“Thanks to AI, the historic signals that exposed a phishing email – poor grammar, misspelt words – are now ironed out and replaced with perfect language,” notes Dave Baggett, SVP Cybersecurity with software developer Kaseya.
The FBI’s numbers: scale and escalation
Phishing is no niche problem. According to the Federal Bureau of Investigation, some 26 percent of all cybercrime complaints they receive are now phishing-related. The consequences are measurable: the FBI data cited in the source show losses from phishing attacks have risen 274 percent in the last couple of years. Those figures frame an urgent shift — an old technique becoming vastly more damaging as its mechanics change.
How Generative AI rewrites the playbook for attackers
Generative AI and Large Language Models (LLMs) have removed constraints that once limited phishers. Where poor grammar, clumsy tone and amateurish formatting were once reliable cues, LLMs now produce polished, contextual text in any language and can pair it with realistic brand graphics and convincing web addresses. Threat actors can use GenAI to automate highly tailored messages at scale — blurring the line between broad campaigns and individual “spear phishing.”
The source describes practical tactics: attackers can set GenAI to scour LinkedIn for recent hires and then impersonate a new manager to “groom” a target over multiple emails, culminating in urgent wire-transfer requests or casual demands for payroll data or passwords. Those attack chains frequently rely on human trust and social engineering rather than malware-laden attachments, allowing messages that are technically clean to bypass traditional filters.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAsymmetry highlighted by Kaseya: costs and defensive trade-offs
Dave Baggett frames a core asymmetry: attackers can use frontier LLMs “basically for free” to craft perfect phishing templates, while defenders face prohibitive costs if they tried to run every inbound email through the same models. Baggett estimates that doing so would be about 100x too expensive. That cost delta forces defenders to consider alternatives: smaller, distilled models tuned for specific signals; routing only a subset of inbound messages through large models; or combining LLMs with other analytic tools.
Baggett also raises the possibility that, over time, inference will get cheaper and allow higher-percentage LLM inspection — but he notes that may not be achievable for some years. He warns of a future risk too: attacker tooling could evolve from human-designed campaigns to agentic models that plan and supervise attacks at scale.
Defensive toolbox: AI, vision, sender analysis, and targeted LLM use
Defenders are not without options. The source sketches a layered defensive approach that shifts emphasis from spotting typos to modelling intent and behavior. Tactics include using compact models tuned to sentiment or meaning, computer vision to analyze images, sender analysis to verify origins, and linked-content inspection to examine embedded URLs without triggering threats. Baggett suggests admins could be given the ability to route particular suspicious messages through a frontier LLM trained on critical email-security aspects.
The article names practical, available products: INKY Smart Insights uses GenAI to reduce manual email investigations to seconds of automated triage and translates technical indicators into plain-language verdicts. Kaseya Intelligence is cited as a complementary toolset that can support decision-making across broader security environments. According to Baggett, Smart Insights “will identify problems and give a narrative explanation of its reasoning” in an accessible way — a feature pitched as valuable to MSPs and non-expert administrators.
How MSPs, security administrators, and end users are affected
- MSPs: Must be alert on behalf of customers who lack in-house expertise; tools like Smart Insights can let MSPs deliver LLM-level sophistication without proportional overhead.
- Security administrators: Face trade-offs between cost and coverage; options include using distilled models, selective routing of messages to frontier LLMs, and enhancing admin workflows to reduce alert fatigue.
- End users (employees): Remain the primary target of social-engineering tactics — particularly “green” employees who have just changed jobs and may be vulnerable to impersonation scams discovered via LinkedIn scouting.
The war on GenAI-powered phishing is far from won, but the article closes on a pragmatic note: defenders who understand where and how to apply smarter tools — smaller models, targeted LLM use, computer vision and clearer user-facing context — can blunt the advantage attackers currently enjoy. Kaseya’s summit is offered as a forum for further discussion.




