AI is making phishing boring again (and that is the problem)
Threat Intelligence

AI is making phishing boring again (and that is the problem)

Mathew Potter

Security Analyst

August 19, 2026

Every year someone declares that AI will "revolutionize" security. Most of that is noise. The part worth paying attention to is simpler: it is cheaper to write a believable email than it used to be.

What changed

IBM's Cost of a Data Breach report this month framed frontier AI models as shifting the threat landscape. You do not need to agree with every headline metric to see the pattern in your own inbox. Partner-tone requests. Urgent wire instructions. Fake DocuSign flows. They look polished because the drafting cost dropped.

AXA XL and others have warned that MFA alone is not a finish line when phishing is tuned to harvest tokens in real time. MFA still matters. It is just not the only control.

Why law firms feel it first

Legal work runs on email and trust. A message that sounds like a partner or a general counsel assistant gets acted on fast. Associates paste matter details into public AI tools because it saves time. Clients ask what AI you use on their files. The risk committee asks for a policy you do not have yet.

None of that requires a vendor pitch about "AI-powered defense." It requires clear rules, logging, and periodic testing of the channels you actually use.

Practical steps

  • Turn on impersonation protection in your mail platform if you have not already. Review DMARC, SPF, and DKIM while you are there.
  • Publish a short AI use policy: what may go into external tools, what may not, and who approves exceptions.
  • Run a phishing exercise that includes voice and SMS, not just links.
  • Get an external review before you answer a corporate client's security addendum. Guessing on a questionnaire is how firms lose work.

Closing thought

AI did not invent social engineering. It scaled it. The firms that stay out of the news are usually the ones doing unglamorous work: access control, logging, training, and an occasional independent assessment to prove the basics are real. That is the lane Forensic Five stays in. Happy to scope a review if you are feeling the renewal or questionnaire pressure this fall.

Tags

AI phishing BEC law firms security awareness

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.