This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Malicious vs. Defensive: How AI is Changing Cybersecurity

Download resources

About this session

Phillippe Dumont, technical sales specialist at Abnormal AI, argues that generative AI has collapsed the cost of both reconnaissance and message crafting, turning business email compromise (BEC) into the most lucrative, hardest-to-detect email threat. He contrasts phishing, which still forces an attacker through a long post-compromise chain, with BEC, pure social engineering that carries no malicious link, attachment or authentication failure for traditional gateways to catch, and cites FBI data showing over 55 billion dollars lost to it since 2014. He shows how AI-written phishing kits, malicious GPT variants and phishing-as-a-service cut reconnaissance from roughly 40 hours to under a minute per target, then walks through a real multi-week proof-of-concept case where a spoofed 'controller' and impersonated executives nearly moved 916,000 dollars out of a law firm's trust account before Abnormal's API-based detection caught it on three behavioral signals. He closes on defensive AI built from ingested telemetry, feedback loops and per-organization behavioral baselines, plus a live demo of a detected attack. Audience questions press on auditing AI-driven auto-remediation, defensive-AI security, and data residency.

The widespread adoption of generative AI meant increased productivity for employees, but also for bad actors. They can now create sophisticated email attacks at scale—void of typos and grammatical errors that have become a key indicator of attack. That means credential phishing and BEC attacks are only going to increase in volume and severity. So how do you defend against this threat? Join this session to hear how generative AI is changing the threat landscape, what AI-generated attacks look like, and how you can use defensive AI to prevent this malicious AI from harming your organization.

Key takeaways

  • Treat business email compromise as a distinct, higher-priority threat from phishing: it carries no malicious link, attachment or authentication failure for a traditional secure email gateway to flag.
  • Watch for AI-shortened reconnaissance (public profile scraping down to under a minute per target) as a sign attackers can now personalize BEC at scale, not just mass-market it.
  • Treat a sudden 'reply-to' address mismatch as a strong signal of account compromise, since attackers add it deliberately to keep a communication channel if they lose primary access.
  • In wire-transfer approval chains, require independent, out-of-band verification of any newly introduced third party (like a 'controller' or accounting firm) before releasing funds, even when the email thread looks internally consistent.
  • Evaluate behavioral, API-integrated email security as a complement to (not just banners on top of) existing secure email gateways, since banner fatigue means users stop reading warnings.

Speakers

Phillippe Dumont
Phillippe Dumont
Sr. Security Specialist · Abnormal AI
Philippe Dumont brings over 25 years of cybersecurity experience, having built his career with some of the industry's most prominent companies including Q1labs/IBM, FireEye, CarbonBlack, and Randori before joining Abnormal AI as a Sales Engineer… Read moreRead less

Philippe Dumont brings over 25 years of cybersecurity experience, having built his career with some of the industry's most prominent companies including Q1labs/IBM, FireEye, CarbonBlack, and Randori before joining Abnormal AI as a Sales Engineer. Starting his career in 1999, Philippe developed a strong technical foundation through penetration testing and hands-on deployment of diverse security solutions. Since 2011, he has served in sales engineering roles, leveraging his deep technical expertise to bridge the gap between complex security technologies and customer needs. His extensive experience across the security landscape, from offensive testing to enterprise-scale deployments, enables him to deliver tailored solutions that address real-world cybersecurity challenges.

Resources

Tags

More from GoSec 2025

Also from Phillippe Dumont

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.