The classic signs of a phishing email — broken grammar, odd phrasing, a generic greeting — are disappearing fast. Attackers now use language models to write fluent, personalised messages at scale, and the old advice to just look for mistakes no longer holds.
What has changedAI lets attackers mimic a colleague's tone, reference real projects scraped from public sources, and localise perfectly. Business email compromise — impersonating an executive or supplier to redirect a payment — has become harder to spot and more convincing than ever.
Why old signals failIf the message reads perfectly and appears to come from someone you know, your instinct to trust it is exactly what the attacker is counting on. Detection can no longer rely on spotting errors.
How to defend- Enforce SPF, DKIM and DMARC so spoofed senders are rejected
- Clearly flag external emails
- Use phishing-resistant MFA so stolen credentials are not enough on their own
- Build a habit of verifying unusual requests through a second channel — especially anything involving money or credentials
NOORTECH helps teams test their human and technical defences together. Talk to us about a phishing-resilience review.