Security1 distinct publisher2 min readPublished
An SC Media column prices the old deterrent at three hours of attacker research per target and argues the tooling has removed it, which leaves headcount doing no useful work inside a targeting model.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The two percentages in that column are doing less work than they look like they are doing. A 1,265% increase in phishing through late 2024 [3] means volume finished at 13.65 times where it started [16]. The 442% vishing figure over the same period [4] works out to 5.42 times [17]. Neither number arrives with a base count, a named dataset, or a breakdown by victim size in the text supplied [19], so they describe the direction of message volume and say nothing about how many 200-person companies were on the receiving end.
The figure that carries the argument is the three hours [2]. Attacker time was the scarce input, and scarce inputs go to the biggest expected payout. That is triage, and triage is what kept the small manufacturer off the list, not anything the manufacturer did [1].
Compressed reconnaissance moves that cost from per-target to per-pipeline. According to the column, the same tooling that writes the lure also picks which employee to approach, works out which systems that person can reach, and drafts the pretext, doing each stage adequately rather than well [11]. Once the marginal cost of the five hundredth target sits close to the cost of the first, revenue stops being a useful sort key and conversion probability replaces it. A company with one controller, an informal approval chain, and a help desk that resets passwords over the phone scores high on that key.
The guardrail debate is where operators get misdirected. ChatGPT, Claude, and Google Gemini make voice cloning difficult; a local model on a laptop does it without strain [6], and the sample can come from a YouTube clip of the chief executive speaking at a chamber of commerce event [7]. The column names three uses for the resulting call: authorizing a wire transfer, changing direct-deposit details, and talking a help desk representative into a password reset [8]. All three are procedures. That is also where the fix sits, at the price of friction rather than licences: a callback to a number of record before money moves or a credential changes, because voice recognition as an informal verification step is spent [9].
None of this is an incident report. There is no victim, no CVE, no dwell time, and the piece is a commentary column rather than telemetry [18]. Read it as a pricing update on attacker labour. A risk register that still ranks likelihood by employee count is charging for a deterrent the seller has withdrawn.
Ranked by verification strength, evidence, and original report placement.
For nearly two decades phishing relied on volume over quality, and people caught most of it through awkward phrasing, bizarre formatting, or a sender claiming to be the "Microsoft Security Department" from a Gmail address.
Large language models let threat actors generate context-aware, grammatically flawless lures in any language, at any scale, for any target.
The piece is an SC Media Perspectives commentary column published on scworld.com, written by members of a community of cybersecurity subject matter experts.
The 1,265% and 442% growth figures appear without a base count, a named dataset, or any breakdown by victim organisation size in the text supplied.
For years small and midsize businesses had an unspoken advantage in social engineering: they were not worth the attacker's effort.
The column's example of the old economics: a sophisticated attacker was not going to spend three hours personalizing a spear-phishing email to trick a controller at a 200-person manufacturing company when a Fortune 500 target was available, and that math no longer works.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Adobe puts more than 70 creative tools behind Slackbot on Slack's two top tiers2 distinct publishers
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two percentages, no denominator, one voice
The argument rests on 1,265% and 442%, and neither number arrives with a counting body, a baseline volume or a window tighter than 'through late 2024'. SC Media hyperlinks them; nothing readable here says who measured what. The claim the headline actually turns on — weeks of recon compressed into hours — names no tool and cites no engagement. What is solid is the small stuff: the column is plainly labelled commentary, and its characterisation of pre-LLM phishing tells is uncontroversial.
Attacker uptake attested at the model vendor's door
What is genuinely on the record comes from Anthropic: nearly 800 malicious actors identified on Claude in a year, and one extortion campaign run largely through Claude Code down to reasoning that a church was worth $75,000 rather than $2.5 million. That is real, dated-ish usage disclosed by the party best positioned to see it. What no one here counts is the half that matters to this story — how much of that activity reaches firms of 200 people, and whether a single small business has changed a wire-approval or help-desk procedure as a result.
Sober mechanisms, overreaching arithmetic
The mechanics are the restrained part of this piece — a chamber-of-commerce clip and a laptop, a pipeline that is merely adequate at every step, stages chained without a human in between. The overreach is arithmetic wearing the costume of a finding: 13.65 times and 5.42 times sound like measurements of the SMB threat and are neither measured against a base nor split by company size. 'Every business with a registered domain name and an email server' is where the rhetoric lands, not where the evidence does.
Contributed column, employer unstated
Perspectives is SC Media's contributed-expert channel, and this piece reaches us without a byline or an affiliation — so the question a reader would ask first, namely who sells what to the small businesses being told they are now worth targeting, cannot be answered from what we have. The corroboration carries its own angle too: Anthropic's threat-intelligence publishing doubles as a demonstration that Anthropic watches its own model carefully. Nothing here makes the argument wrong. It does mean every interest in the chain points the same way, toward urgency.
Clear text, unverifiable core
We can hold this column to account with unusual precision because it says what it means and labels itself commentary, so our read of what is being claimed is firm. Our read of whether it is true is thinner: a single publisher, no competing account, and the two figures that would settle the question are exactly the two we cannot trace to a counter. The confidence stated here belongs to the assessment, not to the thesis.