Kaseya Advises MSPs on Detecting AI-Powered Phishing That Bypasses Email Filters
New guidance emphasizes monitoring identity, email, and endpoint activity to catch sophisticated attacks.

Key Takeaways
- AI is making phishing attacks more personalized and harder for traditional email filters to detect.
- MSPs should monitor identity, email, and endpoint activity to catch attacks that bypass the inbox.
- The guidance is advisory, with no specific CVEs or incidents cited.
- Proactive detection and rapid response are critical to mitigating the impact of successful phishing.
Quick answers
- What happened?
- Kaseya has published guidance for Managed Service Providers (MSPs) on detecting and containing phishing attacks that evade traditional email filters. With AI enabling more personalized and convincing lures, the vendor recommends monitoring identity, email, and endpoint activity to identify and respond to threats that reach the inbox.
- What should defenders do?
- MSPs should implement monitoring of identity, email, and endpoint activity to detect anomalies indicative of phishing. This includes reviewing login patterns, email rules, and endpoint behaviors. Rapid response protocols should be in place to contain any detected compromise.
On August 20, 2026, BleepingComputer reported on new guidance from Kaseya aimed at helping Managed Service Providers (MSPs) combat phishing attacks that slip past conventional email security. The advisory highlights how AI is being used to craft highly personalized and convincing phishing messages, making them harder for traditional filters to detect.
Kaseya's recommendations focus on a multi-layered detection approach. MSPs are urged to monitor identity, email, and endpoint activity to spot anomalies that may indicate a successful phishing attempt. This includes watching for unusual login patterns, email forwarding rules, or endpoint behaviors that suggest compromise.
The guidance is advisory in nature and does not reference specific incidents or CVEs. It underscores the growing challenge of AI-enhanced phishing and the need for proactive monitoring beyond the inbox. For MSPs, the key is to assume that some phishing emails will get through and to have mechanisms in place to detect and contain the fallout quickly.
While no specific patches are mentioned, the emphasis is on enhancing visibility and response capabilities. By correlating signals across identity, email, and endpoints, MSPs can better protect their clients from credential theft, data breaches, and subsequent ransomware deployment.
Security Details
The article discusses the growing threat of AI-personalized phishing and the need for MSPs to implement layered monitoring. No specific technical details of attacks are provided, but the guidance emphasizes correlating identity, email, and endpoint signals to identify compromises that bypass email filters.
Mitigation
MSPs should implement monitoring of identity, email, and endpoint activity to detect anomalies indicative of phishing. This includes reviewing login patterns, email rules, and endpoint behaviors. Rapid response protocols should be in place to contain any detected compromise.
Sources
BleepingComputer
How MSPs can catch phishing attacks email filters miss
Aug 20, 2026 · 14:01
Original link
Related Security News

AI Chatbot Manipulation Campaign Targets Users via Disinformation and Phishing
Security researchers have identified a coordinated campaign in which attackers are manipulating responses from major generative AI platforms, including ChatGPT, Gemini, and Google AI Overview. The operation involves seeding the web with malicious links and data, then optimizing content to influence AI outputs. The goal appears to be amplifying disinformation and directing users to phishing sites designed to harvest credentials.




