threat_intelligence1259 wordsRead on Arc Codex

How MSPs can catch phishing attacks email filters miss

Your clients receive thousands of emails every day, but all it takes is one convincing message to turn a seemingly harmless email into a security incident you will be responsible for cleaning up. AI has fundamentally changed phishing, making it easier to launch, harder to detect and far more convincing than traditional email filters were built to stop. With a large language model and a few publicly available LinkedIn profiles, attackers can generate highly personalized phishing emails in minutes. Harvard Business Review found that AI-generated spear phishing campaigns achieved a 54% click-through rate, matching those of human experts at a fraction of the cost. Understanding how these attacks work and why traditional filters struggle to stop them is essential to protecting clients before a single email becomes a costly breach. Inside an AI-powered phishing campaign Every AI-assisted phishing campaign follows the same basic path. AI simply makes each stage faster, more convincing and much harder for traditional defenses to detect. Reconnaissance: AI finds the right target Attackers use AI to scan LinkedIn, company websites and other public sources to build a profile of a specific employee. Within minutes, they know who that person works with, what projects they're involved in and how they communicate. Why this matters for MSPs: Public information gives attackers everything they need to create a believable phishing email before it ever reaches your client's inbox. Content generation: AI writes an email that looks legitimate AI uses that information to create an email that appears to come from a trusted colleague, customer or vendor. Every message is personalized, contextually relevant and free of the spelling mistakes or awkward phrasing that once made phishing easy to spot. Why this matters for MSPs: The biggest challenge is no longer identifying obvious phishing emails. It's protecting clients from messages that look and read like legitimate business communication, making users far more likely to trust them. Delivery and evasion: The email gets through AI also helps attackers evade detection by creating a unique version of every email — a technique known as polymorphic phishing. It continuously changes subject lines, sender details, formatting and content, while using trusted cloud services, QR codes and redirect chains to bypass traditional filters. Why this matters for MSPs: Traditional email gateways rely heavily on signatures and known indicators of compromise. When every email is different and constantly changing, those indicators become far less reliable, allowing more phishing emails to reach your clients. Post-compromise activity: The damage happens fast If a user clicks a malicious link or enters their credentials, the attack escalates quickly. Attackers can steal session tokens, create mailbox rules to hide their activity and begin moving through the client's environment within minutes. According to IBM's 2024 Cost of a Data Breach Report, phishing is the leading cause of data breaches, accounting for 16% of incidents and costing organizations an average of $4.8 million per breach. Why this matters for MSPs: By the time a phishing email reaches the inbox, prevention alone is no longer enough. Protecting clients requires visibility beyond email, with endpoint detection, identity monitoring and rapid response working together to stop attackers before they can expand their access. 2026 Kaseya Email Security Report: AI, Phishing & Emerging Threats Explore the latest phishing trends and AI-driven email threats. Learn practical strategies to strengthen your email security. Download Kaseya's 2026 Email Security Report to learn about this year's emerging cybersecurity threats. Download NowWhat catches an AI-generated attack AI can disguise a phishing email, but it can't disguise the identity, endpoint and user activity that follows. That's where modern detection makes the difference. Monitor behavior, not just emails Every successful phishing attack leaves signs that something isn't right. Instead of just examining the email, monitor for unusual account and user activity, such as: - A new forwarding or mailbox rule, which sends messages to an external address, especially immediately after a login from an unfamiliar location. - Impossible travel, where the same account logs in from two different countries within minutes. - Repeated multifactor authentication prompts that the user didn't initiate, often indicating MFA fatigue or push bombing. Behavioral analytics and anomaly detection help surface these warning signs, even when the phishing email appears completely legitimate. Correlate activity across the environment A single suspicious login or endpoint alert may not mean much on its own. But when identity, email and endpoint activity are correlated, it becomes much easier to recognize an active phishing attack before it escalates. Look out for: - A user signing in from a trusted device, but the endpoint immediately begins launching PowerShell scripts or other unusual processes. - A user successfully logging in, then immediately attempting to access systems, applications or data they've never used before. - A sudden spike in outbound emails from an account that normally sends only a handful of internal messages each day. Automated threat correlation connects these signals across email, identities and endpoints, helping MSPs identify active phishing attacks faster while reducing alert fatigue. Detect faster, respond sooner The sooner an attack is detected, the less opportunity an attacker has to expand their access. Once credentials are compromised, every minute counts. - Automatically flag and investigate suspicious account activity before attackers can move laterally. - Isolate compromised endpoints to stop malware from spreading. - Disable compromised accounts or terminate active sessions before additional data is accessed. Faster detection and response reduce attacker dwell time, improves incident response efficiency and helps MSPs contain phishing attacks before they become costly breaches for their clients. | Traditional email gateway | Modern phishing defense | | Blocks known malicious senders and links | Detects suspicious identity, email and endpoint activity | | Focuses on threats before delivery | Continues monitoring after delivery | | Relies on known phishing signatures | Detects account compromise, session hijacking and lateral movement | | Prevents malicious emails | Detects, contains and responds to active attacks | What MSPs can do this week Here are practical steps MSPs can take to reduce risk and strengthen their clients' defenses - Modernize security awareness training: Run phishing simulations that look like what AI produces now, not the misspelled, generic templates from five years ago. Training built on old examples teaches people to watch for the wrong thing. - Verify high-risk requests: Require a phone call or a separate channel to confirm any wire transfer, credential reset, or vendor payment change, no matter how convincing the email looks. This one habit stops most business email compromise attempts cold, because it doesn't rely on anyone spotting anything. - Monitor account activity after delivery: Don't stop at the inbox. Monitor for suspicious mailbox rules, logins from unfamiliar locations, impossible travel and repeated MFA prompts. These behaviors often provide the earliest indication that an account has been compromised. - Measure response time, not just resolution time: Measure how long it takes to detect and contain a suspected compromise. Treat that number with the same weight as ticket resolution time. A faster response window is what limits the damage once a phishing email gets past the gateway, and one eventually will. AI changed phishing. MSPs need to change their defenses AI has changed phishing from a filtering problem into a detection problem. As phishing attacks evolve, the advantage belongs to MSPs that can detect and respond before a compromised inbox becomes a client-wide breach. Download the 2026 Kaseya Email Security Report to learn how modern phishing attacks bypass legacy defenses and the strategies MSPs are using to stay ahead. Sponsored and written by Kaseya. Comments have been disabled for this article.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.