Why You Can’t Treat Phishing Emails the Same Anymore
With the development of AI, the phishing red flags you were taught no longer work. Here’s why and what you can do instead.
The Old Way.
Phishing emails are not as easy to spot as they used to be. In the past, an email’s quality could indicate whether it was legitimate or not. Things like typos, awkward phrasing, poor grammar, and generic greetings were clear signs that an email was a phishing scam. With the power of modern AI tools, these obvious tells are now few and far between.
A Look at What’s Different.
Quality
Modern phishing emails are more polished. This means accurate spelling, more effective messaging, correct grammar, and realistic sentence structure. The improvements aren’t limited to their text. With modern image generation, scammers can create sleek, stylized graphics that make emails feel more professional and are difficult to distinguish from the real thing.
Personalization
Gone are the days of generic greetings like “Dear Customer” or “Dear User.” Expect scammers to address you by name. The personalization goes beyond specific greetings. Scammers can craft emails that appear to be from people you know, like bosses or trusted coworkers. By reading information like a target’s public profile, recent posts, and writing style, LLMs can generate messages that mirror a coworker’s tone. Alternatively, emails may seem to come from sources you’d expect, like a DocuSign from a vendor, an inquiry from a known client, or a multi-factor authentication warning.
Efficiency and Cost
Previously, drafting well-made emails with coherent graphics took hours. With AI, scammers can create higher quality emails in minutes instead of hours and at a fraction of the cost. Harvard University researcher Fred Heiding performed a study where he and others tested well-crafted phishing emails made by human experts against AI-generated emails and arbitrary phishing emails. They found that AI-generated emails and well-crafted emails both received a 54% click-through rate, while the generic phishing emails received only 12%. These statistics demonstrate the significant effectiveness of generated phishing emails. The combination of an efficient drafting process and effective material demonstrates why they pose a threat.
Why This Matters for Your Business.
AI has lowered the cost of a targeted phishing attack significantly. Personalized, well-researched attacks used to be reserved for large enterprises with deep pockets and high-value targets. Now, that same level of targeting has a much lower threshold, making small and midsized businesses more viable targets than they previously were. An employee who’d catch a generic “Dear Customer” scam is far more likely to click when the message references their actual manager, project, or a vendor they work with regularly.
A Few Quick Tips.
Slow down. Consider the content of the email instead of the quality. Extreme urgency or offerings that seem too good to be true can be warning signs that an email may not be legitimate
Hover before you click. A displayed link or email address can be adjusted or faked. Simply hovering over a link will reveal the real destination.
Verify through another platform. Don’t rely on an email reply to verify suspicious emails. Connect with the email sender via alternative communication methods, like text or a phone call before providing sensitive information, especially if the email contents involve money or login credentials.
The New Playbook.
Now that AI has made the old phishing checklist obsolete, detecting scams can seem intimidating. Polish, personalization, and a familiar name in the “From” field are no longer proof that a message is safe. The good news is that the fix isn't complicated: slow down, verify through a second channel, and treat pressure to act fast as a warning sign rather than a reason to comply. Making these simple actions a habit can go a long way.