Phishing 3.0 is Here: The AI Cyber Arms Race
The cybersecurity landscape is shifting at breakneck speed, and the days of simply defending the email gateway are long gone as we enter the era of agentic AI. Broadcasting live from RSAC, Techstrong Group’s Alan Shimel sits down with Ironscales CEO and Founder Eyal Benishti to discuss the terrifying reality of “Phishing 3.0″—a new wave of highly contextualized, multimodal attacks supercharged by artificial intelligence. Benishti breaks down the findings of their latest report, revealing that a staggering 80% of organizations have already suffered a trust-breaking business communication breach, and explains why defenders must leverage advanced AI to combat the asymmetric advantage of modern threat actors.
Transcript
Hi, everyone. We're back here live at "Techstrong TV" at RSAC with our continuing coverage here at Moscone West. There's a little bit of a lull.
I think there's a keynote going on there, so there's a lot of people in there. Traffic, I'm sure people heading to sessions or lunch. Let me introduce you to my next guest.
His name is Eyal Benishti. Yeah. Eyal is the CEO of a company called Ironscales.
Eyal, it's great to have you on again. It's great to be here. It's been a while.
Quite inviting. Yeah. Yeah.
It's been a minute. You got to come more often, not just RSA. As you told them twice a year, you say, huh?
Well, we do these every day. Well, not in person. Yeah.
But we do them virtual, and we do about three to four hours of video a day. Oh, wow. A lot.
Not just myself. No. But we do a lot.
It's been impressive. A lot of video. Eyal, let's start a little bit with you.
I mentioned you're the CEO of Ironscales. Yeah. But give people a sense of kind of what your journey's been like.
So I started a business, I'm founder and CEO, started a business about 12 years ago back in Tel Aviv, with kind of the mission to fix email security. Felt that it was broken. A lot of the stuff that I was kind of reversing and researching was coming via email.
So I realized that we really need to find a new, better way on how to kind of make sure that phishing stays outside of the employee mailbox space. And decided to start Ironscales with a mission to make email security much more powerful and much simpler than it used to be. Took email security from the gateway level down to the mailbox level and said, "Hey, let's stop focusing on the threat.
" So build a lot of behavioral models in order to identify emails that maybe are not bad by content. There is nothing necessarily malicious in the file of the link, but the intent is malicious. Uh-huh.
They're trying to lure them do weird stuff like, wire money, pay invoices, do all this kind of fun stuff that the traditional secure email gateways were not able to detect and stop. And pretty much pioneered this kind of new category that at some point Gartner called integrated cloud email security, and now it's part of the email security platform. New category.
Yeah, it's been a fun journey. Absolutely. So, this is a very familiar pattern that I see with founders.
And let me move this thing because I might be cutting off your camera angle. I apologize. Founders recognize a problem.
They recognize a problem. They have that problem. But they realize they're not the only one with that problem.
This is a problem, and it is a problem that needs to be solved. And that's what drives the passion- Mm-hmm ... for founding the company, for doing what they need to do.
And that's obviously what drove your path. But again, I study founders and startups, not as a hobby. I do it for a living here.
That's enough to get the company founded. There's that initial vision, that mission. But over time, things change.
It grows. It morphs. It pivots.
Market fit, all things that come in. As you sit here today and you look back to your original vision, what has changed? What's grown?
What's stayed the same? It's a great question because we are really in a pivotal point where, about a decade after we've started the company, it seems like the threat landscape is shifting again in a dramatic way, and we're- Is that your way of saying AI? Look, we started as a AI company.
Uh-huh. Now it's generative AI is the new thing. Right.
And agentic AI. These are kind of the new things that are kind of driving cybersecurity and how we think about what it takes in order to keep companies secure. But yeah, look, AI is everywhere.
If you walk on the floor, not in West, but in the main show, you will see- Yeah ... like AI everywhere. Well, you see it here too, believe me.
You can't escape. You can't walk down the street without seeing it on the billboards and the phone books. And it's very easy to say AI- Buzz stuff ...
and it's much harder to explain how you implement AI now to really solve a problem and not just try and kind of wrap something with some nice shiny buzzwords and- Mm-hmm ... and features. So yeah, AI was always kind of in the core of what we are doing and how we are tackling the issue because it is a powerful tool, and I call it a tool because I totally believe that it's a tool.
It's not a solution. It's not a solution. Right.
Yeah. It's not a bullet point, it's not a silver bullet to any of the problems that we are trying to solve. But it's important.
It's there. Again, it's a super powerful technical control. It's not replacing the need to take care of the human kind of element inside the organization at all.
Humans are still part of the solution, the way we saw it and we still see it at Ironscales. So we want to make sure that we are leveraging this tool in order to help solving the technical and non-technical pain points and challenges that organizations are experiencing these days. I love it.
Now, before we go to this survey and research that you had done, Ironscales, what's the website? com. com.
Yeah. com. Okay.
You guys recently had a report out based on some survey data and research you had hired a company to do with. Give us an idea, first of all, why did you do it? To your question earlier, which was a great question, I know.
0 era. Okay? From the gateway and secure level gateways to the mailbox and advanced AI and behavioral models in order to stop phishing.
0, and we really wanted to run the survey to see, again, to validate a lot of the things that we are seeing. 0. 0, it's this new type of phishing that is multimodal, it's highly contextualized, it's happening over different channels of digital communication for businesses.
It's not just an email problem- Sure ... anymore. 0, again, it's a much, much bigger problem than just email phishing.
So we ran the survey because we want to see how different organization, how they think about it. Are they suffering any damage or loss? Because we don't want to go and solve a problem that doesn't exist, or it's not a big enough problem for our customers.
So we sponsor this research in order to get some more information. I love it. I always like to say every report always says three key things.
Tell me the three key things that you see in this, that came out in this one. I think that the three key things is first, that the problem is real. Like in organizations, they are experiencing, the loss is significant, and I think the most important thing, they're willing to do something about it.
" Excellent. There's always something in every report, though, that you didn't have on your bingo card. Right?
It would surprise you. It didn't seem that that was going to be what it was. Anything in here that it would surprised you?
I think that the fact that about 80% of them have said that they've experienced some trust, kind of a trust issue in their environment. Like trust was broken in one way or another over business kind of communication. That really took me back a little bit because we knew that- That's a crazy 80.
Over 80. That's critical mass. Everyone.
Honestly, I didn't think that the number will be that high. No. If I had to guess, it was something in the 30s.
So that's the one thing that I wasn't expecting to see out of this survey. I love it. Where can people get the report?
com, but- It's on our website Right front page? Yeah. Come to the website, and you will be able to download the full report.
It's a very interesting report. So we all think AI is important. It's changing things.
As you said, you were doing AI, ML, and all of that. Now agentic and- Yeah ... generative.
But you come here to this conference and it's all about AI this year, and agentic AI. How does that make you feel? Vindicated, like, "Yeah, we're right.
" I think we need to, again, we need to be careful when we are kind of trying to say AI or throw AI on everything. Let's really try and understand, again, what's the real attack surface? Or what really change in the way that threat actors are basically launching their attacks?
What's the right approach? " I think when you look at where we started, we knew that threat actors are using AI to attack organization. That's nothing new.
And we use AI in order to stop these type of attacks. Now we are stepping into a new kind of situation where threat actors are using agentic AI, which is autonomous agents that can just go and do some stuff from collecting information, weaponizing this information, do the entire ideation phase and execution, and it's really mind-blowing, like what agentic AI. And we're just starting.
We're just scratching the surface. You're preaching to the choir. I use it myself, and it's like addicting already.
It is. Because it sucks you in. You just, where does the time go?
You gotta run, but wait, it's just almost finished working, right? Exactly. That's what we do.
It's very powerful, and it's- Yes, it is ... getting cheaper and cheaper, by the way. Yeah.
A lot of it is open source and accessible- Yes, it is ... for everyone. But you do have to be careful with the open source because look, these are non-deterministic agents that learn, and so from a security point of view, sometimes the open source stuff, right, you got to do a little research on what's the best way to lock that down.
But think about the attackers, not the defenders. They don't need to be successful- No ... 100%, or so they can use the cheap stuff.
No. They give you one out of 10, one out of 100. They're making out money like mad.
Exactly. So there is always this asymmetric kind of situation where they can use cheaper kind of models in order to attack us, but we need to use the more expensive models in order to defend. But that's the- But that's the nature of this ...
that's the nature. I agree. Not gonna- I agree.
That's the one thing that will never change no matter what type of technology is going to be introduced next year. I agree. Hey, I just want to make sure we covered everything here, Yahav.
We got the report. It's on the first page. So when are we going to see you again?
Before next year, I hope. I hope so. I'm going to hold you to that.
Okay? All right. Absolutely.
Thank you very much. com. Go check them out.
Check out this report, too. There's some interesting information there. As we said, some of it to be expected, but some of it's surprising.
We're going to take a break. I think we've got maybe a half-hour break in the program. We'll be back, though.
We've got full day of coverage today, tomorrow, the day after that. We're live at RSAC. I'm Alan Shimel.