AI-generated phishing emails in a target's native language bypass foreign-language detection heuristics
cybersecurity+2cybersecuritydefenseai0 views
Spear phishing against military and defense industry targets traditionally came in broken English or machine-translated text that email filters flagged. LLMs now generate grammatically perfect, culturally appropriate phishing emails in any language, eliminating the linguistic tells that security training taught users to spot. A Chinese APT can now send flawless American English emails referencing specific defense programs. This persists because email security training and detection models were built on the assumption that foreign adversary communications would contain linguistic artifacts, and retraining an entire workforce to detect linguistically perfect phishing requires a fundamentally different security awareness approach that nobody has developed yet.
Evidence
https://www.mandiant.com/resources/reports/m-trends-2024