Skip to content
Beveiligingsnieuws

Phishing 3.0: Defending Agent vs Agent

phishing 3.0

Email defenses were built for a world where the danger was visible in the message: malicious links, infected attachments, and obvious spam. As attackers changed the target, many organizations kept using the same playbook. Now the threat has moved again—into intent, and beyond that into automated planning and execution. That evolution is often described as phishing 3.0, where agentic AI and synthetic media turn “social engineering” into a fast, multi-channel operation.

In this article, we’ll look at what phishing 3.0 changes in practice, why trust-based attacks are harder to stop with perimeter controls, and what “defender-side” automation needs to look like to regain speed and accuracy.

From scanning messages to breaking trust

For years, secure email gateways and similar tools have worked largely the same way: scan what arrives, compare it against known bad patterns, and block anything that looks malicious. That approach made sense when attacks relied on payloads—things security tools could recognize inside the message.

But phishing evolved. In the next phase, attackers needed to communicate in a way that looked normal. Instead of hiding a weapon in the attachment or link, they pushed a convincing request that depended on the recipient’s judgment. Traditional gateways struggled because there was often nothing “malicious” to flag.

Phishing 3.0 goes further: it combines AI generation, automation, and multiple channels. The lure can be drafted by generative AI, delivered through email and collaboration platforms, and reinforced with voice and video manipulation. At this stage, the threat is not merely a person typing messages—it is increasingly an agent that researches, composes, sends, and adjusts its behavior.

Why agentic AI changes the economics of phishing

Earlier phishing campaigns required time and attention from humans. Reconnaissance meant reading public web content, extracting details from business materials, mapping relationships, and studying executives before a convincing pretext could be written.

Agentic AI reduces that cost dramatically. An automated system can summarize an organization’s public footprint, draw information from code repositories and documentation, identify reporting structures, and generate a tailored narrative in seconds. The same workflow can then be repeated across a large number of organizations—turning “targeting” into something scalable.

That shift increases both quality and reach. Rather than relying on error-prone, generic lures, attackers can generate interactive conversations that better match how people speak and respond. Meanwhile, the blast radius widens because personalization is no longer reserved for high-value targets. Organizations that assumed attackers wouldn’t bother with them can end up inside an automated pipeline anyway.

Multi-channel attacks make inbox-only defenses incomplete

The most damaging phishing attempts don’t necessarily stay in the inbox. A well-documented case described an attacker impersonating a UK-based CFO via an email that began the interaction. When the employee hesitated, the attacker escalated to a deepfake video call that appeared to include familiar colleagues. Importantly, synthetic identities were used for the other participants, and the employee approved multiple transfers worth roughly $25 million.

This illustrates a critical limitation: if your security posture assumes that “the message” is the only place to verify identity, attackers can route around that assumption using voice and video. In other words, phishing 3.0 targets trust signals across channels, not just email content.

What the data suggests about trust-based compromises

Single incidents are costly, but patterns are more useful for planning defenses. A study commissioned by IRONSCALES surveyed 128 security and IT leaders in US organizations of 1,000 to 5,000 employees. Respondents reported that trust in digital communications is already under pressure.

Key findings include:

  • 88% experienced at least one incident that undermined trust in digital communications in the prior year.
  • 82% reported heightened interest from threat actors in their specific industry.
  • 60% lacked confidence in their ability to counter deepfake attacks, despite training.
  • 55% said a failed response to a trust-based attack increases the likelihood of a full breach.
  • More than one-third saw attackers masquerade as trusted vendors or partners.

These numbers matter because many existing tools are built around the idea that the threat can be identified inside a message. But the modern approach impersonates trust across channels where there is often little to scan for “badness,” leaving defenders to rely on behavior, context, and cross-signal verification.

Why the old response model falls behind

Traditional operations often follow a simple cadence: block known threats, detect what slips through, investigate, and clean up after. That workflow can work when adversaries send small volumes of messages and defenders can react faster than the next wave arrives.

However, phishing 3.0 changes the timing. Agent-driven campaigns can generate tailored lures and deploy them faster than a team can read, triage, and respond manually. Even if each individual alert is handled well, the overall volume creates a structural delay.

One referenced 2026 study reported that SOCs averaged thousands of alerts per day and investigated only a fraction of them. When automation and personalized lures accelerate the flow, defenders cannot simply “outwork” the problem with the same staffing model.

As a result, organizations need a shift in posture. Instead of relying only on block-and-react, security teams must also preempt: anticipate the attack being built, harden detection before the first message lands, and let automation handle routine work so humans focus on decisions requiring judgment.

Defender-side agents: the symmetry requirement

If attackers increasingly use agents, defenders need their own agentic capabilities. Otherwise, the defender stays in a speed and scale disadvantage—forever arriving after the decision has already been made by automation.

That transition is already underway in parts of the market. In the Crogl study referenced in the source material, teams with stronger security postures adopted AI in the SOC at higher rates than peers. There are also examples of AI-powered triage agents that identify malicious emails more effectively than manual review and can reduce the time analysts spend on routine investigation.

The key point is not that AI merely “shows alerts.” The goal is different: an agent should investigate end to end and present a clear verdict to a human, reducing alert overload and accelerating resolution.

What “agentic defense” can include

Conceptually, an agent-based defensive approach can map to three activities:

  • Anticipation: simulate how an attacker would research and prepare, then harden detection before the campaign begins.
  • Investigation: perform deeper triage that compresses time-to-understanding and time-to-response.
  • Education: run simulations that reflect reconnaissance-aware tactics, not only generic template-based phish.

Across these use cases, the underlying idea is to learn organizational communication patterns and improve detection based on real-world signal rather than static assumptions.

Practical guidance for practitioners

If you’re responsible for security outcomes, the most useful changes often start with measurement and scope.

Measure what reaches the inbox after the gateway

Instead of focusing only on what perimeter controls block, track post-delivery outcomes. The source material emphasizes that modern attacks live beyond the gateway, so asking vendors for their “miss rate” after delivery is more actionable than relying on vague performance claims.

Extend the threat model beyond email

Identity verification cannot stop at the inbox. The cited scenario involved a video call, not just a message. If you only validate text-based artifacts, attackers can shift the most persuasive part of the interaction to voice and video.

Evaluate automation by outcomes, not dashboards

A tool that increases the number of alerts a human must review may worsen operational load. When judging automation, ask what percentage of incidents get resolved without a human touching them, and whether the workflow reduces time-to-decision.

Train employees with reconnaissance-aware scenarios

Generic simulations teach people to spot generic phish, but phishing 3.0 often uses personalization. Training should therefore reflect the kinds of reconnaissance attackers use and the more tailored pretexts that result.

Conclusion: treating phishing 3.0 as an operational reality

Phishing 3.0 is not a distant forecast. The shift toward agent-driven phishing, synthetic media, and multi-channel delivery is already changing outcomes. Trust is being exploited faster than many defenses can respond with traditional block-and-react processes.

Organizations that handle the transition best will stop treating the defense as something humans only “catch up” with after the fact. Instead, they’ll bring agentic capabilities to the defensive field—preempting campaigns, investigating threats efficiently, and improving training with realistic reconnaissance-aware scenarios.

Source: https://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus.html