Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

Why Payload-Free Phishing Bypasses Every Filter

Traditional email filters look for malicious links, but modern attackers use AI agents to build trust through payload-free dialogue. Learn how to stop them.

Why Payload-Free Phishing Bypasses Every Filter

An email hits your accounts payable team’s inbox from a known vendor’s address.

No sketchy link to a fake login portal. No macro-laced PDF invoice attached. No flashing red text demanding immediate action. It just reads:

"Hey Luis, are you at your desk this afternoon? I have a quick question about our remaining Q3 deliverables."

If your company relies on a traditional secure email gateway (SEG) (opens in new tab) or a standard spam filter, that message sails right through to the inbox with a clean bill of health. Why? Because the security tools didn't find a weapon.

That’s why payload-free dialogue (opens in new tab) has become one of the most dangerous threat vectors in cybersecurity.

Cybercriminals have realized that fighting your expensive firewall and AI-driven link scanners is a waste of time. Instead, they’re dropping the payload entirely and using autonomous AI agents to initiate back-and-forth conversations to build rapport with your employees before dropping the real trap.

Here’s why static scanners are blind to this tactic, and why dynamic dialogue monitoring is the only way to stop the modern hustle.

Secure email gateways have a massive blind spot

Look at how we’ve historically trained our digital doormen.

Cybersecurity operated on a contraband model for years. A secure email gateway works a lot like the security checkpoint at an airport. It scans every piece of luggage (every email) looking for prohibited items.

  • It checks URLs against global blocklists to see if the link leads to a known phishing site.
  • It strips attachments and runs them in a digital sandbox to see if they deploy malware.
  • It looks for mismatched domains and known malicious sender IPs.

This model is efficient at catching the obvious stuff. But a static scanner is a machine looking for a weapon. It’s unequipped to identify a really good liar.

If an attacker sends a plain-text email with absolutely no links and no attachments, the SEG throws its hands in the air. There’s nothing to scan, no sandbox to run, and no URL to check.

The gateway stamps the email as "Safe" and delivers it to your employee.

Now, the attacker has bypassed your perimeter, and the real game begins. The financial stakes here are astronomical: The FBI's 2025 Internet Crime Report (opens in new tab) logged a staggering $3.05 billion in reported losses explicitly tied to business email compromise (BEC) (opens in new tab), which is the category where payload-free conversational attacks thrive.

How AI scales payload-free phishing attacks

Payload-free attacks were highly effective but difficult to scale.

If an attacker wanted to trick a finance director into wiring money without using a malicious link, they had to sit at a keyboard and manually type out the emails. They had to play the long con, responding to the target's questions, mimicking a vendor's tone, and building psychological trust over days or weeks. Because human labor is expensive and slow, attackers reserved this tactic exclusively for massive, high-value targets.

Generative AI removed that friction.

Threat syndicates deploy specialized AI agents to handle the initial communication. These bots can simultaneously hold 10,000 unique, highly persuasive conversations with 10,000 different corporate employees.

They don't get tired, they don't make spelling errors, and they have infinite patience.

Threat intelligence tracking the modern phishing landscape reveals that over 82% of all phishing emails now contain AI-generated content (opens in new tab), according to StationX.

3 stages of a payload-free attack

When an AI agent targets your workforce, it follows a strict, highly optimized psychological playbook designed to lower the employee's defenses.

  1. Innocent opener: The attacker sends a completely benign, plain-text email. It’s usually framed as a quick check-in, a vague question about an ongoing project, or a request for a phone call. The goal of this step is simply to get the employee to reply, which signals that the inbox is active and the target is responsive.
  2. Rapport building: Once the employee replies, the AI agent engages in a polite, professional back-and-forth dialogue. It might complain about the weather, reference a fake upcoming meeting, or apologize for a delay. This stage establishes a baseline of trust. The employee stops viewing the sender as a potential threat and starts viewing them as a normal colleague or vendor.
  3. Pivot to out-of-band: After trust is established, the agent makes its move. But it still doesn't send a link. Instead, it requests an action that occurs outside the email environment. It might ask the employee to execute an out-of-band wire transfer by updating a routing number in their internal system, or it might ask for a "quick favor" requiring the employee to text a specific MFA code to a "new vendor portal."

By the time the actual fraudulent request is made, the employee is already completely bought in. And when the trap snaps shut, the damage is severe — according to Bright Defense, the average initial loss in a phishing-based BEC incident (opens in new tab) exceeds $160,000 before any recovery efforts even begin.

Moving past the static scanner

If your security architecture relies exclusively on finding a malicious payload, you’re bringing a metal detector to a debate tournament. You have the wrong tool for the job.

To stop an AI agent from running a long con on your accounts payable team, you have to fundamentally change how you analyze inbound communication. You have to move past static link scanners and embrace in-line conversational analysis.

This demands an intelligent system that doesn't just read the code of an email, but actually understands the semantic meaning, context, and intent of the dialogue.

Decoding the Intent with Dynamic Monitoring

Instead of asking, "Does this email contain a virus?", modern dynamic dialogue monitoring asks a much more complicated set of questions:

  • Contextual anomalies: Is it normal for this specific vendor to email this specific employee at 6:00 PM on a Friday asking about wire transfers?
  • Linguistic shifts: Does the writing style of this sender suddenly deviate from their historical communication patterns? Are they using different sign-offs or abnormal industry jargon?
  • Urgency detection: Is the sender artificially inflating the stakes of the conversation? Are they applying subtle pressure, demanding absolute secrecy, or insisting that normal approval channels be bypassed?
  • Out-of-band pivot: Is the sender attempting to move the conversation away from the corporate email server? Are they suddenly asking the employee to use WhatsApp, SMS, or a personal phone number?

These are the true indicators of a payload-free attack. They can’t be caught by a legacy gateway looking for bad code, and can only be caught by an intelligent system that actively reads the room.

Fighting cybercriminals’ agents with Doppel’s agents

As threat actors increasingly outsource their social engineering to autonomous LLM agents, the volume and sophistication of payload-free attacks will only continue to skyrocket.

You can’t expect a busy, stressed employee to accurately perform complex linguistic analysis on every single email they receive. You need an agentic defense that operates with the same speed and intelligence as the attacker.

Doppel (opens in new tab)’s dynamic dialogue monitoring shifts the balance of power.

By analyzing the context, intent, and subtle behavioral shifts within a communication thread, Doppel identifies the rapport-building phase of a payload-free attack before the fraudulent request is ever made. We don't wait for a bad link to drop; we flag the manipulation the moment the conversation turns suspicious.

The agentic AI-native social engineering defense platform (opens in new tab) converts these live conversational lures into proactive, contextual simulations (opens in new tab) for your workforce. Doppel trains your employees (opens in new tab) on the exact conversational tactics being used in the wild, hardening your human perimeter against the threats that bypass traditional filters.

The most dangerous attack is the one that arrives empty-handed. If you want to secure your organization against the next generation of financial fraud, stop searching for the payload and start analyzing the conversation. Get a demo (opens in new tab) with Doppel.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.