I recently gave an agentic AI system a single instruction: research online, then write an email that would get me talking about my job. I gave it no script, no target list, and not one detail about myself. Everything it needed, it went and found.

About a minute later, a message from “Max Carter, Cybersecurity Product Research” landed in my inbox, inviting me to take part in a benchmarking study. It was courteous, accurate about my background, made no demands, and explicitly promised not to ask for anything confidential. It also asked six questions I would have had to be very careful about answering. I’ve reproduced the whole thing further down. First, the reason it worked.

Remember the old advice by security professionals for spotting phishing emails? “Just look for bad grammar,” or “if it’s generic, it’s probably fake,” they’d say. But today, that doesn’t hold up. Attackers can now generate flawless, recipient-tailored content in seconds thanks to AI-powered phishing.

These emails are often free from grammatical errors and personalized to seem relevant. Even worse, they’re easy to scale. Attackers can create and drop thousands of these messages into inboxes with one click.

Security awareness training still plays a massive role. But it’s only a baseline and can’t shoulder the full burden of defense, since a typical inbox is flooded with phony emails and fraudulent requests. Technology, such as stronger detection, monitoring, and response capabilities, counters these threats, catching what slips past even vigilant employees.

What Happened When I Gave an AI Agent One Instruction

That list above describes the ingredients. I wanted to see how hard it actually is to assemble them, so I ran the experiment on myself.

In plain English; no code, no phishing kit, no technical skill of any kind. I told an agentic AI system to email me, to research me first using public sources like LinkedIn, to hold a business conversation, and to introduce itself under a name that would read as a real person rather than a bot. That was the entire brief. I never told it who I was, what I do, what pretext to use, what to ask for, or how to sound.

Below is the message I received minutes later from an email address at a registered domain.

Read it again with a security eye. Almost every sentence in that message is doing a job.

  • There is nothing to click. No link. No attachment. No payload. There is nothing for a secure email gateway to sandbox, no domain to reputation-check, and no malware to detect. The request is the attack, and the compromise happens the moment I hit reply.
  • It chose its own pretext, and it chose a good one. I never told it to pose as a researcher. It landed on a benchmarking study, a format security and product leaders receive constantly, agree to routinely, and associate with professional generosity rather than risk.
  • It offers to pay me back. “I’ll return a concise summary of the themes and observations” turns an extraction into an exchange. The anonymized summary promise does similar work: it signals discretion and quietly implies that other respected people are already participating.
  • It did the reconnaissance itself and got it right. Current role, prior functional background, and the topics I engage with publicly, all pulled from open sources without being asked. Accuracy here is not decoration. It is evidence that a real person spent real time on me, which is precisely what earns a reply.
  • It disarms the security objection before I can raise it. “I am not requesting confidential roadmap, customer, vendor, or internal organizational information.” Nobody taught it that move. And look at what is still fair game after that sentence: how decisions actually get made, which problems drive investment, whose feedback carries weight, and what the organization treats as success. That is the intelligence, and the disclaimer is what makes handing it over feel safe.
  • There is no urgency at all. No deadline, no pressure, no consequence for ignoring it. Just “if you are open to participating.” Manufactured urgency is the single most-trained phishing red flag in existence, and this message simply declines to use it. Patience costs an automated system
  • It asks for opinions, not facts. “Where do you see more hype than substance” is an invitation to be candid, and candid people volunteer more than they intended to. The final question asks about my career history, which builds rapport rather than gathering data, the sort of thing you include when you want a relationship, not a single answer.
  • One control fired, and it was not enough. The external-sender banner did its job. It also appears on nearly every legitimate vendor note, customer thread, and newsletter that reaches me, which is exactly why it has stopped carrying signal. Below the banner, an AI assistant had already summarized the message into something even easier to act on.

But the email itself is not the story. The arithmetic behind it is.

From instruction to delivered message took roughly a minute of my time. Not a minute of compute, a minute of human effort, most of it spent typing the request. There was no infrastructure to stand up, no template to buy, no target research to commission, and no requirement that the sender write well or even speak fluent English. The same instruction, with one name swapped, runs against every employee on a public org chart. The target list is free, and it is already online.

Agentic systems also do not stop at drafting. The same loop that researched me and wrote that message can send it, read my reply, and compose an informed follow-up that references whatever I just volunteered, then keep going, patiently, for as long as I keep responding. The message above is deliberately the opening of a relationship rather than a single ask, and nothing about that approach requires a human to be present. It can be running with a thousand people at once, each thread developing independently.

Phishing used to force attackers into a trade-off: high volume with low quality, or high quality with low volume. Crafting a genuinely convincing, well-researched, patiently played message cost real hours, which capped how many people could receive one. That constraint is gone. Speed, scale, and quality now arrive together, and they arrive for attackers whose only skill is describing what they want.

So, hold that email up against the awareness training checklist. Bad grammar? Flawless. Generic greeting? My name, my role, and my actual background. Suspicious link or attachment? Neither. Unrealistic urgency? None whatsoever. It explicitly leaves the decision to me. Asking for money, credentials, or confidential data? It goes out of its way to say it is not. Unexpected external sender? Yes, and that is the only box it ticks, alongside the legitimate mail I receive all day. Which rule is supposed to catch Max Carter?

Why AI-Powered Phishing is Harder for Employees to Spot

Just look at your email inbox over the last few months. You’ll notice a lot more messages just appear more legit, even ones you know are fake. That’s not by accident.

AI has shed the clumsy tells that once made it easy to identify. And according to the ENISA 2025 Threat Landscape report, AI-powered phishing accounts for over 80% of global social engineering activity.

Those emails with poor writing and awkward formatting became polished and mirrored legit company communications.

The generic tones that sounded like a memo and didn’t address you directly became your company’s voice, referencing actual projects or team members.

And those obvious punctuation errors and odd capitalization were replaced with natural, human-sounding sentences that seemed authentic.

Attackers use large language models (LLMs) to study targets and create more convincing phishing messages. AI finds how targets speak, their topics, and their keywords so that attackers can generate persuasive content. Hence, the old awareness methods no longer work.

How AI Phishing Attacks Use Personalization to Increase Trust

AI has supercharged social engineering. Attackers can collect pools of information, analyze them, and apply them to their phishing campaigns. For example:

  • Public information: Scraped from social media and websites to reference real job titles, projects, or connections.
  • Breached data: Purchased credentials or personal details used to address you by name or reference past interactions.
  • Role-specific details: Tailored to your department, so finance sees invoices, HR sees benefits requests, etc.
  • Account or vendor references: Familiar supplier logos, contract numbers, or software and providers you use make fakes look real.
  • Executive context: CEO or manager impersonation using bios and recent company news to push urgent requests.

This personalization makes messages feel credible. Victims are more likely to fall for the request. AI phishing attacks are done at scale. So, cybercriminals are winning at scale, especially in AI-generated spear phishing.

Why Awareness Training Cannot Carry the Full Burden

Humans are vulnerable. Even your most careful, well-trained employee will read emails while rushed or multitasking. So, they can easily be caught off guard by the sheer volume and quality of AI-powered phishing messages.

As noted in joint guidance from NSA, CISA, and FBI, threats can stem from “large-scale data collected and curated by third parties.” This magnifies the risk. Cybercriminals can collect tons of useful data relatively quickly and easily for targeted phishing. Done in the thousands; the damage is amplified.

FBI reports on AI data security showed AI cybercrime cost U.S. victims about $893 million last year. The biggest cause was “AI-enabled synthetic content,” so convincing that it couldn’t be detected by the 22,000 individuals and businesses who fell victim.

There is a harder problem underneath the volume, too. Awareness training teaches people to protect credentials, money, and confidential files. It does not teach them that how their organization makes decisions is also an asset — that naming the problems driving investment, the feedback that carries weight, and the measures of success hands an outsider a map. Max Carter asked for none of the protected categories and all of the unprotected ones, and a helpful employee having a normal professional day would have answered.

It’s why organizations need to shift their strategy. Phishing detection and other technical controls can catch the threats that inevitably slip past human oversight.

What Security Teams Should Monitor Beyond the Inbox

AI cyber threats are smart. Employees downloading files or reading phony emails is inevitable. But you can track activity post-click. Here’s what to monitor:

  • Unusual logins: Did an employee log in from an unfamiliar location or device? Are they accessing the system at off-hours that don’t match their normal schedule?
  • Suspicious mailbox rules: Did someone create a rule to forward emails externally or automatically delete certain messages? Inbox rules could be added to hide evidence of a breach.
  • Credential usage: Is a single account being used from multiple geographic locations simultaneously? Are credentials being used or changed to access systems the employee doesn’t normally use?
  • Endpoint and account activity: Are files being downloaded in bulk or renamed in unusual patterns? Is there new admin activity or changes to privileged accounts without explanation?

Unfamiliar external correspondents: Is an employee exchanging substantive replies with a brand-new external domain that has no history with your organization, no matching customer or vendor record, and no other recipients inside the company? Sustained one-to-one threads with an unknown sender are worth a look even when nothing was clicked.

Phishing detection can go beyond the inbox. These behavioral indicators are often the first sign of a successful compromise.

How MDR Services Help Detect the Activity That Follows Successful Phishing

Managed detection and response (MDR) services let you go beyond the inbox and gain complete visibility across your identities and endpoints. Activity is monitored 24/7, so you can spot whether a phishing attack has spiraled into a breach.

If identified, MDR can triage alerts to notify the team of an incident, plus distinguish genuine threats from false positives. Experts also offer response support to contain threats, minimizing potential damage.

Email should be part of that same MDR coverage, not a separate tool bolted on. A well-built MDR for Email layer pairs AI-driven detection with inline blocking to stop email-based attacks before they land, while automated user report investigations cut response time significantly. Legitimate business email keeps moving instead of getting flagged as a false positive. And when something does get through, the response doesn’t stop at the alert. The team investigates blast radius, validates containment, and remediates to confirm the compromise didn’t spread past the inbox.

That visibility matters most in the cases where there was never a click to begin with. When the opening message only collects information, the damage surfaces later, in the follow-up that lands with impossible specificity, in the login that arrives already knowing the right context, in the invoice that references a real project. Correlating identity, endpoint, and email activity over time is how that sequence gets caught while it is still a sequence.

MDR services catch the post-click activity most employees can’t see. Because human intuition isn’t enough to combat AI-powered phishing.

AI-Powered Phishing Requires Awareness and Detection

Awareness training still matters. But AI-powered phishing has raised the bar by enabling higher-quality email content to be sent at scale. Phishing detection needs more.

MDR services supplement a robust awareness program. They let you monitor what might happen after an employee clicks an email link. Unusual login? Spotted and access removed. Odd inbox rule added? Detected and reversed.

It took me one sentence and about a minute to produce a message polished enough that I read every word of it in my own inbox, warning banner and all — and I knew it was coming. Anyone can run that experiment, and plenty of people already are, at a scale and a patience no training program can outpace. Assume the convincing email will arrive and build the detection that catches what happens next.

Stay vigilant with powerful technical defenses and withstand these modern AI threats.