Kaseya report flags AI phishing

- Kaseya said on March 17, 2026, its 2026 INKY Email Security Report found AI had reshaped phishing and email-based cybercrime. (kaseya.com) - Dave Baggett, Kaseya’s SVP of Security Suite, said “AI-generated phishing became the baseline,” as attackers produced convincing messages at scale. (kaseya.com) - The full report, “Email security report: AI, phishing and the new era of defense,” is available from Kaseya’s resource page. (kaseya.com)

Kaseya’s 2026 INKY Email Security Report argues that phishing has changed shape as generative AI improves the quality and scale of email attacks. The company said in a March 17 release that 2025 was an “inflection point” for email-based cybercrime, with AI reshaping both attacker tactics and defensive strategy. (kaseya.com) Dave Baggett, Kaseya’s senior vice president of Security Suite, said AI-generated phishing had become “the baseline,” eroding older cues such as bad grammar, suspicious domains and obvious links. The report, titled “Email security report: AI, phishing and the new era of defense,” says phishing remains central to cybercrime and that defenses now need to focus more on intent and context than on static indicators. (kaseya.com) Kaseya frames the shift as one from noisy, easy-to-spot spam toward polished, contextual messages delivered through trusted infrastructure and legitimate-looking workflows. ### What exactly is Kaseya saying changed in phishing? Kaseya says generative AI has turned phishing from a “high-volume nuisance” into what the report calls a “precision instrument.” The report says messages are now more polished, more contextual and more likely to be delivered through infrastructure that does not immediately look malicious. (kaseya.com) Baggett said the practical result is that older detection habits are losing value. “Attackers can now produce highly convincing messages at scale,” he said, adding that defenders now have to evaluate “intent and context, not just indicators.” (kaseya.com) ### Which old warning signs does the report say are fading? The Kaseya report says traditional signals such as poor grammar, suspicious domains and obvious malicious links are becoming less reliable. It lists five headline findings, including that phishing is now “AI-generated by default,” brand impersonation is the dominant fraud lever, infrastructure abuse is replacing malicious domains, and static detection models are obsolete. (kaseya.com) The report also says attackers are embedding manipulation inside ordinary business workflows. That matters because many user-facing heuristics were built around spotting clumsy wording or visibly malicious infrastructure, not messages that look polished and arrive through trusted services. (kaseya.com) ### How big is the email threat in Kaseya’s telling? Kaseya ties the report to broader cybercrime figures from the FBI’s 2024 Internet Crime Report. The report says total reported cybercrime losses reached $16.6 billion in 2024, up 295% over five years, and says 26% of all cybercrime complaints filed with the FBI were phishing-related. (kaseya.com) Kaseya’s March release adds that business email compromise losses alone reached $2.8 billion, and that INKY processed more than 4.5 billion emails in 2025 while observing impersonation of 281 unique brands. The company also said 82% of ransomware attacks targeted organizations with fewer than 1,000 employees. (kaseya.com) ### What kinds of phishing does the company say are expanding? Kaseya said attackers are moving beyond standard email lures into calendar invitations, protected documents and callback phone numbers. The company said AI-generated layouts are helping impersonators more closely resemble legitimate messages from financial institutions and retail brands. (kaseya.com) The broader market has shown similar pressure on older inspection methods. In a July 8 article, The Hacker News described a “ghost phishing” campaign in which malicious content stayed hidden until a browser decrypted and rendered it, a technique the publication said could evade static URL checks and network-level controls. (kaseya.com) ### What defenses does Kaseya say need to change? Kaseya says email security has entered a phase defined by “adaptive detection, contextual reasoning and systemic resilience.” In its March release, the company said INKY expanded generative AI-driven detection models, intent-based labeling, multi-label classification and computer-vision-based contextual understanding during 2025. (kaseya.com) The report does not present email as a broken channel. Instead, it says the structure of defense has to change as attackers use AI, trusted infrastructure and workflow-based deception. Kaseya’s resource page says the report covers emerging phishing techniques observed across billions of analyzed emails and includes predictions for how AI will reshape both phishing and email defense in 2026. (thehackernews.com) Kaseya published the report on March 17, 2026, and the document remains available through the company’s resource page. The Hacker News highlighted the report again on September 2, 2026, in a social post pointing readers to Kaseya’s findings on AI-driven phishing and defensive strategy. (kaseya.com 1) (kaseya.com 2)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.