
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Threat actors are using a new 'Conversation Overflow' technique to bypass AI- and machine learning-based email security systems. By embedding hidden benign text in phishing emails, attackers trick AI filters, allowing malicious messages to reach victims and resulting in credential theft and data breaches within enterprise networks.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves AI systems explicitly (AI/ML-enabled security platforms) and their use in cybersecurity. The attackers exploit the AI systems' detection mechanisms to bypass security, leading to phishing attacks that cause harm (credential theft). This constitutes an AI Incident because the AI system's malfunction or limitation directly contributes to the harm. The article details ongoing attacks, not just potential risks, so it is not an AI Hazard. It is not merely complementary information because the main focus is on the attack method causing harm, not on responses or broader ecosystem context.[AI generated]