PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

How Polymorphic Phishing Campaigns Leverage AI to Evade Detection

By Wesley Grant
April 24, 2025
in Analysts Coverage, Cyberscams, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
polymorphic phishing

Exhausted African American employee working on project in office. Man and women in casual sitting and standing at table and using laptops. Multiethnic staff concept

A novel artificial intelligence feature is making phishing attacks—already the weapon of choice for cybercriminals—even more effective.

In the past, phishing emails were sent out en masse using the same template, making it easier for fraud detection systems to identify patterns among these blanket messages. Now, a technique called polymorphic phishing incorporates AI to randomize components of fraudulent emails—such as sender names, subject lines, and even the content.

This allows bad actors to launch customized email campaigns that can bypass many security measures. As with many AI-powered fraud mechanisms, polymorphic phishing attacks have rapidly gained traction. According to SecurityWeek, at least one polymorphic feature was present in 76% of all phishing attacks last year.

“Phishing attacks remain the leading way cybercriminals breach networks and systems, infect devices—both personal and corporate—with ransomware, and coerce employees and consumers to reveal and leak sensitive personal information and corporate intellectual property,” said Tracy Goldberg, Director of Cybersecurity at Javelin Strategy & Research.

“DNS security features, used to block malicious websites and web-based attacks, and spam blocking, which traps suspicious emails based on domain, keywords, and email server rules, are being circumvented by these emerging polymorphic phishing attacks,” she said. “That means spam blockers and DNS filtering are increasingly less effective.

Innovating New Fraud Vectors

This new spin on phishing is part of a broader trend: through technology and social engineering, cybercriminals have gained an edge over organizations. This is especially true in the financial services industry, where longstanding compliance and risk concerns have made institutions slower to adopt new technologies.

Meanwhile, cybercriminals face no such constraints. They’ve been quick to experiment with emerging tech like AI, developing new and more effective methods of attack. One result: novel fraud vectors, such as AI agents, which can be developed to carry out fraud attacks autonomously.

Known and Trusted Users

To combat these innovations, organizations must look beyond their current limitations to find solutions against this growing threat. They will also need to adapt and integrate emerging technologies capable of identifying such threats more effectively.

“Verifying the authenticity of senders through protocols like Domain-based Message Authentication, Reporting and Conformance (DMARC), and DomainKeys Identified Mail (DKIM), remain among the best tactics to stop phishing and spam,” Goldberg said. “Additionally, AI can be used to help email security, by relying on defenses that analyze emails to detect content patterns that suggest the email has been automated, rather than written by a human.”

“That, of course, increases the risk of so-called ‘false positives,’ meaning legitimate emails that have been sent en masse—such as marketing emails or those sent through mail merge—are more likely to get blocked,” she said. “Companies will soon be forced to lean toward encrypted email security that limits email access to known and trusted users.”

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: AIAI AgentsArtificial IntelligenceDKIMDMARCphishingPhishing AttacksPolymorphic Phishing

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025
    metal cards

    Metal Card Magnitude: How a Premium Touch Can Enthrall High-Value Customers

    December 2, 2025
    digital gift cards

    How Nonprofits Can Leverage Digital Gift Cards to Help Those in Need

    December 1, 2025
    stored-value prepaid

    How Stored-Value Accounts Are the Next Iteration of Prepaid Payments

    November 26, 2025
    google crypto wallet, crypto regulation

    Crypto Heads Into 2026 Awaiting Its ‘Rocketship Point’

    November 25, 2025
    Merchants Real-Time Payments, swipe fees, BNPL

    The 3 Key Trends That Will Shape Merchant Payments in 2026

    November 24, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result