, and the total damage from attacks has reached $50 billion since 2013.

Particularly dangerous are fraudulent emails without malicious attachments, imitating requests from company executives. Such attacks convince employees to transfer confidential data or transfer money.

“AI scans everything from website code to aspects of human behavior,” says Sean Joyce, head of cybersecurity at PwC.

Familiar protection methods are becoming less effective. Spam filters block mass mailings, but are unable to track thousands of unique emails created by AI. The authors of the study warn that companies must adapt their cybersecurity strategies.

Employee training, two-factor authentication and advanced filters can help reduce the risk of attacks. Companies are advised to review their security measures to combat new types of fraud.


(the text translation was done automatically)