Cybercriminals are increasingly using AI chatbots to create phishing emails , and this has caused huge concern, as it has been found that phishing emails created through AI are almost impossible to detect.

According to a new report from security firm Egress ( Phishing Threat Trends Report ), artificial intelligence detectors cannot tell whether a phishing email has been written by a chatbot or a human, in three out of four cases (71.4%).
This has to do with the way AI detectors work. Most of these tools are based on large language models (LLMs). Their accuracy increases with the size of the samples. Typically, they require at least 250 characters to work properly.
However, almost half (44.9%) of phishing emails do not meet the 250-character requirement and a further 26.5% fall below 500, meaning that AI detectors attacks. currently do not work reliably on 71.4% of
See also: AtlasCross Group: Using the American Red Cross as a phishing lure
HTML Smuggling: The leading obfuscation technique
The Egress report also addresses other factors in phishing. The researchers found that human-generated phishing emails are also becoming increasingly difficult to detect, due to a 24.4% increase in obfuscation techniques used.
These techniques have also evolved, with nearly half (47%) of threat deploying two layers of obfuscation and less than a third (31%) using only one technique.
The most popular technique is HTML Smuggling , where legitimate HTML5 and JavaScript features are exploited to encode and embed malicious code into HTML files or web pages

Additionally, Egress found that 34% of its mail flow can be categorized as “graymail,” which the company describes as “bulk emails , such as notifications, updates, and promotional messages.” These make it harder for phishing detectors to detect, and recipients are more likely to click on such a phishing email because they don’t realize it’s dangerous.
See also: Phishing attacks against Celsius Network Creditors intensify
Phishing emails bypass security defenses
Phishing emails generated by AI and the evasion techniques they use are making it increasingly difficult to detect dangerous messages. Although the number of phishing attacks has not increased, the number of emails that bypass security defenses is increasing.
For example, emails that evaded Microsoft defenses increased by 25% in 2023 compared to 2022. Those that evaded secure email gateways (SEGs) increased by 29% over the same period.
Jack Chapman, Egress' Vice President of Threat Intelligence, said these findings should prompt us to change our approach to anti-phishing.
“Legacy approaches to email security rely heavily on quarantine, which prevents end users from seeing phishing emails, but as our report highlights, some messages will inevitably get through. That’s one of the reasons we added banners to neutralize threats in the inbox. These banners are designed to clearly explain the riskin a way that’s easy to understand, acting as a lesson for user education. Ultimately, teaching someone to take the bait is a more sustainable approach to long-term resilience,” he commented.
See also: Should employees who constantly click on phishing emails be fired?

Phishing emails have become a growing problem as cybercriminals exploit artificial intelligence and more advanced techniques to bypass security systems. Different obfuscation techniques, such as HTML Smuggling, make it even more difficult to detect malicious messages.
Protection methods (especially for businesses):
- Informing staff about new threats and training with test phishing attacks.
- Monitoring and protection of endpoints.
- Restrict access to critical systems ( only those who absolutely need to have access to critical systems should have access)
- Network segmentation
Source: www.infosecurity-magazine.com
