AI Is Making Phishing Attacks Harder to Spot for Federal Agencies

AI is making phishing harder to spot, and federal agencies are urged to pair ongoing training with technical email defenses.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
AI Is Making Phishing Attacks Harder to Spot for Federal Agencies

Generative artificial intelligence is changing how phishing attacks look, and that is making them harder for workers to catch. A new analysis published October 1, 2026, by Matt Hoadley outlines the risks for federal agencies and their contractors.

For years, security training taught employees to look for misspelled words, awkward phrasing, and generic messages. AI tools are making many of those warning signs outdated.

Attackers can now write polished, natural-sounding messages with far less effort. They can also tailor those messages to specific people, organizations, and situations using public information.

Why Federal Agencies Are a Target

When a federal employee or contractor is targeted, that person may only be the entry point. The bigger goal is often access to agency systems and sensitive or classified data.

With stolen login details, attackers can steal, leak, or change data. They can also impersonate staff or disrupt government services. The attackers may be independent or state-sponsored, with political or financial motives.

In the past, planning an attack took manual research. An attacker had to read LinkedIn profiles, agency bios, and personal websites, then connect the facts.

AI can now analyze large amounts of information quickly and build a believable approach. It can also copy the writing style of a specific person, such as a chief financial officer, by studying their public posts.

The author warns that the most likely threats are ordinary, not dramatic deepfakes. One example is an email that seems to come from a supervisor and mentions real people and projects.

The employee clicks a link, enters a password on a fake page, and is redirected to the real login page. Thinking they made a typo, they log in again without suspicion.

How Agencies Can Respond

Government workers usually take security training once a year. The author says this can become background noise that meets compliance rules but does not change behavior.

Suggested fixes include shorter refresher sessions, manager-led talks about recent incidents, and timely alerts when phishing attempts rise. Authorized phishing simulations can also help employees practice and learn from mistakes.

Training alone is not enough, since some attacks will succeed. Email systems such as Microsoft Exchange can be set to scan messages, attachments, sender domains, and IP addresses. Tools like Microsoft Defender for Office 365 can add protection.

Employees also need simple ways to report suspicious messages. Security teams can then block senders or domains across the agency and warn other staff.

Agencies can also block certain website categories, such as shopping sites, which can include fake lookalike retailers.

The author says none of these steps is foolproof on its own. The recommendation is to combine updated training with several technical safeguards to lower the chance of successful attacks and contain them faster when they happen.

From our research desk
AI Jobs Automation Index
Which jobs are AI tools targeting most? We mapped 3,400+ AI tools to real job functions — with BLS employment & salary data.
Explore the index
maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents