/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

IBM Research says AI can make phishing, already used in ~90% of cyberattacks, more effective at scale, although the team has not yet detected widespread use

Phishing attacks are already devastatingly successful.  What happens when artificial intelligence makes them even harder to spot?

The Messenger Eric Geller

Context & Ripple Effects

IBM Research identifies phishing as a dominant entry point in cyberattacks and flags generative AI as a way to increase the volume and quality of social-engineering attempts, while stressing that broad adoption had not yet been observed.

The warning fits later coverage of more personalized phishing aimed at corporate executives and a wider AI-driven contest between attackers and defenders. It matters because phishing is a distribution problem: small gains in credibility or targeting can be applied across many potential victims.

First-order effects

  • Security teams face pressure to treat polished, tailored phishing as a growing risk scenario even before IBM sees widespread AI-enabled campaigns.
  • Attackers that adopt AI can reduce the effort required to draft and vary lures, potentially making familiar email-based defenses less reliable against higher-volume targeting.

Second-order effects

  • Email-security vendors and corporate defenders will need to emphasize behavioral signals, authentication controls, and user verification rather than relying chiefly on obvious writing flaws in suspicious messages.
  • Higher-quality impersonation attempts can shift more security spending toward executive protection and identity-focused defenses, consistent with reports of personalized executive phishing.

Third-order effects

  • If AI-assisted phishing becomes routine, social engineering may industrialize into an iterative attacker-defender cycle, with both sides applying AI to generate, detect, and adapt campaigns.
  • The durable constraint may shift from producing convincing messages to controlling trusted identities and verification channels; the pace of that shift remains uncertain because IBM had not detected widespread use at the time.

The trend: This is one early signal of AI industrialization in cybersecurity, where automation lowers the cost of both offensive targeting and defensive response.

Discussion

  • @ericgeller Eric Geller on x
    Phishing attacks are wildly successful. AI is likely to make them even more effective. My new feature, part of a package of spooky stories published today in @TheMessenger, explores what these smarter attacks will look like and how we'll have to respond. https://themessenger.com/…