Hoxhunt upgrades phishing response automation for security teams

Hoxhunt has expanded Respond, its email incident response platform, to automate investigation and removal of reported phishing messages. The system groups duplicate reports into campaign-level incidents, suppresses benign or repeated submissions, and deletes confirmed malicious emails across affected inboxes. Hoxhunt says the platform can cut phishing tickets needing analyst attention by up to 99 percent and remediate confirmed campaigns in under a minute.
Hoxhunt's Respond platform now handles reported email investigations and cleanup with less manual triage. It clusters duplicate submissions into one campaign incident, filters out harmless or repeat reports, and can remove verified malicious messages from all impacted mailboxes. Remediation is reversible, and employees get immediate feedback.
The offering comprises Instant Feedback, Incident Orchestration, Search & Destroy, and Feedback Rules. Hoxhunt says the automation can reduce analyst tickets by as much as 99% and clear confirmed campaigns in less than a minute. It also reports enterprise customers saving over 900 SOC analysis hours monthly, with classification models trained on a decade of employee-reported phishing data and five million-plus human sensors.
Security teams may see less repetitive triage, allowing analysts to focus on complex threats. Employees could benefit from faster removal of malicious messages and clearer feedback, reducing exposure across shared inboxes. Organizations may become more resilient if reporting habits strengthen and response times shrink. At the same time, reliance on automated classification could introduce risks if errors occur, so oversight may remain important. The broader effect could be a workplace culture where reporting suspicious email feels useful rather than burdensome.