AI and Phishing: The New Rules for Spotting a Scam
We all used to rely on the obvious signs to spot a phishing email. Things like bad grammar, weird spelling, or a link that didn’t match what we expected. Maybe the sender’s address was a jumbled mess, or the message felt stiff or written in a way that seemed awkward. Those were our clues that something wasn’t right.
But here’s the thing: AI has changed the game.
Now, phishing emails can look perfect. No typos. No awkward phrasing. No suspicious-looking URLs (at least, not obviously). The messages sound natural, urgent, and even personalized. That “invoice” from your vendor? It might read exactly like the real thing. That “urgent request” from your CEO? It could use their actual tone, their actual words. AI doesn’t just mimic humans, it mimics specific humans by going through anything it can find online to find a person’s writing style and voice. And it’s getting really good at it.
So, what now? Do we just throw our hands up and accept that we’re all one click away from disaster? No. Because while the tactics have improved, they cannot fully overcome our ability to be skeptical and curious. We can still do a few things that can keep us safe.
Here are a few ways to stay safe as AI continues to evolve.
Trust Nothing (Yes, Really)
We’ve always been told to “trust but verify.” But let’s make this a bit more direct. Don’t trust. Not emails. Not texts. Not even that DM from your coworker asking you to “quickly approve this payment.” Assume every link, every attachment, and every request for action is suspicious until proven otherwise. AI can make a phishing email look legitimate, but it can’t actually make it legitimate. At least not yet. So, treat it like a stranger at your door. Don’t let them in without checking who they are and what they want.
Verify Like Your Business Depends on It (Because It Does)
If an email or message claims to be from someone you know or a service you use, don’t use the contact info in the message. Open your browser, type in the website directly, and log in to check for any alerts or requests. Urgency is a scammer’s best friend. They will say “Act now or your account will be locked!”, but a brief pause to verify can save you hours of regret.
When in Doubt, Pick Up the Phone (But Not the Number in the Email)
Phone numbers can be spoofed. Voices can be cloned. Even video calls can be faked. So, if you get a request that feels off, especially one asking for money, data, or access, reach out to the person or company through a known, trusted method. Use the phone number on their official website, not the one in a suspicious message. And if you’re still unsure? Talk to someone else in your organization. A second set of eyes (or ears) can spot what you might miss.
The Bottom Line
AI has made phishing harder to detect, but it hasn’t made you powerless. The same principles that protected us before (skepticism, verification, and a refusal to rush) still work. They’re just more important than ever.
So, next time you see an email that seems fine, ask yourself: Would I have trusted this a year ago? If the answer is “only because it looks perfect,” that’s your clue.
Pause. Verify. Protect.
Want more?
Check out our Practical Momentsseries on YouTube where we explore all kinds of cyber scenarios to help keep you safe and secure!