COMMENTARY: “Look for spelling mistakes and bad grammar.” For years, that was one of the defining pieces of advice for spotting phishing attempts. Today, anyone can use generative AI to create polished, personalized phishing emails in seconds, rendering that advice increasingly irrelevant.The generic, blasted-out email is being replaced by one that’s well-written and appears crafted specifically for its recipient, referencing their employer, a recent purchase, or even a coworker's name.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]The problem isn't simply that phishing emails are getting better. It's that many techniques employees have been taught to identify phishing are becoming less reliable in the AI era.
This shift also has implications for phishing simulations. If security awareness campaigns continue relying on suspicious emails filled with grammatical mistakes, they risk measuring employees against attacks that attackers have largely abandoned.Simulations should reflect today's threat landscape by testing employees against attacks they are likely to encounter.
AI has industrialized phishing
Recent Barracuda research found that 90% of high-volume phishing campaigns use phishing-as-a-service kits, making sophisticated phishing campaigns easier to launch and scale.Generative AI allows attackers to create phishing emails with flawless grammar, localized language, and personalized messaging in seconds, reducing the skill and effort required to execute convincing attacks.PhaaS has done for phishing what SaaS did for business software. Instead of building phishing infrastructure themselves, attackers subscribe to ready-made kits that include templates, fake login pages, hosting, and automation, enabling even relatively inexperienced attackers to launch sophisticated campaigns. Our research shows that 90% of high-volume phishing campaigns use these kits.AI improves quality, while PhaaS improves scale. Together, they have changed the economics of phishing in favor of attackers.Stop training employees to judge writing quality
AI killed the typo, and the typo was our best friend. For 20 years, we taught people to spot phishing by looking for bad grammar, awkward phrasing, and clumsy translation, but AI has made that playbook obsolete.Generative AI has shifted phishing from a language problem to a decision-making problem. Organizations need to shift security awareness training from evaluating how an email is written to evaluating what it asks an employee to do, because the social engineering techniques phishing relies on persist in the AI era.Organizations should train employees to recognize:- Urgency designed to bypass normal processes. Attackers want employees to act before they think, so phishing campaigns often create manufactured time pressure, like a warning that an account will be locked or payroll information must be updated immediately.
- Requests that break established business workflows. A vendor suddenly changing banking information, an executive asking for gift cards, or a coworker requesting credentials should trigger additional verification, regardless of how legitimate the email appears.
- Pressure to stay within the attacker's communication channel. If a sender discourages calling back, insists on replying only by email, or pushes an employee to continue exclusively over text or chat, it should raise suspicion.