Close Menu
NCIJ Network NCIJ Network
    What's Hot

    New leadership initiative carries on legacy of late Indonesian environmental activist

    August 20, 2026

    Lack of water storage is an urgent national security issue | Water

    August 20, 2026

    Togo charges two French journalists over incorrect documents, rights group says

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New leadership initiative carries on legacy of late Indonesian environmental activist
    • Lack of water storage is an urgent national security issue | Water
    • Togo charges two French journalists over incorrect documents, rights group says
    • Novak Djokovic documentary: Tennis great on being ‘my own biggest doubter’ and childhood that shaped his career
    • Reform UK proposes tax rebates for firms to boost apprenticeships
    • FBI Agents Search Eric Swalwell’s Home as Part of Federal Inquiry
    • ‘Treasury demand has become materially more valuation-sensitive’
    • It’s Greg Brockman’s OpenAI now
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    How MSPs can catch phishing attacks email filters miss

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Your clients receive thousands of emails every day, but all it takes is one convincing message to turn a seemingly harmless email into a security incident you will be responsible for cleaning up.

    AI has fundamentally changed phishing, making it easier to launch, harder to detect and far more convincing than traditional email filters were built to stop.

    With a large language model and a few publicly available LinkedIn profiles, attackers can generate highly personalized phishing emails in minutes. Harvard Business Review found that AI-generated spear phishing campaigns achieved a 54% click-through rate, matching those of human experts at a fraction of the cost.

    Understanding how these attacks work and why traditional filters struggle to stop them is essential to protecting clients before a single email becomes a costly breach.

    Inside an AI-powered phishing campaign

    Every AI-assisted phishing campaign follows the same basic path. AI simply makes each stage faster, more convincing and much harder for traditional defenses to detect.

    Reconnaissance: AI finds the right target

    Attackers use AI to scan LinkedIn, company websites and other public sources to build a profile of a specific employee. Within minutes, they know who that person works with, what projects they’re involved in and how they communicate.

    Why this matters for MSPs: Public information gives attackers everything they need to create a believable phishing email before it ever reaches your client’s inbox.

    Content generation: AI writes an email that looks legitimate

    AI uses that information to create an email that appears to come from a trusted colleague, customer or vendor. Every message is personalized, contextually relevant and free of the spelling mistakes or awkward phrasing that once made phishing easy to spot.

    Why this matters for MSPs: The biggest challenge is no longer identifying obvious phishing emails. It’s protecting clients from messages that look and read like legitimate business communication, making users far more likely to trust them.

    Delivery and evasion: The email gets through

    AI also helps attackers evade detection by creating a unique version of every email — a technique known as polymorphic phishing. It continuously changes subject lines, sender details, formatting and content, while using trusted cloud services, QR codes and redirect chains to bypass traditional filters.

    Why this matters for MSPs: Traditional email gateways rely heavily on signatures and known indicators of compromise. When every email is different and constantly changing, those indicators become far less reliable, allowing more phishing emails to reach your clients.

    Post-compromise activity: The damage happens fast

    If a user clicks a malicious link or enters their credentials, the attack escalates quickly. Attackers can steal session tokens, create mailbox rules to hide their activity and begin moving through the client’s environment within minutes.

    According to IBM’s 2024 Cost of a Data Breach Report, phishing is the leading cause of data breaches, accounting for 16% of incidents and costing organizations an average of $4.8 million per breach.

    Why this matters for MSPs: By the time a phishing email reaches the inbox, prevention alone is no longer enough. Protecting clients requires visibility beyond email, with endpoint detection, identity monitoring and rapid response working together to stop attackers before they can expand their access.

    Explore the latest phishing trends and AI-driven email threats. Learn practical strategies to strengthen your email security.

    Download Kaseya’s 2026 Email Security Report to learn about this year’s emerging cybersecurity threats.

    Download Now

    What catches an AI-generated attack

    AI can disguise a phishing email, but it can’t disguise the identity, endpoint and user activity that follows. That’s where modern detection makes the difference.

    Monitor behavior, not just emails

    Every successful phishing attack leaves signs that something isn’t right. Instead of just examining the email, monitor for unusual account and user activity, such as:

    • A new forwarding or mailbox rule, which sends messages to an external address, especially immediately after a login from an unfamiliar location.
    • Impossible travel, where the same account logs in from two different countries within minutes.
    • Repeated multifactor authentication prompts that the user didn’t initiate, often indicating MFA fatigue or push bombing.

    Behavioral analytics and anomaly detection help surface these warning signs, even when the phishing email appears completely legitimate.

    Correlate activity across the environment

    A single suspicious login or endpoint alert may not mean much on its own. But when identity, email and endpoint activity are correlated, it becomes much easier to recognize an active phishing attack before it escalates. Look out for:

    • A user signing in from a trusted device, but the endpoint immediately begins launching PowerShell scripts or other unusual processes.
    • A user successfully logging in, then immediately attempting to access systems, applications or data they’ve never used before.
    • A sudden spike in outbound emails from an account that normally sends only a handful of internal messages each day.

    Automated threat correlation connects these signals across email, identities and endpoints, helping MSPs identify active phishing attacks faster while reducing alert fatigue.

    Detect faster, respond sooner

    The sooner an attack is detected, the less opportunity an attacker has to expand their access. Once credentials are compromised, every minute counts.

    • Automatically flag and investigate suspicious account activity before attackers can move laterally.
    • Isolate compromised endpoints to stop malware from spreading.
    • Disable compromised accounts or terminate active sessions before additional data is accessed.

    Faster detection and response reduce attacker dwell time, improves incident response efficiency and helps MSPs contain phishing attacks before they become costly breaches for their clients.






    Traditional email gateway

    Modern phishing defense

    Blocks known malicious senders and links

    Detects suspicious identity, email and endpoint activity

    Focuses on threats before delivery

    Continues monitoring after delivery

    Relies on known phishing signatures

    Detects account compromise, session hijacking and lateral movement

    Prevents malicious emails

    Detects, contains and responds to active attacks

    What MSPs can do this week

    Here are practical steps MSPs can take to reduce risk and strengthen their clients’ defenses

    • Modernize security awareness training: Run phishing simulations that look like what AI produces now, not the misspelled, generic templates from five years ago. Training built on old examples teaches people to watch for the wrong thing.
    • Verify high-risk requests: Require a phone call or a separate channel to confirm any wire transfer, credential reset, or vendor payment change, no matter how convincing the email looks. This one habit stops most business email compromise attempts cold, because it doesn’t rely on anyone spotting anything.
    • Monitor account activity after delivery: Don’t stop at the inbox. Monitor for suspicious mailbox rules, logins from unfamiliar locations, impossible travel and repeated MFA prompts. These behaviors often provide the earliest indication that an account has been compromised.
    • Measure response time, not just resolution time: Measure how long it takes to detect and contain a suspected compromise. Treat that number with the same weight as ticket resolution time. A faster response window is what limits the damage once a phishing email gets past the gateway, and one eventually will.

    AI changed phishing. MSPs need to change their defenses

    AI has changed phishing from a filtering problem into a detection problem.

    As phishing attacks evolve, the advantage belongs to MSPs that can detect and respond before a compromised inbox becomes a client-wide breach.

    Download the 2026 Kaseya Email Security Report to learn how modern phishing attacks bypass legacy defenses and the strategies MSPs are using to stay ahead.

    Sponsored and written by Kaseya.

    attacks catch email Filters MSPs Phishing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Elementor Pro bug exposes WordPress sites to RCE attacks

    Agentic AI Presents New Insider Threat Model for Orgs

    Citrix urges admins to patch new NetScaler flaws as soon as possible

    CISA warns of hackers exploiting critical MLflow vulnerability

    OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

    Critical Zimbra RCE flaw now actively exploited in attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    New leadership initiative carries on legacy of late Indonesian environmental activist

    August 20, 2026

    Lack of water storage is an urgent national security issue | Water

    August 20, 2026

    Togo charges two French journalists over incorrect documents, rights group says

    August 20, 2026

    Novak Djokovic documentary: Tennis great on being ‘my own biggest doubter’ and childhood that shaped his career

    August 20, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    New leadership initiative carries on legacy of late Indonesian environmental activist

    August 20, 2026

    Lack of water storage is an urgent national security issue | Water

    August 20, 2026

    Togo charges two French journalists over incorrect documents, rights group says

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.