Skip to content
Go to homepageDrova logo

AI phishing: the email with perfect grammar

Staff were trained to spot the typos and odd phrasing. AI-written phishing has neither. What changed, and what still works.

Phishing still wants the same three things: a login, a click or a payment. What AI changed is the quality and the volume, and in doing so it broke the assumption underneath the most common phishing safeguard a business has.

Simple feature visual

TL;DR

  • AI phishing is ordinary phishing written, personalised and scaled by AI. The goal is unchanged; the craft is now flawless.
  • The tells most awareness training taught, typos, odd phrasing, generic greetings, were symptoms of attacker effort. AI removed them, so training built on them protects against attackers who no longer exist.
  • Spear phishing that once took hours of research per target now takes seconds, which means small businesses get the personalised treatment too.
  • What still works does not depend on spotting the fake: verification through a second channel, phishing-resistant sign-in, and a culture where reporting is never punished.
  • If your risk register lists staff awareness training as the main phishing safeguard, the entry is due a re-score.

What is AI phishing?

AI phishing is phishing written, personalised and scaled with AI. The attack itself is decades old: a message that impersonates someone you trust to get a login, a click on something harmful, or a payment. What is new is that the message is now fluent in any language and register, addressed to the right person by name, and able to reference your real colleagues, suppliers and projects, all assembled from public information in seconds.

For businesses, the most damaging version is the one that opens a business email compromise: a harvested login that lets an attacker sit inside a genuine mailbox and redirect genuine payments. The mailbox-and-money half of that story is covered on our page about AI-driven fraud. This page owns the way in: the email itself, and the safeguard it walked past.

Part of our series on the real risks of AI for a business: familiar risks, with the likelihood turned up.

What AI actually upgraded

The grammar

Flawless spelling, native phrasing, even the house style of the organisation being impersonated. The single most-taught tell is gone.

The personalisation

Names, job titles, live projects and supplier relationships pulled from public sources and woven in automatically. Spear phishing is no longer reserved for big targets.

The volume

A campaign that once needed a team now runs from a subscription. More attempts reach more inboxes, and each one is individually tailored.

The follow-through

Replying no longer breaks the illusion. Automated back-and-forth can answer questions, supply documents and keep the thread alive until you act.

The assumption underneath

The safeguard that stopped working

For a decade the standard phishing safeguard was awareness training, and the training's core promise was that fakes are spottable: look for bad spelling, clumsy phrasing, greetings that don't fit. The advice worked because those flaws were symptoms of effort. A convincing email took time, so most attackers never made one.

AI removed the effort without changing the attack. The email with perfect grammar is not a more advanced scam; it is the same scam with the flaw removed. So nothing announced the failure: the register still says staff awareness training, the training still runs, and the thing it teaches people to look for no longer appears.

A safeguard whose assumption has expired while its paperwork stays current is the hardest form of AI risk to spot, and it is rarely limited to phishing. The vocabulary for checking yours is on the safeguards page.

Process over perception

What still works

Everything that still works shares one property: it does not depend on the email looking wrong. Verification through a second channel. Any request involving money, credentials or urgency gets confirmed on a channel the email did not choose, a known number, a walk to the desk. Phishing-resistant sign-in. Passkeys and hardware security keys mean a harvested password is not enough on its own. Reporting without blame. The person who clicked is your fastest alarm; punish the click and you silence the alarm.

Then update the paper. Re-score likelihood on the phishing entry in your risk register, and move verification and sign-in ahead of awareness training as the lead safeguards. Training still belongs, but its content changes: behaviour to follow, not tells to spot.

For reporting routes, the NCSC's phishing guidance covers the UK, and the ACSC's business email compromise guidance covers what to do in Australia when a mailbox or payment is compromised.

AI phishing FAQs

Is AI phishing different from ordinary phishing?

The goal is identical: a login, a click or a payment. What changed is execution. AI writes fluently in any language, personalises each message from public information, and runs thousands of attempts at negligible cost. It is ordinary phishing with the flaws removed.

Can you tell if a phishing email was written by AI?

Usually not, and trying is the wrong game. Judge a message by what it asks you to do, not by how it reads. A request that cannot survive verification on a second channel is the signal; the prose no longer tells you anything.

Does spam filtering stop AI phishing?

Filters still remove bulk phishing, but personalised, low-volume spear phishing is designed to look like legitimate one-to-one mail, which is exactly what filters are built to let through. Filtering is one layer. Verification behaviour and phishing-resistant sign-in are the layers that hold when it misses.

How does phishing relate to business email compromise?

Phishing is usually the way in. A harvested login gives an attacker a genuine mailbox, and from there the fraud becomes payment redirection from a real address. The mailbox-and-money half is covered on our page about AI-driven fraud; this page covers the email that opens the door.

What should phishing training teach now?

Behaviour, not detection. Train the verification habit, normalise reporting with zero blame attached, and retire the spot-the-typo material. The measure of good training is how fast people report, not how well they grade prose.

The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.

Phishing is just one risk. See everything AI is driving.

AI risk series

Explore related topics

The real risks of AI for a business

The series hub: what counts as an AI risk, the four families, and where to start.

Fraud no longer needs a forger

Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.

AI scams targeting businesses

Old cons, industrialised: the four branches, the tells that remain, and what to do if you're hit.

Guardrails, safeguards, controls: what AI actually needs

Three words untangled, and the four families of AI-era safeguards.

Prompt injection: the attack your register hasn't heard of

Instructions hidden in ordinary content, and the safeguards that limit the damage.

How to run an AI risk assessment

Three ways to do it, compared, and the five steps.

The AI risk register

What every entry carries, with worked examples.

The AI policy your business actually needs

The full template, free on the page, and how to make it yours.

AI in risk management: what it can genuinely do

The four jobs AI does well, and the three things it must never own.

What is AI disruption?

A plain definition: the change is in your risks and plans, not just your tools.

AI cyber attacks: when the attack is automated

Familiar attacks at a new tempo: the real uplift, the hype, and the fundamentals that still hold.

AI hallucinations at work: examples and what they cost

Three documented cases with price tags, and the verification safeguards that catch fabrication before it ships.

See your own AI risk picture

The risks AI is driving against your objectives, scored for your business.