Generative AI and agent systems are becoming cybercriminals’ new weapon — phishing enters a new era

SECURITYGenerative AI and agent systems are becoming cybercriminals’ new weapon — phishing enters a new era
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Generative artificial intelligence (GenAI) and emerging agent-based systems are rapidly becoming the next major weapon in the cybercriminal arsenal. Instead of clumsy emails full of typos, companies are now facing perfectly written messages in any language — crafted by large language models capable of cloning voices and even generating realistic images. According to cybersecurity analysts at Check Point Software Technologies, this is a “silent revolution” in phishing and smishing that is fundamentally rewriting the rules of cybersecurity.

Not long ago, fake emails were easy to spot — full of mistakes, odd links or strange wording. Today, these telltale signals have virtually disappeared. Attackers are using large language models (LLMs) to create polished, personalized messages based on LinkedIn data, press releases or stolen information. Increasingly, they are also using voice cloning and deepfakes to impersonate executives and obtain wire transfers or confidential data.

“Cybercriminals now operate like organized enterprises. They use automation, cloud infrastructure and ‘AI-as-a-Service’ models. Generative AI writes the content, while agent systems act as campaign managers. These tools analyze victims’ reactions, learn from them and adjust tone, language and communication channel in real time — whether via email, SMS or synthetic voice calls,” explains Wojciech Głażewski, Managing Director of Check Point Software in Poland.

Experts call this new trend Advanced Persistent Manipulation (APM) — long-running, intelligent social engineering campaigns that do not aim to deceive instantly, but instead patiently build trust over time. As a result, traditional anti-phishing training based on spotting mistakes is losing effectiveness, and SOC teams are overwhelmed by the volume of increasingly realistic threats. AI also enables attackers to generate thousands of personalized messages at near-zero cost — dramatically changing the economics of cyberattacks.


How to defend against AI-powered attacks?

A new cybersecurity architecture is needed

Check Point argues that fighting this new era of threats requires a fundamental overhaul of security strategy. The key is adopting AI-based solutions that analyze context, tone and behavioral patterns — not just signatures. Organizations must also extend Zero Trust principles to communication channels such as email, SMS and messaging apps — enforcing identity verification and multi-factor authentication for high-risk actions.

An effective defense should also include XDR platforms that correlate data across endpoints, networks, identity systems and email infrastructures — enabling early detection of coordinated campaigns. Mobile devices must no longer be overlooked, as they are primary targets for smishing; modern tools now protect smartphones from malicious links embedded in SMS or apps. Finally, automation is critical — SOAR platforms allow incidents to be mitigated in real time, isolating accounts and blocking attacker infrastructure within seconds rather than minutes.


Regulators and boards raise the bar

New regulations — such as the SEC’s 4-day incident disclosure rule in the U.S., alongside GDPR, HIPAA and PCI DSS — make AI security an increasingly important element of corporate responsibility. Cyber insurers are also tightening their requirements, penalizing companies that fail to implement next-generation safeguards.

Check Point experts warn that generative and agent-based AI are not threats of the future — they are already here. Companies that fail to adapt will soon be facing adversaries that operate faster and more intelligently than ever before.

Check out our other content
Related Articles
The Latest Articles