Ransomware, Phishing, AI/ML, Application security

AI killed the typo. Now it’s time to rewrite phishing training.

Glowing fishing hook catching an envelope over a sprawling night city circuit grid dramatic neon lighting phishing cyber security email threat with copy space

COMMENTARY: “Look for spelling mistakes and bad grammar.” For years, that was one of the defining pieces of advice for spotting phishing attempts. Today, anyone can use generative AI to create polished, personalized phishing emails in seconds, rendering that advice increasingly irrelevant.

The generic, blasted-out email is being replaced by one that’s well-written and appears crafted specifically for its recipient, referencing their employer, a recent purchase, or even a coworker's name.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The problem isn't simply that phishing emails are getting better. It's that many techniques employees have been taught to identify phishing are becoming less reliable in the AI era.

AI has industrialized phishing

Recent Barracuda research found that 90% of high-volume phishing campaigns use phishing-as-a-service kits, making sophisticated phishing campaigns easier to launch and scale.

Generative AI allows attackers to create phishing emails with flawless grammar, localized language, and personalized messaging in seconds, reducing the skill and effort required to execute convincing attacks.

PhaaS has done for phishing what SaaS did for business software. Instead of building phishing infrastructure themselves, attackers subscribe to ready-made kits that include templates, fake login pages, hosting, and automation, enabling even relatively inexperienced attackers to launch sophisticated campaigns. Our research shows that 90% of high-volume phishing campaigns use these kits.

AI improves quality, while PhaaS improves scale. Together, they have changed the economics of phishing in favor of attackers.

Stop training employees to judge writing quality

AI killed the typo, and the typo was our best friend. For 20 years, we taught people to spot phishing by looking for bad grammar, awkward phrasing, and clumsy translation, but AI has made that playbook obsolete.

Generative AI has shifted phishing from a language problem to a decision-making problem. Organizations need to shift security awareness training from evaluating how an email is written to evaluating what it asks an employee to do, because the social engineering techniques phishing relies on persist in the AI era.

Organizations should train employees to recognize:

  • Urgency designed to bypass normal processes. Attackers want employees to act before they think, so phishing campaigns often create manufactured time pressure, like a warning that an account will be locked or payroll information must be updated immediately.
  • Requests that break established business workflows. A vendor suddenly changing banking information, an executive asking for gift cards, or a coworker requesting credentials should trigger additional verification, regardless of how legitimate the email appears.
  • Pressure to stay within the attacker's communication channel. If a sender discourages calling back, insists on replying only by email, or pushes an employee to continue exclusively over text or chat, it should raise suspicion.

This shift also has implications for phishing simulations. If security awareness campaigns continue relying on suspicious emails filled with grammatical mistakes, they risk measuring employees against attacks that attackers have largely abandoned.

Simulations should reflect today's threat landscape by testing employees against attacks they are likely to encounter.

Teach verification, not detection

Perhaps the most important habit organizations can teach is to independently verify unusual or high-risk requests through a trusted channel.

If an email appears to come from HR, finance, or IT and requests an unusual action, employees should confirm it using a different known contact method, not by replying to the message itself.

Take an employee who receives an email that appears to be from their manager, asking them to make a payment to a vendor. Following the instructions sends money directly to the attacker. Taking a minute to call their manager exposes the scam. The phishing message may be flawless, but the verification process breaks the attack.

AI powers the attack, but humans still make the decisions

Phishing defense is one-sided. A defender has to be right every time, whereas the attacker has to be right once. Every other defense can be perfect, and one person clicking one link at 4:55 p.m. on a Friday undoes it.

Now consider the force multiplier effect of AI and PhaaS: more attacks, sent faster, at a barrier to entry near zero, against the same number of defenders.

Phishing doesn’t attack technology; it attacks trust. People don’t fall for phishing because they lack training. They fall for it because they’re human. Urgency is part of normal life. Employees receive genuine password resets, payroll notifications, and fraud alerts, so a fake one blends into legitimate noise.

That’s why awareness alone was never the finish line. The goal isn't to eliminate every click. It’s to build a security culture where employees pause before acting, confirm unusual requests through trusted channels, and know what to do when something doesn't feel right.

The organizations that successfully manage phishing risk will build security habits that remain effective even when the malicious email looks perfect.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Barracuda's Adam Khan

Adam Khan, Barracuda Vice President of Global Security Operations & AI Security, XDR/MDR, Office of the CTO.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds