MailGuard Aug 20, 2026, 11:35:08 AM 7 MIN READ

AI Has Changed the Economics of Deception. Has Your Client's Email Security Changed Too?

There was a time when creating a convincing scam email required time, research and a reasonable understanding of the target. Poor grammar was common. Templates were reused. Messages were generic. The attacker often had to choose between scale and personalisation. That trade-off is disappearing. 

Artificial intelligence is making it easier to create convincing content, imitate communication styles, automate research and scale social engineering. Recent warnings from the Australian Securities and Investments Commission illustrate the nature of the problem. ASIC has reported increasingly sophisticated scams involving AI-generated content, fake endorsements and deepfake impersonation. It also reported the removal of 11,964 phishing and investment scam websites during 2025, a 90% increase on the previous year.

For partners, the important question is not whether AI will be used in email attacks. It already is. The question is whether the security architecture protecting your customers' inboxes was designed for an era in which deception can be produced cheaply, quickly and at scale.

AI does not need to invent a new attack

One misconception about AI-driven cybercrime is that it will necessarily produce entirely new categories of attacks. It does not have to. Some of the most damaging techniques are familiar: phishing, credential theft, business email compromise (BEC), invoice fraud, executive impersonation and malware delivery.

What changes is the economics. An attacker can potentially produce more variations of a message, tailor communications to different audiences, refine language, automate repetitive tasks, create more believable supporting material and experiment at greater scale. That makes existing attacks more difficult to distinguish from legitimate business communication.

insert pic

The end of the obvious phishing email

Security awareness training has historically relied on recognisable indicators such as poor spelling, strange formatting, generic greetings, suspicious links and unusual requests. Those indicators still matter. But they should not be treated as a complete detection strategy. AI makes it easier to remove some of the traditional weaknesses in fraudulent communication.

That means a message can be grammatically perfect and still be malicious. It can sound exactly like the person it is impersonating. It can refer to a genuine project. It can use information that is publicly available. It can arrive at exactly the right moment.

The question therefore changes from “Does this email look suspicious?” to “What evidence do we have that this communication should be trusted?”

The real target is trust

Email attacks work because email is trusted. Businesses communicate through it every day. Employees receive invoices, contracts, purchase orders, password resets, meeting invitations, shipping notifications and financial requests.

The majority of these communications are legitimate. That is the attacker's advantage. A fraudulent email does not need to look malicious. It needs to look normal.

Why this matters for Microsoft 365 customers

For many businesses, Microsoft 365 is now the foundation of workplace communication. That makes its security controls an essential part of the defensive stack. But it should not lead organisations to assume that email security is therefore solved.

Microsoft itself is describing a future in which security systems need to continuously perceive, reason and act, rather than simply generate more alerts. Its recent discussion of AI-driven security highlights the need to connect detection and analysis with action.

For partners, this reinforces the value of layered security. The question is not whether a customer has a particular security product. The question is whether their overall architecture is capable of detecting threats that change faster than static rules and known indicators.

What should partners be looking for?

1. How much trust is being placed in the inbox? If employees routinely make financial, operational or security decisions based on incoming email, the inbox should be treated as a high-risk business system.

2. How does the organisation detect impersonation? Can the security stack recognise when an email appears to come from a legitimate person or organisation but contains suspicious characteristics?

3. How quickly are new threats identified? Threats that are generated or modified rapidly can challenge systems that rely heavily on previously known indicators.

4. What happens after a user reports a suspicious message? Detection is only part of the equation. Organisations also need efficient investigation, response and remediation.

5. Are security controls working together? Email protection, identity security, endpoint protection, MFA, user reporting and incident response should not operate as disconnected islands.

AI needs AI on the defensive side

There is an obvious temptation to reduce this conversation to: “Attackers are using AI, so defenders need AI too.” That is directionally correct, but incomplete. The real advantage comes from applying automation and intelligence where humans are least effective.

Humans are good at understanding business relationships, context and intent. Machines are better at analysing enormous volumes of signals consistently and continuously. The future is not humans versus AI. It is humans supported by systems capable of processing far more evidence than a human can reasonably evaluate.

A new conversation for MSPs and resellers

For partners, this creates an opportunity to move beyond the traditional “Do you have phishing protection?” conversation.

Ask customers: “How confident are you that your email security can recognise a convincing message that has never been seen before?”

That question opens a more valuable conversation about capability: real-time analysis, unknown-threat detection, impersonation, investigation, response and integration with the broader security environment.

The partner advantage

Customers do not need another warning that cybercrime is becoming more sophisticated. They need help translating that change into practical security decisions. AI should not automatically mean buying more products. It should mean reassessing whether existing controls are capable of operating at the speed and scale of the threat.

Final thought

AI is not making cybercrime dangerous because attackers suddenly have magical new capabilities. It is making cybercrime dangerous because it can make existing deception cheaper, faster and easier to scale.
That changes the economics of the attack. It should change the economics of defence too.

For MailGuard partners, the message to customers is simple: If attackers can use AI to produce convincing deception at scale, your email security needs to be able to analyse and respond at scale too.

The inbox remains one of the most important trust environments in the business. Protecting it requires more than recognising yesterday's threats. It requires security capable of understanding what tomorrow's threats may look like.

Keeping Businesses Safe and Secure

Prevention is always better than a cure, and one of the best defences is to encourage businesses to proactively boost their company's cyber resilience levels to avoid threats landing in inboxes in the first place. The fact that a staggering 94% of malware attacks are delivered by email, makes email an extremely important vector for businesses to fortify.

No one vendor can stop all email threats, so it's crucial to remind customers that if they are using Microsoft 365 or Google Workspace, they should also have a third-party email security specialist in place to mitigate their risk. For example, using a specialist AI-powered email threat detection solution like MailGuard.

For a few dollars per staff member per month, businesses are protected by MailGuard's specialist, AI-powered zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies your client's intelligence, knowledge, security and defence.

MailGuard provides a range of solutions to keep businesses safe, from email filtering to email continuity and archiving solutions. Speak to your clients today to ensure they're prepared and get in touch with our team to discuss fortifying your client's cyber resilience.

Talk to us

MailGuard's partner blog is a forum to share information; we want it to be a dialogue. Reach out to us and tell us what your customers need so we can serve you better. You can connect with us on social media or call us and speak to one of our consultants.

Australian partners, please call us on 1300 30 65 10

US partners call 1888 848 2822

UK partners call 0 800 404 8993

Keep Informed with Weekly Updates