For years, the advice for spotting a scam email was simple: watch for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it actually worked.
It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company — and can be written to sound like they came from someone your team already knows.
The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed. AI took that excuse away entirely.
The UK’s National Cyber Security Centre says generative AI can now produce convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says essentially the same thing: criminals use AI to eliminate the grammar and spelling errors that used to flag a message as fake, so it reads as genuinely believable. The one thing most people were trained to look for no longer tells you much of anything.
The writing is clean, because a machine wrote it in seconds, in whatever tone the attacker asked for. It’s personal, too — attackers can feed public details about your company into an AI tool, pulled straight from your website, your team’s LinkedIn profiles, or a press release, and get back a message tailored precisely to you: the right names, the right titles, a believable reason to be in touch.
And there’s simply more of it. AI makes each message faster to produce, so attackers send far more of them. The FBI’s Internet Crime Complaint Center added an AI-specific section to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses.
The scam email isn’t the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in your finance team gets a message that looks exactly like a supplier they genuinely deal with, mentions a real project, and asks to update the bank details on the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.
It’s tempting to assume your email security handles this. It catches plenty, and it should stay switched on — but a well-written, personalized email asking a normal-sounding question doesn’t always trip a filter, especially with no obvious bad link or attachment attached. Both the NCSC and the FBI expect AI to push more of these through, which is why the last real line of defence is a person who knows exactly what to check.
AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip — enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI-written emails so convincing makes AI-generated calls convincing too. The defence is identical: if a call or voicemail asks for money or login details, hang up and call the person back on a number you already have.
If you can’t trust how an email is written anymore, look at what it’s asking you to do — that’s where the real warning signs live, and AI hasn’t changed them. It asks for money, gift cards, or a payment to a new account. It asks for a login, a verification code, or personal details. It creates pressure — a deadline, a threat, a “do this now.” It asks you to change the bank details for an invoice or a supplier. It arrives with a link or attachment you weren’t expecting. Or the display name looks right, but the actual email address underneath doesn’t match it.
Every single one of those is about what the email is asking for, not how it’s written. The rule worth teaching your team: when a message is about money, logins, or how you pay someone, slow down before acting.
Check money and login requests through a separate channel — if an email asks you to pay a new account or change a supplier’s bank details, call the person on a number you already have. Don’t reply to the email and don’t use a number it supplies. Make one firm rule for payment changes: confirm every change to bank details by phone, even when it’s marked urgent. Turn on phishing-resistant MFA or passkeys, so a stolen password is harder to use even if someone gets fooled. Make it genuinely easy to report a suspicious email, and make sure nobody feels foolish for checking. And remind the team periodically that scam emails look perfect these days — a five-minute chat beats a poster nobody reads.
Getting the SPF, DKIM, and DMARC records on your own domain configured properly also stops attackers from spoofing your company’s name to send convincing fakes to your own clients — a piece our clients often haven’t had checked in years. It’s also exactly the kind of thing worth covering in staff training on spotting scam emails, since the technical fix only stops half the problem.
Can you still spot a phishing email by bad spelling and grammar?
Not reliably anymore. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it’s asking you to do instead.
What warning signs still actually work?
The request itself — paying money, changing bank details, sharing a login or verification code, or being pushed to act urgently. None of those depend on how well the email is written.
Is AI-generated phishing really more effective?
Yes. Both the NCSC and the FBI have warned that AI makes phishing more convincing and more personalized, and the FBI has tied it to tens of thousands of fraud complaints and hundreds of millions in reported losses. Cleaner, tailored messages get opened and clicked more often.
Will my spam filter stop AI-written phishing?
It catches a lot, and it should stay on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone — a trained person is the real backstop.
What should staff do if they’re not sure about a message?
Slow down and verify through a channel they trust, like calling a known number or asking the person directly. And report it, even if it turns out to be genuine — nobody should feel silly for checking.
Prepared by the EB Solution team — cybersecurity and managed IT services for businesses across the Greater Toronto Area. Want your team trained to spot these before they cost you? Reach out to EB Solution and we’ll get it set up.