Phishing Has a New Problem: The Attacker Isn't Human Anymore
Email defences built for bad links and bad attachments are struggling as AI agents start writing, sending, and even reading the mail on both sides.

Key points
- Traditional email security scans messages for malicious links or attachments, a model that assumes the danger sits in the file.
- Attackers have shifted from bad content to bad intent, using clean-looking messages that manipulate the reader rather than infect the machine.
- AI agents are now writing phishing lures at scale, and in some companies AI agents are also reading and acting on incoming email.
- Defenders face a world where software talks to software, and a convincing request can trigger action without a human ever seeing it.
Email security hasn't really changed in ten years. A message arrives, a scanner checks it for something nasty, and if nothing lights up, it lands in the inbox.
That approach worked when the danger was a booby-trapped attachment or a link to a fake login page. It works less well now, and it's about to work even less, because the sender isn't always a person.
The Hacker News mapped this shift this week, and it lines up with what incident responders have been quietly saying for months.
What actually changed?
The payload moved out of the file and into the words. Modern phishing doesn't need a virus attached. It just needs a believable message telling someone in finance to change a bank account, or telling an assistant to buy gift cards for the boss.
Nothing lights up on a traditional scanner. The email is, technically, clean, and the harm sits entirely in what it convinces a human to do.
Security vendors have tracked this trend for years under the label BEC, meaning business email compromise, where criminals impersonate an executive or supplier to trick staff into moving money. The FBI's Internet Crime Complaint Center has ranked BEC among the costliest categories of cybercrime for most of the last decade.
Where does AI come in?
On the attacker side, generative AI, meaning software that writes fluent text on demand, removes the last easy tell. Broken English, odd phrasing, copy-paste templates: all gone.
A criminal can now produce a thousand tailored lures in the time it once took to write one. Each one references the right project, the right vendor, the right tone. Language is no longer a filter.
On the defender side, AI is being pointed at the same problem in reverse. Newer tools try to model intent rather than scan for bad words: does this request make sense, from this sender, at this time, to this person? That's a harder question, and the answers are probabilistic. AegisAI, a startup we covered on 24 July, is one company betting its entire product on this approach.
Why do AI agents on the receiving end matter?
Because the human is starting to leave the loop. Companies are deploying AI assistants that read email and, in some cases, act on it: book the meeting, approve the invoice, reply to the customer.
If a phishing message is aimed at that assistant rather than the person, the old advice doesn't apply. The assistant doesn't hover over a link. It reads instructions and tries to be helpful.
Researchers have shown that hidden instructions inside an email, a technique called prompt injection, text designed to hijack an AI assistant's behaviour, can push these agents into actions their owner never requested. Forwarding sensitive files, wiring money, draining a shared drive. We reported the mechanics of that attack on 4 August, when security researchers demonstrated it against AI chatbots built into live email platforms.
Should you worry?
Two practical things follow from this. First, the old rule still holds: if a message is pushing you to move money or hand over a code, slow down and confirm through a channel you already trust, ideally a phone call to a number you already have.
Second, if your employer is rolling out AI tools that read your mailbox or act on your behalf, it's fair to ask what guardrails exist. Who approved that agent's permissions? What can it do without checking with you first?
The part I'd watch most closely isn't the phishing volume, it's the prompt-injection angle. Attackers don't need to fool a person anymore if they can just instruct the software acting on that person's behalf. That's a narrower attack surface than a crowded inbox, but it's one most organisations haven't thought through.



