Skip to content

Image: redcanary.com · rights & removal

Executive Summary

The article discusses the increasing sophistication of AI tools used by adversaries to craft convincing phishing emails. It highlights that traditional methods cannot handle such a vast volume and requires advanced triage techniques for defense. Red Canary's AI-based agent handles 94% accuracy in triaging these complex tasks, addressing the scale challenge effectively.
Key points:
Over 3.8 million phishing attacks reported by APWG.
Q2 alone accounted for more than 1.1 million new phishing campaigns.
Defenders need scalable solutions to manage this high volume of threats.
The article outlines a multi-agent workflow designed specifically for handling triage tasks.
The agent integrates traditional and AI-powered feature extraction, applies rules engines for detection, and utilizes hybrid ML/AAI classification methods when necessary. It includes transparent processes with summary explanations and feedback loops for accuracy, ensuring reliable operation.
<RED>
Verifiable facts:
3.8 million phishing attacks reported in 2025.
Q2 reported over 1.1 million new campaigns.
Red Canary's AI agent achieves 94% triage accuracy on email investigations.
</RED>
<PURPLE>
The article posits that the increasing complexity and volume of phishing emails pose an insurmountable challenge for traditional methods, necessitating innovative solutions like AI-driven triaging agents. The multi-agent approach leverages a combination of automated features extraction, rule-based detection, and machine learning to handle the overwhelming workload efficiently.
While the agent excels in triage tasks, it underscores the need for continuous improvement as adversaries continue to refine their techniques. The article suggests that attackers are likely adapting by shifting focus from simple evasion to more advanced deception methods, indicating a cycle of adaptation where defenses must remain vigilant and adapt accordingly.
The narrative highlights the importance of context-sensitive analysis tools like AI in cybersecurity. It emphasizes that traditional security measures often fall short due to the sheer volume and complexity of threats, underscoring the necessity for specialized solutions tailored to these evolving challenges.
By integrating multiple methods and continuously refining its agents through feedback loops, Red Canary aims to maintain a competitive edge against sophisticated adversaries. This approach not only underscores the need for innovation in cybersecurity but also sets an example for other security teams facing similar challenges with rapidly evolving threats.

Facts Only

Verifiable facts:
3.8 million phishing attacks reported in 2025.
Q2 reported over 1.1 million new campaigns.
Red Canary's AI agent achieves 94% triage accuracy on email investigations.

Full Take

The article posits that the increasing complexity and volume of phishing emails pose an insurmountable challenge for traditional methods, necessitating innovative solutions like AI-driven triaging agents. The multi-agent approach leverages a combination of automated features extraction, rule-based detection, and machine learning to handle the overwhelming workload efficiently.
While the agent excels in triage tasks, it underscores the need for continuous improvement as adversaries continue to refine their techniques. The article suggests that attackers are likely adapting by shifting focus from simple evasion to more advanced deception methods, indicating a cycle of adaptation where defenses must remain vigilant and adapt accordingly.
The narrative highlights the importance of context-sensitive analysis tools like AI in cybersecurity. It emphasizes that traditional security measures often fall short due to the sheer volume and complexity of threats, underscoring the necessity for specialized solutions tailored to these evolving challenges.
By integrating multiple methods and continuously refining its agents through feedback loops, Red Canary aims to maintain a competitive edge against sophisticated adversaries. This approach not only underscores the need for innovation in cybersecurity but also sets an example for other security teams facing similar challenges with rapidly evolving threats.

From the original · Red Canary

We’ve already established that artificial intelligence is raising the bar for adversaries. This is especially the case when it comes to crafting phishing messages.
Read the full story at redcanary.com

Sentinel — Likely Synthetic

Confidence

This article demonstrates elements indicative of both organic human writing and an AI-generated structure in its presentation, with some human-like traits mixed into the AI framework.

Signals Detected
medium severity: The text lacks human writer's idiosyncratic voice and personal touch, indicating a lack of organic narrative flow.
high severity: Claims about specific features and results are not substantiated or attributed with appropriate sources.
Human Indicators
The text is generally coherent but lacks the human element of a writer's style, making it difficult to attribute authorship based on stylistic evidence. The text does not provide specific examples or detailed reasoning that would suggest organic thought processes typical of a human writer.
Train, triage, repeat: The AI agent changing how we fight phishing | Huntaegis