What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AI is making social engineering more convincing and easier to tailor, while AI agents add a separate risk: an agent that reads hostile content and can use connected tools may be manipulated into unsafe actions. Those risks are converging, but current reporting does not show that autonomous agents commonly run business email compromise (BEC) campaigns end to end. For companies, the practical response is to verify sensitive requests independently, protect identities and sessions, and tightly limit what agents can do.
What is AI-powered business email compromise?
Business email compromise is fraud or intrusion that exploits business email, identities, or trusted workflows. An attacker may impersonate an executive or supplier, take over a real account, or manipulate an employee into changing payment details or disclosing information. AI can help with reconnaissance and tailored messages; it does not, by itself, make an email genuine or prove that a particular attack used AI.
Google Threat Intelligence Group reported that threat actors were using AI to gather information and create realistic phishing scams. That supports a claim about AI-assisted deception, not a claim that autonomous agents are routinely conducting BEC from start to finish. Google Threat Intelligence Group’s February 2026 report describes the observed misuse.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →It helps to keep four mechanisms distinct:
- AI-assisted persuasion: AI may help attackers research a target or produce plausible, personalized text, audio, images, or video.
- Account or session compromise: Stolen credentials or hijacked sessions can make a fraudulent request appear to come from a real account.
- Prompt manipulation: Malicious instructions embedded in content may try to steer an AI agent that reads or processes it.
- Excessive agent permissions: If an agent can take consequential actions without adequate limits or review, manipulation or error can have a larger impact.
These risks can overlap, but they are not interchangeable. A polished message is not proof of AI use, and an agent that can be manipulated is not necessarily part of a BEC campaign.
#1 Best Overall
What do the 2026 figures show—and what don’t they show?
The available figures describe particular surveys, incident samples, and prompt detections. They are useful signals, but they measure different things and should not be read as a single estimate of how common AI-driven BEC is.
| Finding | What was measured | How to interpret it |
|---|---|---|
| 65% said AI increased attack effectiveness; 34% said reported ransomware incidents began with phishing or other email-based social engineering. | Proofpoint’s 2026 survey of 953 cybersecurity professionals at ransomware-affected organizations across 12 countries, conducted March–April 2026. Proofpoint’s survey announcement. | The 65% figure is respondents’ reported assessment, not a measured causal rate for all attacks. The 34% figure is within that survey context, not a universal incident rate. |
| Reported initial threats included malicious links (47%), malicious attachments (46%), credential harvesting (36%), and BEC (35%). | The same Proofpoint survey and period. Proofpoint’s survey announcement. | These categories should not be treated as mutually exclusive; the report does not establish that interpretation. |
| 81% of investigated incidents were BEC; 79% of BEC cases involved MFA bypass. Median BEC dwell time was 19 minutes in MDR-enabled environments versus 18 days in non-monitored environments. | Eye Security’s analysis of 343 incidents from January–December 2025 among mid-market organizations in Benelux and Germany. Eye Security’s 2026 BEC report. | These are proportions and observed times in Eye Security’s investigated sample, not regional prevalence estimates. The dwell-time comparison is an association, not a randomized causal test. The report describes session hijacking techniques, including adversary-in-the-middle, among the ways MFA was bypassed; it does not show that MFA is universally ineffective. |
| 88% of enterprises were experimenting with AI agents, and 82% of leaders planned broader rollouts within 12 to 18 months. | Figures reported in Microsoft’s 2026 Digital Defense Report. Microsoft Digital Defense Report 2026. | These are the report’s figures, not independently verified global census counts or a measure of agent-related BEC incidents. |
| Longer malicious-payload detections increased roughly fivefold from March to May 2026 and approached 1% of observed prompts in May. | Check Point Research’s prompt-detection metrics in its 2026 AI Security Report. Check Point Research’s report. | Prompt detections are not BEC incident rates and do not establish the prevalence of autonomous agent attacks. |
Together, the figures support concern about increasingly convincing social engineering, identity compromise, and the expanding use of agents. They do not quantify how often an autonomous agent conducts BEC end to end.
Rank #2
Can AI agents be tricked by phishing emails?
Potentially, if an agent processes untrusted content and that content influences its behavior. A malicious email, attachment, web page, or document might contain instructions designed to override the agent’s intended task, expose information, or trigger an action through an integration. This is commonly discussed as prompt injection or prompt manipulation.
The risk depends on the agent’s design and access. Reading an email is different from being able to forward it, retrieve private records, change a payment, or run an administrative tool. An instruction embedded in hostile content should be treated as untrusted input—not as authorization to act. Microsoft’s 2026 Digital Defense Report identifies risks including malicious instructions in content, data exposure, identity and privilege compromise, excessive agency, and operational tampering.
AI agents and AI-assisted phishing are therefore related but distinct. Attackers can use AI to write a deceptive message without using an agent to attack a business. An agent can also be manipulated through content without that event being BEC. Check Point Research describes AI operating in some attacks, and Microsoft outlines agent-specific attack surfaces, but the cited reporting does not establish the prevalence of autonomous agent-run BEC campaigns. Check Point Research’s 2026 report and Microsoft’s report address these broader developments.
How do you verify a payment change request?
Use the organization’s established approval process and a contact method already on file—not the phone number, link, or reply address supplied in the request. A familiar writing style, voice, or video can be imitated and is not sufficient proof of identity.
Rank #4
- Pause the transaction. Treat urgent requests to change bank details, redirect an invoice, alter payroll, or bypass normal approvals as requiring verification.
- Find a trusted contact route independently. Use an existing supplier record, approved directory, or previously verified phone number. Do not use new contact details from the message under review.
- Confirm the exact change. Ask the known contact to verify the requested action and relevant details through the independent channel. For high-value changes, use a second authorized approver if your policy requires it.
- Follow the normal approval workflow. Record who verified the request, when, and how; do not let a message’s urgency replace required approvals.
- Escalate inconsistencies. If the contact cannot be reached, the details differ, or the request pressures staff to avoid checks, hold the change and report it through the organization’s security or finance process.
Eye Security’s report emphasizes financial-process validation, and its VP of Security Operations, Lodi Hensen, said that BEC depends on credibility and timing. The report’s recommendation is to combine validation with email authentication controls, user awareness, and vigilant financial processes. Eye Security’s 2026 report.
Recommended Free Tools
How can companies protect AI agents from prompt injection?
Build controls around what an agent can access and do, not just around how well it follows instructions. An agent should have a verifiable identity, task-specific permissions, and an explicit boundary between reading content and taking consequential action.
Best Value
- This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
- Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Limit identity and permissions
- Give each agent its own verifiable identity and narrowly scoped credentials; avoid shared human credentials.
- Apply least privilege: grant only the data and tools needed for the assigned task, and review access when the task changes.
- Restrict which tools the agent can call. Use allow-lists or equivalent controls where available, and require a human approval gate for high-impact actions such as moving money, changing access, or sending sensitive data externally.
Treat content as untrusted input
- Assume email, documents, web pages, and stored memory can contain hostile instructions.
- Use prompt-injection detection and intent validation where appropriate, but do not rely on a detector as the sole safeguard.
- Constrain retrieval to the data needed for the task, review outputs that could expose sensitive information, and prevent instructions found in content from silently expanding the agent’s authority.
Make actions auditable and reversible where possible
- Keep immutable logs of agent actions, tool calls, and relevant configuration changes.
- Govern changes to prompts, memory, integrations, and agent settings so an unauthorized change can be identified and investigated.
- Monitor agent activity and maintain a rapid investigation and response path. If an agent behaves unexpectedly, suspend its credentials or integrations while the organization assesses what it accessed or changed.
Microsoft’s report pairs agent risks with controls such as scoped credentials, least privilege, runtime gating, and immutable logs. Microsoft Digital Defense Report 2026.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should companies evaluate their wider BEC defenses?
Evaluate the whole workflow, not just the quality of an email filter or an AI safety feature. BEC can involve email, identity, financial approval, and an agent’s connected tools, so gaps between those controls matter.
- Email and collaboration: Check coverage across the channels employees use for payment, payroll, and supplier requests, alongside email authentication and reporting procedures.
- Identity and sessions: Assess protections for credentials and active sessions, including how suspected session hijacking is detected and contained. MFA is an important layer, but it should sit within broader identity and session protection.
- Monitoring and response: Determine whether suspicious activity can be investigated quickly, who owns the response, and how finance and IT coordinate when payment details may have changed.
- Agent controls: Confirm that agent identities, credentials, tool permissions, approval gates, and action logs can be reviewed and revoked.
- Data protection and governance: Check whether sensitive data can be exposed through retrieval or outputs, and whether changes to prompts, memory, configuration, and integrations are controlled.
- Evidence and fit: For any security service or product claim, examine what channels it covers, how it fits the organization’s geography and deployment, and what evidence supports its effectiveness. Risk reporting alone is not a comparative product test.
Training should reinforce that polished wording or a familiar-sounding voice is not authentication. Proofpoint reported authentic-seeming messages as a reason attacks bypassed controls in its survey context; Check Point describes increasingly convincing forged voice, faces, documents, and live video. Proofpoint’s 2026 survey announcement; Check Point Research’s 2026 report.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11What to do if a BEC or agent incident is suspected
- Stop the action: Pause pending transfers or account changes and notify the relevant finance approver.
- Contain access: Follow incident procedures to secure affected accounts and sessions; disable or restrict a suspected agent’s credentials and integrations if needed.
- Preserve evidence: Retain the original message, headers where available, relevant approval records, and agent or tool logs. Avoid deleting records needed for investigation.
- Trace the impact: Determine which identities, data, messages, tools, and financial instructions may have been accessed or changed.
- Coordinate response: Involve security, IT, finance, and affected business contacts promptly; use established bank, supplier, and incident-reporting channels as appropriate.
Speed matters because an intrusion can remain unnoticed while an attacker uses a compromised identity. Eye Security’s reported dwell-time difference illustrates that point within its own investigated sample; it should not be treated as a universal prediction for another organization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

