Sber has developed a system of AI agents to search for phishing sites and has already integrated it into its internal cyber intelligence platform. The solution operates on the principle of "AI against AI" and is expected to significantly increase the number of resources checked without expanding the staff of specialists.
First, four separate agents independently examine the site from different angles: they analyze the text, program code, infrastructure, and a screenshot of the page. Then, the collected data is transformed into a kind of digital proceeding – an "agent-prosecutor" and an "agent-lawyer" look for inconsistencies in the evidence, and an "agent-judge" delivers the final verdict.
The agent-judge makes the final decision, relying not on a single label, but on a verifiable chain of evidence and arguments.
The system takes less than a minute to analyze one site. The bank's goal is to bring the volume of checks to more than 200 thousand resources per quarter. For now, the AI works as an assistant: it finds potential threats, prioritizes them, and prepares a report, while a human confirms the decision to block.
After training is completed, the system is planned to be transitioned to fully autonomous decision-making regarding the blocking of phishing resources. In the future, the development is also intended to be connected to the X Threat Intelligence platform so that other organizations can use it.