Spear Phishing stories
A surge in non-human identities is leaving businesses more exposed, with privileged access risks now stretching beyond staff to AI agents and machine accounts.
Boards are being told that identity controls and staff training must catch up as AI makes phishing, impersonation and account takeovers harder to spot.
Targeted phishing and payment fraud are getting harder to spot as attackers mimic routine business workflows and trusted contacts.
Smaller operators are carrying much of the danger as a new study finds 66% of assessed US telecoms fall into an elevated risk band.
Downstream AI alerts in Australia and New Zealand are rising as agents and MCP links create fresh routes for sensitive data leakage.
Defenders now have minutes, not hours, as attackers use agentic AI to automate credential theft, scanning and extortion across live operations.
AI tools are exposing smaller firms to faster scams and data leaks, making basic controls and staff training vital to stay resilient.
Only 20% of Australian organisations say they fully understand AI cyber risks, leaving boards exposed as phishing and deepfakes grow more credible.
The hire gives the cybersecurity firm a seasoned customer-facing adviser as enterprises grapple with more convincing phishing and impersonation attacks.
Smaller firms could face more frequent attacks if access to advanced models stays limited to government agencies, Huntress says.
Many New Zealanders are sharing sensitive data with chatbots despite fearing AI fakes, leaving them exposed to scams and data leaks.
Phishing emails can still slip into Microsoft 365 mailboxes when attackers leave the SMTP envelope sender blank, ReliaQuest has found.
New Zealand users risk fake login pages and scam sites after ChatGPT search results were found pointing to unsafe links and downloads.
Banking groups are increasingly paying for rapid removal of phishing and impersonation scams as AI-driven attacks spread across multiple channels.
Microsoft security teams can now ingest email authentication signals in one place, helping spot phishing and spoofing sooner during investigations.
Spoofed emails could still reach public servants and citizens, as 50% of more than 200 New Zealand agencies have not met the DMARC standard.
Most of Southeast Asia's biggest firms still leave customers exposed to spoofed emails, with only 17% enforcing the strictest DMARC setting.
The fake acquisition pitch pushed an Avast employee towards a EUR €626,735.45 wire, exposing a broader impersonation scam across several industries.
Australian firms are being urged to tighten payment checks as email impersonation scams drive AUD $166.8 million in losses.
Australian firms still face email compromise and poor security hygiene, even as AI helps criminals move faster and hide harder.