Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

Spear Phishing in the Generative AI Era: Tailored Fraud Tactics and Defensive Architecture

"Frequent typos" and "unnatural phrasing"—the classic hallmarks used to spot phishing emails—are no longer reliable indicators due to the rise of generative AI. Attackers now leverage public information and leaked data fragments to mimic target-specific nuances. They pivot seamlessly across channels—from email to voice and internal chat—aiming to force the final decision. Imagine receiving an email requesting an account change, followed immediately by a call from a "boss" with a highly convincing voice, and then a verification file shared via Teams. Attackers exploit gaps in workflows, time pressure, and human goodwill. This article is not just a general warning. We deconstruct the attacker's generative AI workflow and map out specific defensive countermeasures (technical, operational, and human) for each phase. Building on technical foundations like SPF, DKIM, and DMARC, we detail a dual-verification playbook that defines "who verifies what, how, and when to halt the process" by department. We also cover dashboard metrics to drive continuous improvement, such as training frequency and KPIs, escalation MTTR, and account change process compliance rates. Now that generative AI has automated highly persuasive attacks, defenders must also automate and standardize their decision-making procedures. This is the core philosophy of Yagura. As lower attack costs exponentially increase attack volume, organizations that fail to leverage generative AI in their defense risk being left behind. That is why Yagura provides a unified approach: research-driven consulting paired with software that supports playbook implementation. Our goal is not just "awareness," but repeatable prevention. This article has two goals. First, to understand the attacker's methodology in constructing highly personalized spear-phishing emails. Second, to help you design defenses of equal granularity and provide you with notice templates and checklists that can be deployed internally starting tomorrow. A "3-Step Action Plan for Tomorrow" is summarized at the end of each section.

AI SOCとは? 仕組み・従来型SOCとの違い

The "Highly Convincing" First-Thing-in-the-Morning Email

The sender is a supplier you exchange messages with every week. The subject line contains that specific phrase from last week's meeting. The body naturally weaves in department names, ongoing projects, and even your manager's favorite phrases, with no unnatural Japanese in sight.
Today's spear-phishing emails arrive tailored to each individual employee—essentially completely made-to-order.

How to Read This Article and Scope (Yagura's Analysis Policy)

This article is intended not only for IT and security departments of Japanese enterprises (practitioners in their 30s to 50s) but also for operational leaders in departments where daily email communication is central to operations, such as accounting, purchasing, executive administration, and customer support. The theme is the intersection of spear phishing and generative AI. We will cover technical defenses like email authentication, URL analysis, and account protection, alongside operational workflows like approval chains, callback verifications, and reporting structures at the same level of resolution. By the end of this article, you will have templates ready for immediate company-wide notifications, the core components of a KPI dashboard to track training progress, and an incident response initial checklist. If you are short on time, you can construct a solid defense framework just by reading the "3 Action Items for Tomorrow" at the end of each section. If time permits, we highly recommend reading chronologically, from real-world cases to playbooks and KPI design.

Why "Made-to-Order Phishing Emails" Exist: What Generative AI Changed

The Turning Point: Traditional vs. Modern Attacks

The key to understanding this change is that the very method of creating attacks has evolved. While the mainstream approach was once to blast identical templates en masse, modern attacks are optimized for individuals, reproducing department names, job titles, active projects, and even company-specific jargon. Unnatural language is no longer a reliable detection indicator. Furthermore, attacks do not end with a single email; they are immediately followed by deepfake voice calls or "confirmation nudges" on internal chats, creating intense time pressure to force hasty decisions. In addition, recipient responses—such as opens, replies, and out-of-office autoreplies—are used as training data to continuously tune the tone, subject lines, and send times.

The Sources of Material (Attacker's Perspective)

Where does this highly convincing information come from? First, there is open-source intelligence (OSINT) such as social media, IR disclosures, press releases, presentation materials, recruiting pages, and corporate registries. Second, there are leaked fragments of past emails, signature templates, and meeting agendas. Third, there is information that organizations unconsciously expose externally, such as direct lines other than main office numbers, personal emails, and calendar fragments. By combining these, attackers craft messages based on real people and actual business matters.

Why Detection Is Becoming Harder

When honorifics and business vocabulary become natural, typos disappear, and actual project names are inserted, detection methods relying on superficial rules can no longer keep up. When elements like an executive’s verbal habits, an administrative assistant’s standard phrasing, or a supplier's signature style are perfectly replicated, it creates a powerful cognitive bias where the recipient assumes the email is legitimate.

Real-World Example: "Merge Variables" Used by Attackers (Selection)

In actual attacks, specific variables are dynamically inserted to mimic target-specific information, including department names, titles, recent project names, internal approval numbers, managers' catchphrases, and company jargon. For transaction-specific details, attackers replicate invoice numbers, contract IDs, billing portal names, payment portal URL structures, and even the exact kanji characters of account names. Furthermore, they leverage time-specific variables—such as month-end close, quarterly earnings, audit responses, and the eve of public holidays—to make recipients feel they must act immediately.

Mock Email Example (Excerpt: Replicating "Authenticity")

Subject: URGENT: [Approval No. RG-24-031] Request to Change Payment Account (Inspected/Accepted)
Sender Name: S-Corp Sales Division [Name] (*Spoofed display name)
Body (Excerpt):
Dear Mr./Ms. K, [Department Name] [Section Name]
Regarding the recent estimate (No. 2025-0712A), could you please update our account name by the end of today for audit compliance? I have already shared this with Manager M. We will apply an early payment discount if this is processed ahead of schedule. The approval number is indeed RG-24-031.
New Account: [Bank Name] [Branch Name] Ordinary Account 1234567 (Yagura Security)

3 Action Items for Tomorrow

  1. Audit Public Information: Identify and remove instances where job titles, direct contact information, and project names are exposed together.

  2. Standardize Signature Templates: Limit variable fields, such as mobile numbers and abbreviations, to a minimum.

  3. Dictionary-Based Time Pressure Filtering: Automatically route emails containing terms like Urgent / By end of today / Prepayment / Account change to an isolation queue.

Deconstructing the Attacker's "Generative AI Workflow" (Mapping 1:1 with Defense)

1) Reconnaissance (OSINT) and Relationship Mapping

Attackers begin their workflow with information gathering. They target details such as job titles, areas of responsibility, typical approval thresholds, recent project names, suppliers, approval workflows, business travel schedules, and internal jargon, gathering them from social media, news releases, registry/IR information, recruiting pages, technical blogs, and public calendar entries. By cross-referencing this data, they build an organizational relationship graph connecting decision-makers, influencers, and execution teams, allowing them to target departments like accounting, purchasing, executive assistants, and customer support. For defenders, establishing a data minimization policy and controlling the exposure of internal nouns like project names and company jargon is the starting point of protection.

2) Persona Generation and Extracting "Authenticity"

Once the information is gathered, attackers move to the "persona generation" phase to model vocabulary, levels of politeness, signature styles, frequent contacts, and typical sending times. Writing styles are cloned using public speeches, past email fragments, and internal style guides. To counter this, defenders should standardize email signature templates to reduce variable elements and establish verification protocols and security keywords as fixed procedures rather than relying on human memory.

3) Prompt Engineering and Variation Generation

In the final phase, attackers combine objectives (wire transfers, account changes, urgent orders, credential harvesting) with roles (managers, auditors, key accounts) and tones (polite, urgent, casual) to generate a massive volume of variations. They optimize these through A/B testing, treating subject lines, names, and real project names as variables. Additionally, they prepare companion assets, such as deepfake audio scripts or Teams/Slack follow-up templates. Defenders must counter this by flagging time-pressure keywords, automatically tagging messages, and routing them to isolation queues.

Example of Prompt Engineering (Attacker's Perspective)
Optimize open and reply rates by running A/B tests on subject lines (e.g., "Audit Compliance" vs. "By end of today"), greeting variations (Last Name + Title), and the inclusion of real project names.

Operational Guide (Deep Dive)

Technical Details: Operating DMARC / BIMI / ARC

First, implement DMARC with p=none and review RUA/RUF reports weekly. Identify and authorize legitimate senders, then gradually transition to quarantine and eventually reject. For critical senders, consider applying adkim/aspf=strict. For BIMI to function, DMARC must be set to reject or quarantine. Preparing an SVG Tiny P/S logo and securing a VMC (if necessary) deters brand spoofing while improving employee visibility and security awareness. If DMARC fails due to forwarding or mailing lists, ARC provides the solution. You should deploy an ARC-enabled SEG or standardize workflows to manually release emails after temporary isolation.

Detection Rules Recipe (SEG/SIEM)

For practical detection rules, first isolate emails containing time-pressure keywords in the subject or body: subject/body ~ /(Urgent|By end of today|Audit compliance|Prepayment|Account change)/. To counter lateral movement where identical subject lines are sent from the same domain in a short window, use the condition same_subject & same_domain within 10m >= 5 to automatically draft a company-wide warning template. For display name spoofing targeting executives, route emails matching display_name in {Executive Name List} & sender_domain != corp to high-priority review. Finally, send shortened URLs (such as t.co, bit.ly, or is.gd) to a delayed analysis queue to evaluate the destination after link expansion.

Key Points for Approval Workflow Design

The foundation of approval workflows is to divide authorization into three financial thresholds (e.g., $5K / $30K / $100K) and assign fixed approvers. For exceptions, require department head approval alongside a formal record. For transactions flagged with terms like Urgent or By end of today, mandate a minimum 30-minute cooling-off period (timeout), extending this window on the eve of holidays/weekends. For secondary verification, ensure audit trails are thoroughly documented, including ticket generation, logging, and three-way matching of approvals, invoices, and purchase orders.

Incident Response Initial Checklist

  1. Isolate: Isolate suspicious emails at the SEG level (do not open attachments).

  2. Report: Report to the CSIRT using the tag #SuspectedBEC (duplicate reports are acceptable).

  3. Secondary Verification: Confirm legitimacy or denial by calling the registered main office number first, then the contact's internal extension.

  4. Halt: Freeze payments and purchase orders until dual-authorization is completed.

  5. Notify: If lateral movement is detected, broadcast alerts using pre-configured company-wide warning templates.

  6. Record: Save the timeline, decision-making rationale, and evidence (screenshots/logs) within the incident ticket.

Glossary

BEC stands for Business Email Compromise. OSINT refers to open-source intelligence gathered from public resources such as recruiting pages, IR documents, and presentation slides. DMARC, SPF, and DKIM are the foundation of email sender authentication, while ARC preserves this authentication across email forwarding environments. Finally, the term timeout referenced throughout this article refers to an intentional delay introduced to neutralize psychological time pressure.

Recommendations from Yagura (Summary)

As generative AI continues to evolve, the sophistication of phishing emails will only increase. Lower attack costs will lead to an exponential rise in attack attempts. If defenders fail to leverage generative AI, this gap will directly translate into security risks. That is why Yagura integrates research with real-world implementation to deliver reliable, reproducible defense.

3 Action Items for Tomorrow (Summary)

  1. Technical Foundation: Finalize your DMARC phase-in roadmap (none -> quarantine -> reject, with weekly RUA/RUF reviews).

  2. Operational Standards: Formalize time-pressure isolation rules and timeout protocols in your playbook.

  3. Visibility and KPIs: Run weekly dashboard reviews tracking training frequency, MTTR, and account-change compliance rates.

Related Services: Learn more about Yagura PhishAI, which uses AI to instantly analyze and verify employee-reported emails, helping security teams investigate the scope of impact and contain similar threats.

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。