AI-driven phishing: why inbox training is no longer enough
For a decade, awareness training leaned on surface cues: broken grammar, mismatched branding, urgency written in a second language. Generative models erased all three. In the samples our research lab collected this quarter, more than four in five credential-harvesting emails were fluent, contextually accurate and referenced real internal projects scraped from public sources.
The practical consequence is that recognition-based training decays fast. What holds up is process: out-of-band verification for payment and credential changes, phishing-resistant authentication, and a reporting path that is faster to use than the malicious link is to click.
In our Ethical Hacking & Cybersecurity Essentials bootcamp we now run a full module on adversarial content generation — students build the lure, then build the control that defeats it. Understanding both sides is the only durable way to stay ahead of a tool that improves every month.
REY Research Lab
This note comes from the REY Cyber Forensics & Cybersecurity Research Lab, where our training programs and casework are developed.