Illustration of a hand reaching out of an email on a laptop screen to grab a credit card and a stack of cash.

We used to spot scam emails by looking for clunky grammar and obvious typos, but that advice is officially outdated. Today, cybercriminals are using AI to generate flawless, highly personalised phishing emails that slip right past traditional defences, meaning your team needs a completely new way to identify threats.

Why the Old Advice is Dead

The spelling-and-grammar trick worked because scammers were often writing in a language that wasn’t their own. AI has completely removed that barrier. The UK’s National Cyber Security Centre (NCSC) and the FBI both warn that generative AI now creates convincing phishing lures without the translation or grammatical errors that used to give them away. The one thing most people were trained to look for is no longer a reliable tell.

What Makes Modern Phishing So Convincing

  • Flawless writing: A scam email now reads exactly like a normal business communication. A machine writes it in seconds, perfectly matching a professional tone.
  • Hyper-personalised details: Attackers feed public information about your company—pulled from your website, LinkedIn profiles, or press releases—into AI tools. The result is a tailored message featuring the right names, accurate job titles, and a highly believable reason for getting in touch.
  • Massive scale: AI allows attackers to produce and send threats incredibly fast. The FBI’s Internet Crime Complaint Center recently added a dedicated AI section to its annual report, tying the technology to over 22,000 complaints and nearly $893 million in reported losses.

Instead of a glaring “Dear customer, your account is suspended” message, someone in your finance team might receive an email that looks exactly like it came from a real supplier. It might mention a genuine project and casually ask to update the bank details for the next invoice. It reads perfectly—the only problem is that the supplier never sent it.

💡 Email threats are evolving fast. Our Cybersecurity services include Security Awareness Training to help your staff confidently identify and report sophisticated attacks.

Beyond the Spam Filter

It is tempting to assume your email security software will catch everything. While filters are essential and block a massive amount of spam, a well-written, personalised email asking a normal-sounding question doesn’t always look dangerous—especially if it doesn’t contain an obvious malicious link or attachment. The NCSC and FBI expect AI to push more of these subtle messages through, which makes a trained, vigilant employee your strongest line of defence.

The Threat Extends to Voice Calls

AI has brought this same level of sophistication to phone calls and text messages. The FBI warns that criminals can now clone a human voice from just a short audio clip. That is enough to leave a terrifyingly accurate voicemail sounding exactly like your boss or a family member, urgently requesting a payment. The defence here is exactly the same: if a call or voicemail asks for money or logins, hang up and call the person back on a trusted number you already have saved.


The Real Warning Signs You Must Watch For

Because you can no longer trust how an email is written, you must look closely at what it is asking you to do. AI hasn’t changed the attacker’s end goal. Slow down if a message:

  • Asks for money, gift cards, or a payment to a new account.
  • Requests a login, a verification code, or sensitive personal details.
  • Creates artificial pressure through strict deadlines, threats, or demands to act immediately.
  • Asks you to change the bank details for an existing invoice or supplier.
  • Includes a link or attachment you were not expecting to receive.
  • Shows a correct display name, but the actual underlying email address doesn’t match.

Actionable Steps to Protect Your Team

  • Verify requests through a different channel: If an email asks for a payment or a change to bank details, call the person on a trusted, pre-existing phone number. Never reply directly to the email or use a number provided in the message.
  • Update your training: Stop telling staff to look for bad spelling. Train them to analyse the request and to slow down whenever money or credentials are involved.
  • Mandate phone confirmations: Create a strict company rule that every single change to bank details must be confirmed by a phone call, no matter how urgent the email claims to be.
  • Enforce strong authentication: Turn on phishing-resistant MFA or passkeys. Even if an employee is tricked into handing over a password, the attacker won’t be able to log in.
  • Encourage a positive reporting culture: Make it incredibly easy to report suspicious emails, and ensure nobody feels silly for double-checking a request.
  • Keep the conversation going: Remind your team regularly that scam emails look perfect these days. A quick five-minute chat during a meeting is far more effective than an old security poster.

Frequently Asked Questions

Can you still spot a phishing email by bad spelling and grammar?

Not reliably. Attackers now use AI to write clean, grammatically correct emails. A message with perfect spelling can absolutely still be a scam, so you must judge it by what it is asking you to do.

What are the warning signs that still work?

Focus on the request itself: paying money, changing bank details, sharing a login or code, or being pushed to act urgently. Those critical signs do not depend on how well the email is written.

Is AI-generated phishing really more effective?

Yes. The NCSC and the FBI warn that AI makes phishing significantly more convincing and personal, tying it to tens of thousands of fraud complaints. Cleaner, tailored messages simply get opened and clicked more often.

Will my spam filter stop AI phishing?

It will catch a lot, and it is a vital layer of security. However, a well-written, highly personalised email with no obvious malicious links can still look legitimate to a filter. Do not rely on technology alone.

What should staff do if they aren’t sure about a message?

They should slow down and verify the request through a completely different, trusted channel—such as calling a known phone number or speaking to the person directly. They should also report it to IT, even if it ultimately turns out to be genuine.

👉 Unsure if your business is protected against AI-driven threats? Our Managed IT Services can assess your email security and implement the right safeguards to keep your inbox secure.

Article used with permission from The Technology Press.


Tags

Comments are closed