Agentic AI pushes phishing defence beyond the email gateway

Phishing campaigns are moving towards an agent-versus-agent contest, as attackers use generative and agentic AI to research targets, draft tailored lures and adapt their activity across email, collaboration platforms, voice and video. A January 2026 Osterman Research study commissioned by IRONSCALES found that 88% of 128 US security and IT leaders had experienced at least one incident that undermined trust in digital communications during the previous year.
The contributed analysis, written by IRONSCALES Chief Product and Strategy Officer Steve Malone, describes this development as “Phishing 3.0”. In this model, the threat is not limited to a malicious link or attachment. It can be a credible request, an interactive conversation or a synthetic voice or video interaction designed to exploit established trust.
From payload scanning to intent and impersonation
The article separates phishing into three stages. Phishing 1.0 centred on harmful content such as malicious links, infected attachments and spam, which secure email gateways were built to identify. Phishing 2.0 shifted to harmful intent: business email compromise, executive impersonation, false invoices and wire-fraud requests that can contain no overtly malicious payload.
Phishing 3.0 adds AI-powered, multi-channel delivery. Agentic systems can examine an organisation’s public footprint, job advertisements, code repositories, cloud documentation and leadership structures, then generate target-specific pretexts at scale. Microsoft has tracked phishing platforms that generate tens of millions of messages each month, while a 2026 Dark Reading readership poll found 48% of security professionals ranked agentic AI as their leading attack vector for the year.
This extends the pattern seen in phishing attacks across collaboration channels, where phishing in Teams formed part of a broader set of quieter attack paths, because a convincing social-engineering campaign need not remain in one messaging channel. The article argues that the economics of reconnaissance change when an automated agent can produce personalised approaches for many organisations in seconds.
Deepfakes broaden the verification problem
The Arup case illustrates the risk outside the inbox. The attack reportedly began with an email impersonating the engineering firm’s UK-based CFO. After an employee hesitated, a deepfake video call appearing to include familiar colleagues led to approval of 15 transfers worth approximately $25 million. The source states that every other face on that call was synthetic.
Osterman Research reported that 60% of respondents lacked confidence in countering deepfake attacks despite existing training, and 55% said a failed response to a trust-based attack increased the likelihood of a full breach. More than one-third had seen attackers masquerade as a trusted vendor or partner. IRONSCALES also said its production-traffic analysis found Microsoft 365 EOP missed 293 phishing messages per 100 mailboxes every 30 days, while Google Workspace missed 350.
Automation must reduce, not add to, alert work
The article contends that the traditional sequence of blocking, then detecting and responding, cannot keep pace with autonomous, personalised campaigns. A 2026 Crogl and Ponemon Institute study found enterprise SOCs averaged 4,330 alerts daily and investigated 37% of them. In the same study, organisations with the strongest security postures had adopted AI in the SOC at a rate of 68%, compared with a 46% average.
Microsoft said its autonomous alert triage agent identified 6.5 times more malicious emails than manual review and saved St. Luke’s University Health Network more than 200 analyst hours per month. The practical implication for businesses is to assess what reaches users after perimeter controls, extend verification procedures to voice and video, and favour automation that investigates or resolves routine cases rather than simply creating more alerts for analysts.

