Leave a message

HOW TO SPOT A PHISHING EMAIL WHEN SCAM MESSAGES LOOK REAL

An illustration of a hand reaching out from a laptop email envelope to grab cash and a credit card, illustrating online fraud and How to Spot a Phishing Email.

Article Summary: Scammers now use AI to write their phishing emails, so the spelling and grammar mistakes that used to give them away are gone. The UK’s National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal, and harder to spot. The way to catch them now is to look at what an email is asking you to do, because the writing no longer gives anything away. 

For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it worked. 

It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know. 

Why the old advice stopped working

The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed. AI took that away. 

The UK’s National Cyber Security Centre says generative AI can now create convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake, so it reads as believable. That means the one thing most people were trained to look for no longer tells you much. 

Why these emails are so convincing now 

  • The writing is clean. A scam email reads like a normal business email, because a machine wrote it in seconds, in whatever tone the attacker asked for. 
  • It’s personal. Attackers can feed public details about your company into an AI tool, pulled from your website, your team’s LinkedIn profiles, or a press release, and get a message tailored to you: the right names, the right job titles, and a believable reason to be in touch. 
  • There’s more of it. AI makes each message faster to produce, so attackers send far more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses. 


These days, a malicious message isn’t always the obvious “Dear customer, your account is suspended.” Instead, someone in your finance team might receive a targeted message that looks like it came from a real supplier, references an ongoing project, and asks to update bank details for an upcoming invoice. Without strong cyber security services and awareness training, these attacks easily slip past unsuspecting staff. 

Your spam filter won’t catch them all 

It’s tempting to assume your automated email security will catch every threat. While spam filters stop a high volume of generic spam, a well-written, personalized message with no malicious link or attachment can easily bypass automated security scans. Both cybersecurity authorities and managed IT specialists expect sophisticated AI phishing emails to penetrate standard defenses, making educated employees your ultimate backstop. 

If you want to evaluate your current defense posture, exploring comprehensive managed IT services can help identify gaps in your security stack. 

It’s not just email anymore

AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip, enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defense is the same: if a call or voicemail asks for money or logins, hang up and call the person back on a number you already have. 

Here are the signs you should still pay attention to 

desktop computer setup displaying a web layout alongside a browser window, illustrating user interface design and WordPress Website Security.

If you can’t trust how an email is written, look at what it’s asking you to do. That’s where the real warning signs are, and AI hasn’t changed them: 

  • It asks for money, gift cards, or a payment to a new account. 
  • It asks for a login, a verification code, or personal details. 
  • It creates pressure: a deadline, a threat, or a “do this now.” 
  • It asks you to change the bank details for an invoice or a supplier. 
  • It comes with a link or attachment you weren’t expecting. 
  • The display name looks right, but the actual email address doesn’t match it. 


Every one of these is about what the email is asking for. So the rule to teach your team is simple: when a message is about money, logins, or how you pay someone, slow down before you act. 
 

How to protect your team 

Teaching your workforce how to spot a phishing email requires updating your security protocols: 

  • Out-of-Band Verification: Require staff to confirm any bank account changes or payment requests via a known phone number. Never rely on phone numbers or links provided within the suspicious email itself. 
  • Update Security Training: Shift training away from spotting typos toward identifying suspicious requests involving financial transactions or credentials. 
  • Implement Phishing-Resistant MFA: Deploy hardware security keys or passkeys across your organization. Paired with proper cloud services configuration and identity management, stolen passwords become significantly less dangerous. 
  • Establish Clear Reporting: Make it simple for employees to report suspicious messages without fear of friction or false alarms. 


If you need guidance on configuring your cloud tools or email environment, feel free to contact our team for expert assistance. 

Frequently Asked Questions 

Can you still spot a phishing email by bad spelling and grammar? 

Not reliably. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it asks you to do. 

What are the warning signs that still work?

The request itself: paying money, changing bank details, sharing a login or code, or being pushed to act urgently. Those signs don’t depend on how the email reads. 

Is AI-generated phishing really more effective?

Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal, and the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions in losses. Cleaner, tailored messages get opened and clicked more often. 

Will my spam filter stop AI phishing? 

It will catch a lot, and you should keep it on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone. A trained person is the backstop. 

What should staff do if they aren’t sure about a message? 

New Logo of Cascade IT Services

Employees should pause and verify the message through a separate trusted communication channel. If you’re looking to strengthen your company’s overall technical defenses and employee security posture, explore our complete range of IT services or visit our about us page to learn more about how we help protect local businesses.

Disclaimer: This blog post is for informational purposes only and does not constitute legal, financial, or IT advice. For professional guidance tailored to your business, consult with Cascade IT Services or a certified Microsoft partner. 

Article used with permission from The Technology Press.