Skip to main content
Emerging ThreatsMalware & Ransomware

MSPs Face Evolving Phishing Threats from AI-Driven Attacks

Concerned office worker scrutinizes a paper at their cluttered desk.

"AI has changed phishing from a filtering problem into a detection problem," Kaseya warns — and the numbers the vendor cites explain why that warning has teeth.

How AI reshapes every stage of a phishing campaign

The anatomy of a phishing attack has not changed; AI has accelerated and refined each step. Kaseya lays out a four-stage path where AI helps attackers move faster and more convincingly: reconnaissance, content generation, delivery and evasion, and rapid post‑compromise activity.

On reconnaissance, attackers use large language models to scan LinkedIn, company websites and other public sources to assemble a target profile within minutes — who they work with, what projects they're on, and how they communicate. That public information feeds content generation: AI produces personalized, contextually relevant messages free of the typos and awkward phrasing that once made phishing easier to spot. Harvard Business Review data cited in the report found AI‑generated spear phishing campaigns achieved a 54% click‑through rate, matching human experts at a fraction of the cost.

Polymorphic phishing: delivery tactics that defeat signature‑based filters

AI enables polymorphic phishing, creating unique versions of each email by altering subject lines, sender details, formatting and content. Attackers also exploit trusted cloud services, QR codes and redirect chains to get past traditional gateways. Because signature and indicator‑based detection depend on reuse and repeatability, Kaseya argues, those techniques become far less effective when every message is different and continuously changing.

When an attacker succeeds, damage unfolds rapidly: stolen session tokens, mailbox rules that hide malicious activity, and lateral movement through a client environment can begin within minutes.

Behavioral detection: what to monitor beyond the inbox

AI can make messages look legitimate, but it cannot erase the identity, endpoint and user behaviors that follow a successful compromise. Kaseya recommends shifting detection from email content to post‑delivery activity and lists concrete signals to watch for:

  • New forwarding or mailbox rules that send messages to an external address, especially immediately after a login from an unfamiliar location.
  • Impossible travel — the same account logging in from two different countries within minutes.
  • Repeated multifactor authentication prompts the user did not initiate, often a sign of MFA fatigue or push bombing.

Correlating identity, email and endpoint signals is central. Examples Kaseya highlights include a user signing in from a trusted device whose endpoint then launches PowerShell scripts, a successful login immediately followed by attempts to access applications or data the user never used before, or a sudden spike in outbound emails from an account that normally sends only a few internal messages each day.

Detect faster, respond sooner: automated correlation and containment

Time matters. Kaseya urges MSPs to automatically flag and investigate suspicious account activity before attackers can move laterally, to isolate compromised endpoints to stop malware spread, and to disable compromised accounts or terminate active sessions to limit data access. Automated threat correlation that connects signals across email, identities and endpoints both speeds detection and reduces alert fatigue, the report says.

The business stakes are explicitly spelled out: according to IBM's 2024 Cost of a Data Breach Report, phishing accounted for 16% of incidents and cost organizations an average of $4.8 million per breach — a practical reminder that prevention and post‑delivery detection must work in concert.

What this means for MSPs, technologists and end users

  • Managed service providers (MSPs): Treat inboxes as only the first line of defense. Kaseya urges MSPs to adopt behavioral analytics, identity monitoring and rapid response playbooks that detect active compromises before they escalate into client‑wide breaches.
  • Technologists and security teams: Invest in automated threat correlation across email, identity and endpoints and prioritize reducing detection and containment time — not just ticket resolution metrics — because every minute matters after credentials are exposed.
  • End users and business leaders: Change habits that attackers exploit. Kaseya recommends verifying high‑risk requests by phone or a separate channel for wire transfers, credential resets, and vendor payment changes; that single habit stops most business email compromise attempts, the report asserts.

Practical steps MSPs can implement this week

Kaseya lists immediate actions that map directly to the threats it describes: modernize security awareness training to mirror AI‑quality phishing simulations rather than outdated, typo‑filled templates; require out‑of‑band verification for high‑risk requests; monitor mailbox rules, unfamiliar logins, impossible travel and MFA prompts after delivery; and measure response time — how long it takes to detect and contain a suspected compromise — as a key operational metric.

AI has made phishing cheaper to produce and harder to spot, but it cannot hide the behavioral traces attackers leave once they succeed. MSPs that pair modernized user training with behavioral monitoring, automated correlation across identity and endpoints, and speedier containment stand the best chance of preventing a single convincing message from becoming a multi‑million‑dollar breach.

Source: How MSPs can catch phishing attacks email filters miss — Kaseya (via BleepingComputer)