For years, security training taught people to spot phishing by its clumsiness: the odd grammar, the strange greeting, the typo in the company name. That advice is aging badly. Attackers now use the same AI writing tools your team uses, and the results read like a perfectly normal email from a vendor, a bank, or your own boss.
Security researchers tracking this shift report that AI assisted attacks are a growing share of what lands in inboxes. The emails are personalized, correctly formatted, and reference real details scraped from LinkedIn or your company website.
What still works
The good news is that the fundamentals still hold, they just need updating:
- Verify requests through a second channel. If an email asks you to pay, change banking details, or buy gift cards, confirm by phone using a number you already have. No exceptions, no matter how legitimate the email looks.
- Slow down on urgency. AI writes polite emails, but the pressure tactics remain. Anything that says act now deserves suspicion.
- Filter before the inbox. Modern email filtering catches most of this before a human ever sees it. The less your team has to judge, the fewer mistakes get made.
- Practice on purpose. Simulated phishing keeps people sharp against current techniques, not the typo riddled classics from 2019.
We run phishing training and email protection for businesses across Chicagoland. Book a free consultation if your team could use a tune up.