Have Questions? Call ParJenn Technologies (409) 684-2517   |   Customer Portal
ai phishing
Cybersecurity Small Business IT

AI Phishing Emails: 6 Signs That Still Catch Them

For about twenty years the advice for catching a scam email was the same. Look for bad spelling. Look for clumsy grammar. A real bank or a real supplier writes properly, so a message full of mistakes was probably fake. That advice was easy to teach and, to be fair, it worked. AI phishing has made it useless, because the mistakes are gone.

Here is what changed. Scammers now write their emails with the same AI tools your team uses to draft a quote. That is all AI phishing is: a scam email written by a machine that spells perfectly. The tool writes cleanly, in whatever tone it is asked for, in seconds. So the message that lands in your bookkeeper’s inbox reads exactly like a message from a real vendor, and that is the whole point of it.

I want to walk through why the old tell worked, why it stopped working, and what you look at instead. The short version is that AI phishing forces you to stop judging how an email is written and start judging what it is asking you to do.

Why AI phishing beats the spelling test

The spelling tell worked for a reason worth understanding. A lot of the people sending scam emails were writing in a language that was not their own, from countries where English is a second or third language. The mistakes were real mistakes. They showed, and your eye caught them.

Then the AI writing tools arrived, and AI phishing arrived with them. Anyone can paste a rough idea into one and get back a clean, well punctuated paragraph in perfect American business English. The person on the other end still cannot write English. It no longer matters.

The UK’s National Cyber Security Centre put it plainly in its report on AI and cyber threats: AI phishing now produces convincing messages without the translation, spelling and grammar errors that used to give it away. The FBI said the same thing in a public warning, that criminals use AI specifically to remove the errors that marked a message as fake.

So the one thing most people were trained to look for tells you nothing now. Worse, it works against you. A clean, professional email feels safe, and feeling safe is exactly what AI phishing is built to create.

What AI phishing looks like when it arrives

The clean writing is only part of it. The bigger change is how personal AI phishing has become.

An attacker can feed public details about your business into an AI tool. Your website, your team’s LinkedIn profiles, a press release, the “About Us” page. Out comes a message with the right names, the right job titles, and a believable reason to be in touch. It mentions a real project. It uses the phrasing your industry uses.

There are also just more of them. When each message takes seconds instead of an hour, attackers send far more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, tied to more than 22,000 complaints and close to $893 million in reported losses. AI phishing is not a rare, targeted event anymore. It is volume.

So the scam email is not the obvious one anymore. It is not “Dear customer, your account is suspended.” It is a message to the person who pays your bills, apparently from a parts supplier you actually use, referencing a real order, asking to update the bank account for the next invoice. Every word of it reads like a real supplier email. The only thing wrong is that the supplier never sent it, which is why you cannot spot AI phishing by reading it.

What we actually see in Southeast Texas shops

I want to give you the local version of this, because it is not abstract.

The AI phishing attempt that hits body shops, dealerships and small contractors around Beaumont, Port Arthur and League City is the supplier bank change. A vendor you have paid for years emails to say they have moved banks. New routing number, new account number, please use these for the invoice that is already in your system. The email looks right. The invoice amount is right. Somebody pays it. The real vendor calls three weeks later asking where their money is.

The second one is the boss email. The owner is “traveling” and needs gift cards bought for a client, or a wire sent today, and cannot talk on the phone. It goes to whoever handles money. It is written the way the owner writes, because the AI was given samples of how the owner writes.

I will be honest about something. The staff who fall for these are not careless people. They are usually the most responsive people in the building, the ones who get things done fast. AI phishing is built for exactly that person.

Your spam filter will not catch all of them

It is natural to assume email security handles this. It catches a lot, and you should keep it on. We run filtering for every client and it does real work.

But think about what a filter looks for. Bad links. Known malicious attachments. Sender addresses on a blocklist. A well written, personal email that asks a normal sounding question and carries no link at all does not look dangerous to a machine. It looks like business correspondence, because it is shaped like business correspondence. That is what makes AI phishing so hard to filter.

Both the NCSC and the FBI expect AI to push more of these messages through, not fewer. That means the last line of defense is a person who knows how to spot AI phishing by what it asks for. Not a person who has been told to look for typos.

It is not just email

The same tools behind AI phishing now clone voices. The FBI warns that a short clip of someone speaking, pulled from a voicemail greeting or a video on your website, is enough to produce a voicemail that sounds like your boss or your spouse asking for an urgent payment.

The defense is the same one you will use for email. If a call or a voicemail asks for money or a login, hang up and call the person back on a number you already have. Not the number in the message. The one in your phone.

How to spot AI phishing: the signs that still work

If you cannot trust how an email is written, look at what it is asking for. That is where the warning signs are, and AI phishing has not changed them, because a scam still needs you to do something.

  • It asks for money, gift cards, or a payment to a new account.
  • It asks for a login, a verification code, or personal details.
  • It creates pressure. A deadline, a threat, or “do this now.”
  • It asks you to change the bank details for an invoice or a supplier.
  • It comes with a link or an attachment you were not expecting.
  • The display name looks right, but the actual email address behind it does not match.

Every one of those is about the request, not the writing. So the rule you teach your team is one sentence. When a message is about money, logins, or how you pay someone, slow down before you act. AI phishing cannot change what it needs from you, only how politely it asks.

That last sign, the display name, deserves a second look. On a phone, most mail apps show only the name, “Mike Rodriguez,” and hide the address underneath. Tap the name. If Mike’s address is a Gmail account or something with an extra letter in the company name, you have your answer.

How to protect your team from AI phishing

None of this needs new software. It needs a few habits, and one rule that nobody is allowed to skip.

Start with the rule. Every change to bank details gets confirmed by phone, on a number you already have on file, before anything is paid. Even when it is urgent. Especially when it is urgent, because urgency is the scam’s favorite tool. We have watched this one rule stop losses that would have cost more than a year of IT service.

Then stop telling staff to watch for bad spelling. Tell them to look at what the email is asking for, and to slow down when it is about money or logins. Say it out loud in a five minute conversation. A five minute chat about AI phishing beats a poster nobody reads.

Make it easy to report a suspicious message, and make sure nobody feels silly for checking. The person who asks “is this real?” ten times is the person who saves you the eleventh time.

Turn on phishing resistant sign in, so a stolen password is harder to use even when someone does get tricked. The plain English version of that is in our post on passkeys for business, which covers what they are and what switching actually involves.

And one more thing, since it is the part people never ask about. Most AI phishing works because the scammer knows who handles money at your business. Take a look at your website and your team’s public profiles and ask whether they are handing that out. Nobody needs to know from your “Meet the Team” page that Sharon handles accounts payable.

What to do if someone already clicked

Sometimes the email works. Here is the order of operations.

If money was sent, call your bank right away. Not tomorrow. Wire recalls sometimes work in the first hours and almost never after a couple of days.

If a password was typed into a page, change that password now, and turn on multi-factor sign in if it was not already on. Then check whether that same password is used anywhere else, because it usually is.

If a link was clicked or a file was opened, the machine may be carrying something. That is where an attacker can quietly sit inside a mailbox and watch. We wrote about how that plays out in our post on phishing attacks that hijack a logged in session. Get the device looked at, and do not just run a scan and call it done.

Our email security service covers the filtering side of this, but I will say again what I said above. The filter catches most of it. A trained person catches the rest.

Frequently asked questions

Can you still spot a phishing email by bad spelling? Not reliably. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it asks you to do.

What are the warning signs of a scam email now? The request itself. Paying money, changing bank details, sharing a login or a code, or being pushed to act right away. Those signs do not depend on how the email reads.

How do I check if a supplier email is real? Call the supplier on the phone number you already have for them, not a number in the email, and ask. It takes two minutes and it is the only check that works every time.

Will my spam filter stop AI phishing? It will catch a lot, and you should keep it on. But a well written, personal email with no bad link can still look legitimate to a filter. A trained person is the backstop.

What should staff do if they are not sure about a message? Slow down and check through a channel they trust, like calling a known number or walking over and asking. Then report it, even if it turns out to be real.

Are AI phishing emails really more effective? Yes. The NCSC and the FBI have both warned that AI phishing is more convincing and more personal, and the FBI has tied AI to tens of thousands of complaints and hundreds of millions in losses.

If you want to know where your own business stands, we put together a short list of the mistakes we see most often, including the payment one. You can grab the 7 cyber mistakes cheat sheet and check it against your own office in about ten minutes.

Featured image: Pixabay

Leave a Reply