JupiteX Get the app
Science & Technology19 Aug 2026 · about 7 min

Phishing 3.0: The Fight Moves to Agent Versus Agent

The brief

Phishing 3.0 is a useful name for the next stage of phishing described by the article: AI appears on both sides of the email battle. Earlier defenses searched for harmful payloads, such as links or attachments. Newer attacks can exploit what a message is trying to make someone believe or do. That shift makes intent central. “Agent versus agent” refers to automated systems working against one another. An attacker’s AI agent can generate messages, adapt language, and target recipients. A provider’s or security team’s AI agent can inspect behavior, identity, context, and requests. The conflict is no longer simply a person sending a suspicious file to a person. The article does not provide a formal definition or technical boundary for “Phishing 3.0.” It does clearly describe the transition from bad content to bad intent, followed by AI-generated senders and AI defenses. The likely implication is an ongoing contest between adaptive attackers and adaptive defenders.

01

What does “Phishing 3.0” mean, and what does “agent versus agent” refer to?

Phishing 3.0 is a useful name for the next stage of phishing described by the article: AI appears on both sides of the email battle. Earlier defenses searched for harmful payloads, such as links or attachments. Newer attacks can exploit what a message is trying to make someone believe or do. That shift makes intent central.

“Agent versus agent” refers to automated systems working against one another. An attacker’s AI agent can generate messages, adapt language, and target recipients. A provider’s or security team’s AI agent can inspect behavior, identity, context, and requests. The conflict is no longer simply a person sending a suspicious file to a person.

The article does not provide a formal definition or technical boundary for “Phishing 3.0.” It does clearly describe the transition from bad content to bad intent, followed by AI-generated senders and AI defenses. The likely implication is an ongoing contest between adaptive attackers and adaptive defenders.

02

How has phishing evolved from malicious links and attachments to attacks based on message intent and AI-generated senders?

Early phishing commonly placed danger in a message’s payload: a malicious link or attachment. Traditional defenses could scan that content and block known threats. The article calls this “Phishing 1.0,” where the danger was relatively tangible and located inside the email.

The next stage moved the danger into the message’s intent. An email could contain no obviously harmful file or link, yet still manipulate someone into transferring money, revealing information, or changing a process. The important mechanism became social engineering: the request looked legitimate, while its purpose was harmful.

The article then describes a newer change: “the sender is no longer a person.” AI can generate or operate senders, making phishing more automated and potentially more adaptive. The source does not give detailed examples or dates for each stage. It does establish a clear direction: from bad content, to bad intent, to AI on both sides of the defense.

03

How much more quickly and widely can an automated AI agent create and send personalized phishing messages than a human attacker?

The source does not state an exact speed or reach advantage, so no reliable numerical comparison can be calculated from it. Its central point is that an automated AI agent can replace the human sender. That removes much of the time required to write, adjust, and send messages one at a time.

A human attacker might manually tailor a message for each target, then send it through a limited process. An AI agent can generate many variations, use available recipient information, and deliver them through automated workflows. Personalization therefore becomes a repeatable operation rather than a scarce human task. The mechanism is scale: software can perform similar actions continuously and rapidly.

This matters because volume and variation can make detection harder. More messages create more opportunities for a victim to respond, while changing wording can reduce reliance on obvious signatures. Still, the article does not quantify the increase in messages per hour, recipients, or success rate. Any exact figure would require evidence beyond the provided text.

04

Why can’t traditional email defenses that scan for malicious links or attachments reliably detect phishing based on intent?

Traditional defenses were designed to find malicious content inside an email. They scan links, attachments, and other recognizable indicators, then block the message when something appears dangerous. This approach worked better when the threat was located in the payload, as the article explains.

Intent-based phishing can avoid those signals. A message may contain a normal link, no attachment, and ordinary language, while urging a harmful action. For example, an attacker might imitate a manager and request an urgent payment using a familiar-looking process. The key mechanism is deception: the email’s danger comes from what the recipient is persuaded to do, not necessarily from a file or link.

Reliable detection therefore requires more than payload scanning. Systems may need to examine sender identity, relationship history, unusual requests, timing, and organizational context. The article does not list specific detection methods, so these are established security practices rather than stated article facts. Its main warning remains clear: bad intent can pass through defenses built only for bad content.

05

What happens when AI agents are used both to create phishing attacks and to defend against them?

When AI agents create phishing and other AI agents defend against it, email security becomes an ongoing contest. The attacker’s system can produce messages and potentially adjust them for different targets. The defender’s system must identify suspicious behavior even when each message looks slightly different. This raises the stakes beyond fixed rules.

For example, an attacking agent could generate a convincing request that avoids a malicious attachment. A defensive agent could compare the sender’s identity, communication history, wording, timing, and requested action with normal patterns. Its key mechanism would be continuous analysis rather than a single scan. Detection must focus on whether the whole interaction makes sense.

The article says defenses are already failing as the sender becomes nonhuman, but it does not describe a specific AI defense product or outcome. The forward implication is an arms race. Defensive systems may become faster and more adaptive, while attackers may generate more varied and convincing messages. Human review and strong verification remain important when systems cannot confidently judge intent.

06

Which actors are involved in this new form of phishing, and what roles do attackers, email providers, security systems, and AI agents play?

Attackers are the people or organizations seeking to deceive recipients. AI agents become their operational tools, generating messages, impersonating senders, or automating delivery. Recipients remain important because phishing succeeds when someone trusts a false message or follows its request. The article’s major change is that the sender may no longer be a person.

Email providers sit between senders and recipients. They transport messages and can apply authentication, reputation, filtering, and abuse controls. Security systems analyze signals and decide whether to deliver, quarantine, warn about, or block an email. Defensive AI agents can help interpret patterns that simple payload scans miss. Their role is to detect bad intent, not just bad files.

The article explicitly supports the shift from human senders to AI and from content checks to intent checks. It does not provide a complete actor map or assign detailed duties to each participant. Those roles reflect standard email-security practice. The central relationship is adversarial: attackers automate deception, while providers and defenders automate trust decisions.

07

How do email systems determine whether a sender, message, or request should be trusted?

Email systems do not rely on one trust test. They commonly check whether the sending domain is authorized, whether the message’s cryptographic signatures are valid, and whether the sender has a good reputation. They may also inspect links, attachments, language, delivery patterns, and known abuse signals. These checks estimate whether a sender or message is legitimate.

For a request, systems and organizations can compare the sender with prior conversations, examine unusual timing or wording, and ask whether the requested action fits normal behavior. Stronger controls may require a separate confirmation channel for payments or sensitive changes. The key mechanism is combining independent signals, because any one signal can be forged or incomplete.

The article specifically criticizes defenses that mainly scan for malicious links or attachments. It does not explain authentication standards or give a trust-scoring method, so these details come from established email-security practice. Its broader lesson is that trust must include intent and context, especially when AI can generate plausible senders and messages.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web