For many years, the standard advice for spotting a phishing email was relatively simple: look for spelling mistakes, poor grammar, and awkward phrasing. That guidance worked reasonably well because many phishing campaigns were mass-produced, poorly translated, and designed to target large numbers of people with minimal effort.
That is no longer a reliable way to identify a malicious email.
Generative AI has significantly changed the quality and sophistication of phishing attacks. Attackers can now produce convincing, professional-sounding messages in almost any language, tone, or writing style within seconds. The obvious warning signs that people were trained to look for are increasingly absent.
How phishing attacks have evolved
The change is not just about writing quality. It is also about speed, scale, and personalisation.
Traditionally, highly targeted phishing attacks required time and effort. An attacker targeting a specific employee would often need to research the organisation, understand internal terminology, identify relevant contacts, and carefully draft a believable message. That limited how many convincing phishing emails could realistically be created.
AI dramatically reduces that effort.
An attacker can now gather publicly available information from LinkedIn, company websites, press releases, or social media profiles and use it to generate tailored phishing emails in seconds. Messages can reference:
- real colleagues
- recent company events
- suppliers or ongoing projects
- internal terminology
- executive names and job titles
The result is a phishing email that feels far more credible than the generic scams many users are familiar with.
In some cases, attackers are also using AI to mimic communication styles. Emails can be generated to resemble the tone and formatting typically used by a manager, finance department, or IT team, making them harder to identify through instinct alone.
AI-driven attacks are no longer limited to email
The same technology is increasingly being used in voice and video-based social engineering attacks.
There have been documented incidents where employees received phone calls that appeared to come from senior executives or trusted colleagues, instructing them to transfer funds, reset credentials, or disclose sensitive information. In some cases, attackers used AI-generated voice cloning to imitate the person’s speech patterns convincingly enough to bypass suspicion.
Video conferencing scams using manipulated audio or synthetic video are also becoming more feasible as the technology improves.
While these attacks are still less common than email phishing, they demonstrate how quickly social engineering techniques are evolving.
What to look for instead
If spelling mistakes and poor grammar are no longer dependable warning signs, organisations need to focus on behavioural indicators instead.
Urgency and pressure
Phishing attacks almost always attempt to create urgency.
Messages claiming that an account will be suspended, a payment must be made immediately, or a password must be reset urgently are designed to push people into reacting before thinking critically.
Legitimate organisations rarely demand immediate action without allowing time for verification.
Unexpected or unusual requests
Even a professionally written message should be questioned if the request itself is unusual.
Examples include:
- requests to change bank account details
- unexpected password reset requests
- invoices that do not match normal processes
- requests to purchase gift cards or transfer funds
- login prompts for services you were not expecting to access
A message can look authentic while still being entirely fraudulent.
Sender details that do not quite match
The display name shown in an email can easily be manipulated.
Users should be encouraged to inspect the actual sender address carefully, particularly for messages involving payments, credentials, or sensitive information. Small changes in domain names, additional characters, or lookalike domains are commonly used to impersonate trusted organisations.
For example, a message may appear to come from Microsoft or a known supplier while actually originating from an unrelated domain.
Links and login pages
Before clicking a link, users should verify where it actually leads.
Hovering over a hyperlink will often reveal the real destination URL. Attackers frequently register domains designed to look visually similar to legitimate services, relying on users glancing quickly rather than checking carefully.
Even convincing login pages should be treated cautiously if they were reached through an unsolicited email or message.
Why ongoing training matters
The increasing quality of phishing attacks is one of the strongest arguments for regular, realistic security awareness training.
Employees who experience simulated phishing exercises in a controlled environment are generally far better prepared to recognise suspicious behaviour in real-world situations. Importantly, modern phishing simulations need to reflect the quality of attacks people are now likely to encounter rather than relying on obviously fake examples.
Security awareness training should also be continuous rather than treated as a one-off compliance exercise. Attack techniques evolve rapidly, particularly as AI tooling becomes more widely available to attackers.
Adapting to a changing threat landscape
AI has not fundamentally changed the goal of phishing attacks. Attackers still want credentials, financial access, sensitive information, or a foothold inside an organisation.
What has changed is how convincing the approach can now be.
Organisations should assume that malicious emails, phone calls, and messages will continue to become more realistic over time. Strong technical controls, layered authentication, email filtering, and staff awareness remain essential, but users should no longer expect phishing attempts to be obvious or poorly written.
The absence of mistakes is no longer a sign that a message can be trusted.
If you would like to discuss simulated phishing testing for your team, get in touch and we can talk through the options.