AI-Written Phishing

AI-Written Phishing

The spelling is perfect. That is the problem.

What Is AI-Written Phishing?

Phishing text is now generated from whatever your company already publishes, so it arrives with no spelling mistakes, the right project name and your manager's own sign-off. In this exercise you watch a campaign being built from two public pages, then receive it yourself by email and by text. You practise judging the request rather than the writing, verifying on a channel you already had, and reporting the half your mail client cannot see.

What You'll Learn in AI-Written Phishing

AI-Written Phishing — Training Steps

  1. Somebody Else's Team Page

    Bob is after Ilverstone Logistics, a freight forwarder with a supplier portal its operations desk signs into every day. He does no scanning and breaks into nothing. He starts with the part of the company that is already published.

  2. Forty-Six Names and a Pattern

    The directory is there so carriers and suppliers can reach the right person. It also hands a stranger the whole department.

  3. How He Writes

    Daniel Okafor posts a department update most Thursdays. The latest one is linked from his own team page.

  4. Project Lantern, and Onwards, D.

    Four hundred words of internal detail, published because it is genuinely useful to customers and carriers. Bob reads it as a specification.

  5. The Studio

    Bob does not write the lure. He rents a service that does, priced per campaign, with the delivery list and the collector built in.

  6. Add the Second Channel

    Email alone gets read and ignored. A text from a different number, arriving half an hour later about the same thing, makes the email feel answered for.

  7. Feed It the Profile

    Everything the brief needs came off two public pages, and none of it took longer to collect than reading this step.

  8. Read What It Wrote

    It takes about four seconds. There is no broken English to notice, because no part of this was written by somebody working in a second language under time pressure.

  9. Launch

    Ninety-two messages to forty-six people, on two channels, from a domain registered yesterday. The whole job has taken Bob about twenty minutes.

  10. Everything Delivered

    Nothing bounced and nothing was filtered. The sending domain has no history at all, which is exactly why no reputation system has anything bad on it yet.

Security Framework Coverage

MITRE ATT&CK

  • T1566.002 Phishing: Spearphishing Link
  • T1566.003 Phishing: Spearphishing via Service
  • T1598.003 Phishing for Information: Spearphishing Link

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind