Kaseya warns MSPs about AI-powered phishing
Kaseya is warning IT support companies that criminals now use AI to write phishing emails that read like real messages from a coworker or vendor. These emails change their wording and sender details every time they go out, so email filters that look for known scam patterns miss them.
- Report priority
- Medium
- Targets
- Windows+1 more
How it works
Attackers feed AI tools public details from LinkedIn and company websites to build a profile of one employee, then have the AI write a personalized email and generate a fresh version of it for every send, so no two copies share the same subject line, sender name, or wording that a filter could flag.
What to do
There is no product version or patch involved here. Any organization whose staff use email and cloud logins is a potential target, especially if public LinkedIn or company-site details exist for its employees.
Kaseya recommends MSPs go beyond email filtering and also watch identity, email, and endpoint activity together, such as unusual sign-ins, new mailbox rules, and suspicious session activity, so an attack that gets past the inbox is caught before it spreads.
Technical details
Affected software: Windows, macOS
The piece describes AI-assisted phishing as a four-stage process: reconnaissance using public profile data, AI-written personalized content, polymorphic delivery that varies subject lines, sender details, and formatting per message while routing through trusted cloud services, QR codes, and redirect chains, and post-compromise activity involving session token theft and hidden mailbox rules. Traditional email gateways rely on signatures and known indicators of compromise, which lose effectiveness when every message is unique. Kaseya positions this as a case for combined identity, email, and endpoint monitoring rather than inbox filtering alone.