For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy for us to teach, and for a long time it worked.
Unfortunately, it doesn't work anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team's inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know.
The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn't their own, and the mistakes showed. AI took that away.
The UK's National Cyber Security Centre says generative AI can now create convincing phishing lures "without the translation, spelling and grammatical mistakes that often reveal phishing." The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake, so it reads as believable. That means the one thing most people were trained to look for no longer tells you much.
These days, the scam email isn't the obvious one anymore. Instead of "Dear customer, your account is suspended," someone in your finance team gets a message that looks like it's from a supplier they really deal with, mentions a real project, and asks to update the bank details for the next invoice. It reads exactly like a real supplier email. The only thing wrong that you can't even see is that the supplier never sent it.
It's tempting to assume your email security will handle this. It catches a lot, and you should keep it switched on. But a well-written, personalized email that asks a normal-sounding question doesn't always look dangerous to a filter, especially when it carries no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these messages through, which is why the last line of defense is a person who knows what to check.
AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip, enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defense is the same: if a call or voicemail asks for money or logins, hang up and call the person back on a number you already have. Places like your bank will NEVER call you and ask you to confirm who you are - you should always confirm who they are!
If you can't trust how an email is written, look at what it's asking you to do. That's where the real warning signs are, and AI hasn't changed them:
Every one of these is about what the email is asking for. So the rule to teach your team is simple: when a message is about money, logins, or how you pay someone, slow down before you act.
Article used with permission from The Technology Press.