This is according to email security provider Egress, which released a Phishing Threat Trends Report that identifies the biggest trends in phishing, as well as the rise of chatbots in the realm of cyber-attacks.
The landscape is facing a concerning development in AI-assisted chatbots, according to Egress. According to them, AI detectors are failing to discern the origin of chatbot phishing emails in just over 71% of instances, meaning AI-generated phishing emails are becoming indistinguishable from those crafted by humans.
According to the report this is because AI detectors rely on large language models (LLMs) to identify malicious content. Detectors become more accurate when the sample size increases, needing a minimum of 250 characters to be effective.
However, the report found that almost half (44.9%) of phishing emails are below that character count, and a further quarter fall below the 500 character count.
“Without a doubt chatbots or large language models (LLM) lower the barrier for entry to cyber-crime, making it possible to create well-written phishing campaigns and generate malware that less capable coders could not produce alone,” said Jack Chapman, VP of threat intelligence at Egress.
“However, one of the most concerning, but least talked about applications of LLMs is reconnaissance for highly targeted attacks.
“Within seconds, a chatbot can scrape the internet for open-source information about a chosen target that can be leveraged as a pretext for social engineering campaigns, which are growing increasingly common,” he continued.
Another growing trend in phishing is the rise in obfuscation techniques, where threat actors make their malicious content more difficult to detect by hiding data with modified content.
The report found that this technique has become more sophisticated and risen to be present in 55% of phishing emails this year, increasing from 24% last year.
According to the report, the most common phishing topic was missed voice messages, where the attacker uses HTML smuggling to hide their payload.
The report also points out that although the overall volume of phishing has not increased, more emails are getting through traditional parameter detection.
The amount of emails that got through Microsoft’s defences, for instance, has increased 25% between 2022 and 2023, and the amount of emails that get through secure email gateways has increased by 29% in the same period.
Recommended reading
- Gartner: Only 8% of Customers Using Customer Service Chatbots
- Comment: Customers Don’t Want Chatbots, and Here’s Why
- EU Creates ChatGPT Task Force to Keep Up with AI Developments
This is due largely to the 11% increase in attacks being sent from compromised accounts, which accounted for almost half (47%) of Microsoft’s missed detections.
“Legacy approaches to email security rely heavily on quarantine barring end users from seeing phishing emails, but as our report highlights, phishing emails will inevitably get through,” said Chapman.
“If you’re relying on traditional perimeter detection that uses signature-based and reputation-based detection, then you urgently need to evaluate integrated cloud email security solutions that don’t rely on definition libraries and domain checks to determine whether an email is legitimate or not.”
This report comes on the heels of the 20th annual Cybersecurity Awareness Month. This year’s theme is “Secure Our World,” which the Cybersecurity & Infrastructure Security Agency says “will also be the enduring theme for throughout the year as we work to drive behavioural change around core cybersecurity habits by providing everyone with the knowledge and tools they need.”





