Phishing Has a New Problem: The Attacker Isn't Human Anymore

Email defences built for bad links and bad attachments are struggling as AI agents start writing, sending, and even reading the mail on both sides.

ThreatVectr Newsdesk· 4 min read
Close-up, edge-to-edge 16:9 photograph of a glowing circuit board with streams of faintly visible text and code cascading across its surface in soft blue and wh
Share

Key points

  • Traditional email security scans messages for malicious links or attachments, a model that assumes the danger sits in the file.
  • Attackers have shifted from bad content to bad intent, using clean-looking messages that manipulate the reader rather than infect the machine.
  • AI agents are now writing phishing lures at scale, and in some companies AI agents are also reading and acting on incoming email.
  • Defenders face a world where software talks to software, and a convincing request can trigger action without a human ever seeing it.

Email security has not really changed in ten years. A message arrives, a scanner checks it for something nasty, and if nothing lights up, it lands in the inbox.

That approach worked when the danger was a booby-trapped attachment or a link to a fake login page. It works less well now. And it is about to work even less, because the sender is not always a person.

The Hacker News flagged this shift, and it lines up with what incident responders have been quietly saying for months.

What actually changed?

The payload moved out of the file and into the words. Modern phishing, sometimes called business email compromise, does not need a virus attached. It just needs a believable message telling someone in finance to change a bank account, or telling an assistant to buy gift cards for the boss.

There is nothing for a traditional scanner to detonate. The email is, technically, clean. The harm is in what it convinces a human to do.

Security vendors have tracked this trend for years under labels like BEC, meaning business email compromise, where criminals impersonate an executive or supplier to trick staff into moving money. The FBI's Internet Crime Complaint Center has ranked it among the costliest categories of cybercrime for most of the last decade.

Where does AI come in?

On the attacker side, generative AI, meaning software that can write fluent text on demand, removes the last easy tell. The broken English, the odd phrasing, the copy-paste template: gone.

A criminal can now produce a thousand tailored lures in the time it used to take to write one. Each one references the right project, the right vendor, the right tone. Language is no longer a filter.

On the defender side, AI is being pointed at the same problem in reverse. Instead of looking for bad words, newer email tools try to model intent: does this request make sense, from this sender, at this time, to this person?

That is a harder question, and the answers are probabilistic rather than yes-or-no.

Why do AI agents on the receiving end matter?

Because the human is starting to leave the loop. Companies are rolling out AI assistants that read email, summarise it, and in some cases act on it. Book the meeting. Approve the invoice. Reply to the customer.

If a phishing message is now aimed at that assistant rather than the person, the old advice, hover over the link, check the sender, does not apply. The assistant does not hover. It reads instructions and tries to be helpful.

Researchers have shown that hidden instructions inside an email, a technique called prompt injection, meaning text designed to hijack an AI assistant's behaviour, can push these agents into actions their owner never asked for. Forwarding sensitive files. Draining a shared drive. Wiring money.

What should ordinary readers take from this?

Two practical things. First, the old rule still holds: if a message is pushing you to move money, change payment details, or hand over a code, slow down and confirm through a channel you trust, ideally a phone call to a number you already had.

Second, if your employer is rolling out AI tools that read your mailbox or act on your behalf, it is fair to ask what guardrails sit around them. Who approved that agent's permissions? What can it do without checking with you first?

The fight is no longer just people versus scams. It is software versus software, with humans as the customers, the victims, and, still, the last line of defence.

© 2026 Threat Vectr