Online Help
28 July 2026 | 11:19 am

For years, security awareness training has taught people to spot phishing by its tells: clumsy grammar, generic greetings, slightly-wrong sender addresses, urgent demands that feel a bit off. AI tools have quietly eroded almost all of those tells.

 

Generative AI makes it trivial for an attacker to produce a flawless, contextually appropriate email in seconds, in fluent English, referencing real details scraped from a company’s website or LinkedIn presence. The “Dear Sir/Madam” giveaway is gone. So is the broken English. What’s left is an email that reads exactly like something a genuine colleague, supplier, or client might send, often timed to coincide with real events, like impersonating a supplier shortly after a genuine invoice has gone out, or referencing a real project name pulled from public job postings or social media.

 

The same shift is happening with voice and video. AI voice cloning needs only a small sample of someone’s voice, sometimes pulled from a public video or conference recording, to produce a convincing imitation. Combine that with a spoofed caller ID and a pretext built from publicly available information, and the classic “call to verify” advice that used to catch out email-only scams becomes far less reliable.

 

None of this means awareness training is pointless, but it does mean training built entirely around spotting obvious red flags needs updating. The more effective approach combines technical controls with a different kind of awareness: verifying unusual requests (particularly anything involving payments, credentials, or sensitive data) through a separate, pre-established channel, rather than trusting the channel the request arrived on. Conditional Access, strong MFA, and email authentication (DMARC, DKIM, SPF) all reduce the chance a convincing email translates into a successful compromise, even if a person is fooled.

 

The honest takeaway is that “spot the scam” is no longer a reliable enough strategy on its own. Layered technical controls, plus a verification habit that doesn’t depend on trusting the message itself, is what actually holds up against AI-generated attacks. If you’d like a review of where your current defences stand against this kind of threat, get in touch.