How MSPs can spot phishing attacks that evade email filters

How MSPs can spot phishing attacks that evade email filters

Phish

Your customers receive thousands of emails every day, but all it takes is one compelling message to turn a seemingly innocuous email into a security incident that you are responsible for resolving.

AI has fundamentally changed phishing: it’s easier to launch, harder to detect, and far more convincing than traditional email filters designed to prevent it.

With a large language model and few publicly available LinkedIn profiles, attackers can generate highly personalized phishing emails in minutes. Harvard Business Review has found that AI-generated spear phishing campaigns are successful 54% click ratewhich matches those of human experts at a fraction of the cost.

To protect customers before a single email becomes a costly breach, it’s important to understand how these attacks work and why traditional filters struggle to stop them.

In an AI-powered phishing campaign

Every AI-powered phishing campaign follows the same basic path. AI simply makes each phase faster, more convincing, and much harder for traditional defenses to detect.

Reconnaissance: AI finds the right target

Attackers use AI to scan LinkedIn, company websites and other public sources to build a profile of a specific employee. Within minutes, they know who this person works with, what projects they are involved in, and how they communicate.

Why this matters for MSPs: Public information gives attackers everything they need to create a credible phishing email before it ever reaches your customer’s inbox.

Content generation: AI writes an email that looks legitimate

AI uses this information to create an email that appears to come from a trusted colleague, customer or supplier. Each message is personalized, contextual, and free of misspellings or awkward wording that once made phishing easy to spot.

Why this matters for MSPs: The biggest challenge is no longer identifying obvious phishing emails. It protects customers from messages that look and read like legitimate business communications and increases the likelihood that users will trust them.

Delivery and bypass: The email arrives

AI also helps attackers evade detection by creating a unique version of each email – a technique known as polymorphic phishing. It continuously changes subject lines, sender details, formatting and content, using trusted cloud services, QR codes and redirect chains to bypass traditional filters.

Why this matters for MSPs: Traditional email gateways rely heavily on signatures and known indicators of compromise. If every email is different and constantly changing, these indicators become far less reliable, allowing more phishing emails to reach your customers.

Post-compromise activities: Damage occurs quickly

When a user clicks on a malicious link or enters their credentials, the attack quickly escalates. Attackers can steal session tokens, create mailbox rules to hide their activity, and begin moving through the client’s environment within minutes.

According to IBM’s 2024 Cost of a Data Breach Report: Phishing is the leading cause of data breacheswhich account for 16% of incidents and cost organizations an average of $4.8 million per breach.

Why this matters for MSPs: Once a phishing email reaches your inbox, prevention alone is no longer enough. Protecting customers requires visibility beyond email, with endpoint detection, identity monitoring and rapid response working together to stop attackers before they can expand their access.

Discover the latest phishing trends and AI-driven email threats. Learn practical strategies to strengthen your email security.

Download Kaseya’s 2026 Email Security Report to learn more about this year’s emerging cybersecurity threats.

Download now

What intercepts an AI-generated attack?

AI can obscure a phishing email, but not the subsequent identity, endpoint, and user activity. This is where modern detection makes the difference.

Monitor behavior, not just email

Every successful phishing attack leaves behind signs that something is wrong. Instead of just examining the email, look for unusual account and user activity, such as:

  • A new forwarding or mailbox rule that sends messages to an external address, especially immediately after a login from an unknown location.
  • Impossible trip where you log in with the same account from two different countries within minutes.
  • Repeated multifactor authentication prompts that are not user-initiated often indicate MFA fatigue or push bombing.

Behavioral analytics and anomaly detection help uncover these warning signs, even if the phishing email appears completely legitimate.

Correlate activity across the environment

A single suspicious login or endpoint alert may not mean much on its own. However, when identity, email and endpoint activity are correlated, it is much easier to detect an active phishing attack before it escalates. Pay attention to:

  • A user logs in from a trusted device, but the endpoint immediately starts launching PowerShell scripts or other unusual processes.
  • A user logs in successfully and then immediately attempts to access systems, applications, or data they have never used before.
  • A sudden increase in outbound email from an account that typically only sends a handful of internal messages per day.

Automated threat correlation connects these signals across email, identities and endpoints, helping MSPs detect active phishing attacks faster while reducing alert fatigue.

Detect faster, react earlier

The earlier an attack is detected, the less opportunity an attacker has to expand their access. Once credentials are compromised, every minute counts.

  • Automatically flag and investigate suspicious account activity before attackers can move laterally.
  • Isolate compromised endpoints to prevent the spread of malware.
  • Disable compromised accounts or terminate active sessions before additional data is accessed.

Faster detection and response reduces attacker dwell time, improves incident response efficiency, and helps MSPs contain phishing attacks before they become costly security breaches for their customers.






Traditional email gateway

Modern phishing defense

Blocks known malicious senders and links

Detects suspicious identity, email and endpoint activity

Focuses on threats before they are delivered

Continues monitoring after delivery

Relies on known phishing signatures

Detects account compromises, session hijacking and lateral movements

Prevents malicious emails

Detects, mitigates and responds to active attacks

What MSPs can do this week

Here are practical steps MSPs can take to reduce risk and strengthen their customers’ defenses

  • Modernize security awareness training: Run phishing simulations that resemble what AI produces today, not the misspelled, generic templates of five years ago. Training based on ancient examples teaches people to pay attention to the wrong things.
  • Review high-risk requests: Require a phone call or a separate channel to confirm a wire transfer, credential reset, or supplier payment change, no matter how convincing the email looks. This one habit prevents most attempts to compromise work email because it doesn’t rely on anyone discovering anything.
  • Monitor account activity after delivery: Don’t stop at the inbox. Watch out for suspicious mailbox rules, logins from unknown locations, impossible trips, and repeated MFA prompts. These behaviors are often the first indication that an account has been compromised.
  • Measure response time, not just resolution time: Measure how long it takes to detect and contain a suspected compromise. Treat this number with the same weight as the ticket resolution time. A faster response window is what limits the damage once a phishing email passes through the gateway, and it will eventually.

AI has changed phishing. MSPs need to change their defense mechanisms

AI has turned phishing from a filtering problem to a detection problem.

As phishing attacks continue to evolve, the advantage lies with MSPs who can detect and respond before a compromised inbox becomes a tenant breach.

Download the Kaseya Email Security Report 2026 Learn how modern phishing attacks bypass outdated defenses and the strategies MSPs use to stay ahead.

Sponsored and written by cashier.

Leave a Reply

Your email address will not be published. Required fields are marked *