{"id":15365,"date":"2026-09-17T17:55:53","date_gmt":"2026-09-17T12:25:53","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15365"},"modified":"2026-09-17T17:55:55","modified_gmt":"2026-09-17T12:25:55","slug":"ai-phishing-prevention","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/","title":{"rendered":"AI Phishing Prevention: What Actually Changed and What to Do About It"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">AI phishing prevention starts with a correction. Nobody can reliably measure how much phishing is AI-generated, because AI-text detection is unreliable and fails almost completely on mixed human and machine writing. What changed is not authorship. It is that the signals awareness training relied on have disappeared.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#What_Changed_About_Phishing_and_What_Did_Not\" >What Changed About Phishing, and What Did Not<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Why_the_Share_of_AI-Generated_Phishing_Cannot_Be_Measured\" >Why the Share of AI-Generated Phishing Cannot Be Measured<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#What_Independent_Data_Shows_About_Phishing_Volume\" >What Independent Data Shows About Phishing Volume<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#The_Better_Question_to_Ask_Instead\" >The Better Question to Ask Instead<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Which_Recognition_Signals_Stopped_Working\" >Which Recognition Signals Stopped Working<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Which_Signals_Still_Work\" >Which Signals Still Work<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#What_AI_Detection_Genuinely_Adds_on_Defence\" >What AI Detection Genuinely Adds on Defence<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Where_Detection_Cannot_Help_at_All\" >Where Detection Cannot Help at All<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#A_Prevention_Strategy_That_Ignores_Authorship\" >A Prevention Strategy That Ignores Authorship<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Why_Better_Lures_Raise_Click_Rate_Without_Meaning_You_Failed\" >Why Better Lures Raise Click Rate Without Meaning You Failed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#What_to_Measure\" >What to Measure<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Training_That_Survives_Better_Lures\" >Training That Survives Better Lures<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Retire_the_Old_Signal_List_This_Quarter\" >Retire the Old Signal List This Quarter<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Changed_About_Phishing_and_What_Did_Not\"><\/span>What Changed About Phishing, and What Did Not<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generative tools changed the economics of writing a lure. An attacker can now produce fluent, contextual messages in any language, at volume, and rewrite them when a campaign stops landing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What did not change is the structure of the attack. A phishing message still needs a pretext, a trigger, and an action. It still asks someone to click, call, pay, or approve. The underlying manipulation is identical to what it was five years ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That distinction matters for where money goes. Defences aimed at detecting machine authorship address a property of the text. Defences aimed at the request address the thing that actually harms you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the useful framing is not that phishing became artificial. It is that phishing became well written, which broke a specific set of controls. Background sits in <a href=\"https:\/\/threatcop.com\/blog\/difference-between-spear-phishing-and-phishing\/\">spear phishing vs phishing<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_the_Share_of_AI-Generated_Phishing_Cannot_Be_Measured\"><\/span>Why the Share of AI-Generated Phishing Cannot Be Measured<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vendors publish confident percentages for how much phishing shows signs of AI involvement. Those figures rest on AI-text detection, and the research on that is not encouraging.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Finding<\/strong><\/th><th><strong>Detail<\/strong><\/th><\/tr><\/thead><tbody><tr><td>OpenAI&#8217;s own classifier<\/td><td>Labelled human text as AI 9% of the time, and correctly identified only 26% of AI-written text<\/td><\/tr><tr><td>Withdrawn by its maker<\/td><td>OpenAI retired the classifier in July 2023 for low accuracy, and had not revived it as of December 2025<\/td><\/tr><tr><td>Academic tool testing<\/td><td>Every tool tested scored below 80% accuracy, with only five above 70%<\/td><\/tr><tr><td>Misattribution bias<\/td><td>Roughly 20% of AI-generated texts were classified as human-written<\/td><\/tr><tr><td>Hybrid text<\/td><td>Accuracy on mixed human and AI writing dropped to nearly zero in 2026 testing<\/td><\/tr><tr><td>Subject-matter bias<\/td><td>Accuracy on scientific text ran 28 to 38 percentage points below humanities text<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The hybrid row is the one that undermines phishing statistics specifically. A real campaign is rarely pure machine output. An attacker generates a draft, edits it, pastes in a real signature block, and adapts a template, which produces exactly the mixed text these tools handle worst.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Several universities, including Cornell and Vanderbilt, withdrew AI detectors over reliability concerns. If the tooling is considered unfit for grading an essay, treating its output as a threat statistic deserves the same scepticism.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Independent_Data_Shows_About_Phishing_Volume\"><\/span>What Independent Data Shows About Phishing Volume<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vendor telemetry dominates this topic, so it is worth grounding the picture in figures collected outside the security industry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FBI&#8217;s <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2025_IC3Report.pdf\" target=\"_blank\" rel=\"nofollow noopener\">2025 Internet Crime Report<\/a> logged 191,561 phishing and spoofing complaints, carrying $215,843,126 in reported losses. Business email compromise accounted for far more money from far fewer cases: $3,046,598,558 across 24,768 complaints, an average near $123,000 each.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read those two lines together and the shape of the problem appears. Volume phishing generates complaints. Targeted, payload-free requests generate losses. The messages that cost the most are the ones with the least for a scanner to inspect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Verizon&#8217;s 2026 Data Breach Investigations Report puts the human element in 62% of breaches, effectively unchanged across three editions despite a decade of awareness investment and steadily improving filters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That flatness is the argument against treating this as a detection problem. If better tooling were closing the gap, the proportion would be falling. Instead, it holds, which suggests the binding constraint sits where the decision is made rather than where the message is scanned. Loss patterns appear in <a href=\"https:\/\/threatcop.com\/blog\/business-email-compromise\/\">business email compromise<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Better_Question_to_Ask_Instead\"><\/span>The Better Question to Ask Instead<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authorship is unmeasurable and, moreover, operationally irrelevant. A credential stolen through a beautifully written lure and one stolen through a clumsy lure are the same incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three questions produce better answers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What fraction of our lures now pass a native-speaker fluency check? That is measurable through your own simulations, and it tracks the thing that actually degraded recognition training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How quickly do people act on messages, and has that changed? Speed reveals processing mode, which is the underlying vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Which pretexts are landing this quarter? Pretext is what attackers iterate, and it is the part employees can be taught to recognise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each of those is measurable from data you already generate. None requires guessing who or what wrote the message.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Which_Recognition_Signals_Stopped_Working\"><\/span>Which Recognition Signals Stopped Working<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Decades of awareness content taught people to look for surface flaws. That list is now largely obsolete, and continuing to teach it actively harms people by giving false confidence.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Spelling and grammar errors.<\/strong> Gone, and in any language.<\/li>\n\n\n\n<li><strong>Awkward phrasing and translation artefacts.<\/strong> Gone, including in languages where attackers were previously weak.<\/li>\n\n\n\n<li><strong>Generic salutations.<\/strong> Attackers can personalise at scale from public sources.<\/li>\n\n\n\n<li><strong>Inconsistent tone.<\/strong> Models match corporate register well enough to pass.<\/li>\n\n\n\n<li><strong>Obvious branding mismatches.<\/strong> Templates are copied accurately rather than approximated.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An employee trained on that list will read a fluent, well-branded, personally addressed message and conclude it is legitimate, because every signal they were taught to check comes back clean.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is the real damage AI did to phishing defence. It did not make attacks cleverer. It removed the tells, which means the training built on them now produces misplaced confidence. Related recognition problems appear in <a href=\"https:\/\/threatcop.com\/blog\/what-is-deepfake-phishing\/\">deepfake phishing<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Which_Signals_Still_Work\"><\/span>Which Signals Still Work<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Fluency is cheap. However, context and process are not, and that is where durable signals live.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, request shape survives. Unusual urgency, a change to payment details, a demand for secrecy, an instruction to bypass a normal process. These are structural to the attack rather than cosmetic, so generation quality does not touch them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Similarly, channel mismatch survives. A finance instruction arriving by text, an HR matter in a personal inbox, a supplier query from a new address. The attacker chooses the channel for deliverability, not plausibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Relationship anomaly survives as well. A first-time sender making a consequential request, a dormant contact reappearing with urgency, an executive contacting someone they have never contacted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And verification always survives. Confirming through a channel the message did not arrive on defeats every lure regardless of how it was written, which makes it the most durable control available. Mechanics appear in <a href=\"https:\/\/threatcop.com\/blog\/credential-harvesting\/\">credential harvesting<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_AI_Detection_Genuinely_Adds_on_Defence\"><\/span>What AI Detection Genuinely Adds on Defence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">None of the above argues against AI-powered email security. It argues for buying it on the right basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Behavioural and relationship modelling is where defensive AI earns its place. A system that knows this sender has never emailed this recipient, that the request deviates from their established pattern, or that the domain was registered last week is evaluating context rather than prose style.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, volume triage is the second genuine win. Sorting reported messages by likely severity, clustering a campaign from scattered reports, and surfacing the ten that matter from four hundred is work humans do badly because there is too much of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither depends on identifying machine authorship. Both depend on data about relationships and behaviour that your environment already produces. Selection criteria sit in <a href=\"https:\/\/threatcop.com\/blog\/evaluating-ai-phishing-triage-tools-in-cybersecurity\/\">evaluating AI phishing triage tools<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_Detection_Cannot_Help_at_All\"><\/span>Where Detection Cannot Help at All<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Three categories defeat content analysis entirely, and they are growing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Payload-free messages contain no link and no attachment. A request to change bank details, or a message carrying only a phone number, gives a scanner nothing to examine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Equally, compromised legitimate accounts send from clean infrastructure with valid authentication and real reputation. The message genuinely is from the partner it claims to be from.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cross-channel attacks begin in email and complete by phone, or begin on a messaging app entirely. Email security inspects one leg of a journey that has several. Voice-side mechanics appear in <a href=\"https:\/\/threatcop.com\/blog\/ai-vishing-what-it-is-and-how-it-works\/\">AI vishing<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For all three, the human layer is not a backstop. It is the only control positioned where the decision happens.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_Prevention_Strategy_That_Ignores_Authorship\"><\/span>A Prevention Strategy That Ignores Authorship<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, build the programme around what the message asks rather than how it reads. Eight measures cover most of the ground.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Finish email authentication.<\/strong> Get every domain you own to DMARC enforcement, since exact-domain spoofing is solvable and most organisations have not solved it.<\/li>\n\n\n\n<li><strong>Monitor for lookalike domains<\/strong>, which authenticate correctly because the attacker owns them.<\/li>\n\n\n\n<li><strong>Deploy phishing-resistant authentication.<\/strong> Passkeys bound to an origin cannot be captured by a convincing fake login page, no matter how well written.<\/li>\n\n\n\n<li><strong>Define out-of-band verification thresholds<\/strong> in writing, so people are not deciding under pressure when to call back.<\/li>\n\n\n\n<li><strong>Make reporting faster than complying.<\/strong> If reporting takes four clicks and acting takes one, design has chosen the outcome.<\/li>\n\n\n\n<li><strong>Simulate across channels<\/strong>, since attacks that start in email finish elsewhere.<\/li>\n\n\n\n<li><strong>Train on request shape<\/strong>, not on spelling, and retire the obsolete signal list explicitly.<\/li>\n\n\n\n<li><strong>Measure time to action<\/strong>, because speed exposes the processing mode that generation quality exploits.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Above all, item 7 needs stating out loud to employees. People who were taught the old signals need to be told those signals are dead, or they will keep applying them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Better_Lures_Raise_Click_Rate_Without_Meaning_You_Failed\"><\/span>Why Better Lures Raise Click Rate Without Meaning You Failed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One measurement trap deserves naming, because it punishes programmes that are working.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When lure quality improves, click rate rises. That happens for reasons outside your control, and a team reading the number alone concludes the training stopped working. Some then respond by making simulations easier, which produces a falling click rate and a workforce no better prepared.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two habits prevent that. Hold simulation difficulty steady across periods, and record it, so a change in outcome means a change in behaviour rather than a change in the test. Then read click rate alongside report rate, since the pair tells a story neither tells alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A rising click rate with a rising report rate usually means the lures got harder and people still escalated. A falling click rate with a flat report rate often means the simulations got easier. Only the combination distinguishes them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Measure\"><\/span>What to Measure<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Click rate alone will mislead you here. Specifically, better lures raise it for reasons unrelated to your programme&#8217;s quality.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Report rate and median report time<\/strong>, which measure the behaviour that scales<\/li>\n\n\n\n<li><strong>Time from delivery to action<\/strong>, distinguishing a four-second reflex from a considered mistake<\/li>\n\n\n\n<li><strong>Repeat-failure rate after intervention<\/strong>, which tests whether training changed anything<\/li>\n\n\n\n<li><strong>Out-of-band verification rate<\/strong> on high-value requests, the behaviour most worth building<\/li>\n\n\n\n<li><strong>Proportion of reports arriving from outside email<\/strong>, showing whether cross-channel awareness exists<\/li>\n\n\n\n<li><strong>Coverage of phishing-resistant authentication<\/strong>, which removes the loss path rather than narrowing it<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The fourth is the one almost nobody tracks and the one most predictive of whether a well-written lure succeeds.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Training_That_Survives_Better_Lures\"><\/span>Training That Survives Better Lures<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Content built on surface flaws depreciates every time models improve. Content built on process does not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In short, the practical shift is from identification to procedure. Rather than teaching people to judge whether a message is genuine, teach them what to do when a request has a particular shape, regardless of how convincing it looks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TSAT supports that by running simulations across email, voice, SMS, and QR vectors and scoring exposure per employee, so training targets the people and channels where the gap actually is. Programme design sits in <a href=\"https:\/\/threatcop.com\/blog\/best-practices-for-email-security\/\">email security best practices<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Retire_the_Old_Signal_List_This_Quarter\"><\/span>Retire the Old Signal List This Quarter<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Open your current awareness content and find where it tells employees to check for spelling mistakes, poor grammar, or generic greetings. That passage is now teaching people to trust a well-written attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Replace it with request shape and an out-of-band verification rule, then measure how often people actually verify rather than how often they click. Verification rate is the number that predicts whether a fluent lure succeeds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After that, <a href=\"https:\/\/threatcop.com\/threatcop-security-awareness-training\">run simulations across the channels attackers actually use<\/a>, because a campaign that starts in email and finishes on a phone call is invisible to a programme that only tests email.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-13ecf92a7983\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-77b8ed6aac82\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-2a7983\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-2a7983'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow much phishing is AI-generated?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-2a7983'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Nobody can say reliably. Estimates depend on AI-text detection, which research shows to be unreliable: OpenAI&#8217;s own classifier flagged human text as AI 9% of the time while catching only 26% of AI-written text, and it was withdrawn in 2023. Accuracy on mixed human and AI text, which is what real campaigns produce, drops to nearly zero.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-d0e0c1403c7d\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-2a7983\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-2a7983'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tAre AI-written phishing emails harder to detect?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-2a7983'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Harder for people, not necessarily for systems. AI removes the spelling errors, awkward phrasing, and generic salutations that awareness training taught employees to spot. Technical controls that analyse sender relationships, domain age, and request patterns are largely unaffected, because they evaluate context rather than writing quality.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-3761c6af82c4\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-2a7983\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-2a7983'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat phishing signals still work?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-2a7983'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Request shape, channel mismatch, and relationship anomaly all survive. Unusual urgency, a change to payment details, a demand for secrecy, a finance instruction arriving by text, or a first-time sender making a consequential request are structural features of the attack. Verification through an independent channel defeats every lure regardless of how well it is written.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-2b3f79f370fb\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-2a7983\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-2a7983'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tCan AI detect AI-generated phishing?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-2a7983'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Defensive AI helps, though not by identifying machine authorship. Its value lies in behavioural and relationship modelling, spotting that a sender has never contacted this recipient or that a request deviates from an established pattern, and in triaging reported messages at volume. Both work on context rather than prose style.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-ee491bba82d0\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-2a7983\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-2a7983'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat should replace old phishing awareness training?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-2a7983'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Replace surface-flaw identification with procedure. Teach people what to do when a request carries a particular shape, such as urgency attached to a payment change, rather than how to judge whether writing looks authentic. Tell employees explicitly that the old signals no longer apply, otherwise they will keep applying them with false confidence.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.<\/p>\n","protected":false},"author":15,"featured_media":15382,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43],"tags":[],"class_list":["post-15365","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-social-engineering"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI Phishing Prevention: What Changed and What to Do<\/title>\n<meta name=\"description\" content=\"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Phishing Prevention: What Changed and What to Do\" \/>\n<meta property=\"og:description\" content=\"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T12:25:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T12:25:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nikunj Rakesh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nikunj Rakesh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/\"},\"author\":{\"name\":\"Nikunj Rakesh\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\"},\"headline\":\"AI Phishing Prevention: What Actually Changed and What to Do About It\",\"datePublished\":\"2026-09-17T12:25:53+00:00\",\"dateModified\":\"2026-09-17T12:25:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/\"},\"wordCount\":2206,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Phishing-Prevention-blog-banner.png\",\"articleSection\":[\"Social Engineering\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/\",\"name\":\"AI Phishing Prevention: What Changed and What to Do\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Phishing-Prevention-blog-banner.png\",\"datePublished\":\"2026-09-17T12:25:53+00:00\",\"dateModified\":\"2026-09-17T12:25:55+00:00\",\"description\":\"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Phishing-Prevention-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Phishing-Prevention-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading AI Phishing Prevention, What Actually Changed, over an abstract stacked bar graphic on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-phishing-prevention\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI Phishing Prevention: What Actually Changed and What to Do About It\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d931534f0bd46db3dcf54b9313f587db\",\"name\":\"Nikunj Rakesh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427\",\"caption\":\"Nikunj Rakesh\"},\"description\":\"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nikunj-rakesh-579a87129\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Phishing Prevention: What Changed and What to Do","description":"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/","og_locale":"en_US","og_type":"article","og_title":"AI Phishing Prevention: What Changed and What to Do","og_description":"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.","og_url":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-17T12:25:53+00:00","article_modified_time":"2026-09-17T12:25:55+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png","type":"image\/png"}],"author":"Nikunj Rakesh","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Nikunj Rakesh","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/"},"author":{"name":"Nikunj Rakesh","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db"},"headline":"AI Phishing Prevention: What Actually Changed and What to Do About It","datePublished":"2026-09-17T12:25:53+00:00","dateModified":"2026-09-17T12:25:55+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/"},"wordCount":2206,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png","articleSection":["Social Engineering"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/","url":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/","name":"AI Phishing Prevention: What Changed and What to Do","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png","datePublished":"2026-09-17T12:25:53+00:00","dateModified":"2026-09-17T12:25:55+00:00","description":"AI phishing prevention starts with a correction: AI authorship cannot be measured reliably. See which recognition signals died, which survive, and what to do.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/AI-Phishing-Prevention-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading AI Phishing Prevention, What Actually Changed, over an abstract stacked bar graphic on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/ai-phishing-prevention\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"AI Phishing Prevention: What Actually Changed and What to Do About It"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d931534f0bd46db3dcf54b9313f587db","name":"Nikunj Rakesh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","url":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/litespeed\/avatar\/13ad07461d83236c3639a7ca7f2d48df.jpg?ver=1789624427","caption":"Nikunj Rakesh"},"description":"Nikunj is a CISO focused on helping organizations build effective security programs and resilient cultures. With a strong track record across industries, he drives governance and risk strategies that protect what matters most. Outside work, he mentors professionals and explores emerging trends shaping the future of cybersecurity.","sameAs":["https:\/\/threatcop.com\/","https:\/\/www.linkedin.com\/in\/nikunj-rakesh-579a87129"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15365"}],"version-history":[{"count":2,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15365\/revisions"}],"predecessor-version":[{"id":15399,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15365\/revisions\/15399"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15382"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}