AI-powered phishing: why the old warning signs no longer work

Spelling mistakes and clumsy grammar used to give phishing away. AI has removed those clues. Here's how to protect your business when attacks look perfect.

For years, security training taught people to spot phishing by its mistakes: poor spelling, awkward grammar, generic greetings and strange formatting.

That advice is now out of date. Generative AI lets attackers produce fluent, well-written, personalised messages in any language, in seconds. The obvious clues have largely gone — so businesses need a different approach.

What’s changed

Perfect writing, at scale

Attackers can now generate convincing emails that match the tone of a real supplier, a bank or your own managing director. They can create hundreds of variations to get past filters, and translate them flawlessly for any market.

Personalisation from public information

Company websites, LinkedIn profiles, press releases and social media reveal who works where, who reports to whom, which suppliers you use and when people are travelling. AI makes it quick to turn that information into a message that references real names, real projects and real timing.

Voice and video impersonation

Voice cloning and deepfake video mean a phone call or voice note that sounds like a senior colleague is no longer proof that it is that colleague. “I’m about to board a flight — can you get this payment out urgently?” is far more convincing in a familiar voice.

Faster, more believable conversations

Attackers can hold realistic back-and-forth email conversations, responding naturally to questions that used to trip them up.

The new warning signs: look at the request, not the writing

If you can’t rely on spotting mistakes, focus on what the message is asking you to do. Be suspicious of any message — however polished — that involves:

  • Urgency or secrecy. “This needs to happen today” or “keep this between us”.
  • Changes to payment details. A supplier’s “new bank account” is one of the most costly scams businesses face.
  • Requests to bypass normal process. Skipping approvals, avoiding the usual system, or paying before an invoice is checked.
  • Unexpected login prompts. Links that ask you to sign in to Microsoft 365 or another service, especially from a message you weren’t expecting.
  • Requests for codes or approvals. Nobody legitimate needs your MFA code, and unexpected approval prompts should be rejected.
  • A change of channel. “Message me on WhatsApp instead” or “call this number, not the usual one”.

Controls that still work when the email looks perfect

Training helps, but the strongest defences don’t depend on people spotting a fake at all.

1. Verify payments through a known channel

Make it a firm rule: any new payee or change of bank details is confirmed by phoning a number you already hold — never one from the email or invoice itself. Require two people to approve new payees and large payments. This one process stops a large share of invoice fraud, whether the request is AI-written or not.

2. Use phishing-resistant authentication

Standard MFA is far better than passwords alone, but attackers can trick users into approving prompts or handing over codes through fake login pages. Passkeys and FIDO2 security keys are resistant to this because they only work on the genuine website. Prioritise them for admins, finance and leadership.

3. Authenticate your email domain

Set up SPF, DKIM and DMARC on your domain, and move DMARC towards enforcement. This makes it much harder for attackers to send email that appears to come from your exact domain — protecting your customers and suppliers as well as your staff.

4. Limit what a compromised account can do

Apply least-privilege access: people should only access the data and systems their role needs. Separate admin accounts from everyday accounts. If one account is compromised, the damage is contained.

5. Detect and respond quickly

Monitoring for suspicious sign-ins, new inbox forwarding rules and unusual activity means a compromised account can be spotted and locked down before it’s used to attack others.

6. Get the basics certified

In the UK, the government-backed Cyber Essentials scheme sets out core technical controls — secure configuration, access control, malware protection, patching and firewalls — that protect against the most common attacks. It’s a practical baseline for any business.

Rethinking security awareness training

Training still matters, but its focus should shift:

  • From “spot the typo” to “verify the request”. Teach people to pause and check through a separate channel whenever money, credentials or sensitive data are involved.
  • Make reporting easy and blame-free. The faster someone reports a suspicious message — or admits they clicked — the faster it can be contained.
  • Use realistic simulations. Practice with well-written, relevant scenarios, not obviously fake examples.
  • Agree a verification phrase or process for urgent requests from senior staff, so a cloned voice alone is never enough.

In the UK, suspicious emails can also be forwarded to the National Cyber Security Centre’s reporting service at report@phishing.gov.uk.

A quick checklist for business owners

  • Payment and bank-detail changes verified by phone using a known number
  • Two-person approval for new payees and large payments
  • MFA enforced for all users, with passkeys for high-risk roles
  • SPF, DKIM and DMARC configured on your domains
  • Least-privilege access and separate admin accounts
  • Monitoring for suspicious sign-ins and mailbox rules
  • Staff trained to verify requests, with an easy way to report
  • Cyber Essentials achieved or in progress

How NXAPP can help

NX Cyber combines the controls above — email security, phishing-resistant identity, monitoring, practical staff training and Cyber Essentials readiness — into one managed service. If you’d like to know how well your business would stand up to a modern phishing attack, book a call.

Let’s talk

Ready to build a smarter,
more secure future?

Book a call with our team and discover how NXAPP can help your business grow, innovate and stay protected.