
The new phishing era is less about obvious scams — and more about convincing, context-aware deception.
The key shift: AI can help attackers create messages that sound natural, match a target's context, and arrive at exactly the right moment. That means "it looks professional" is no longer a useful safety test.
A practical guide for spotting modern social engineering before it becomes an incident.
Traditional phishing often relied on obvious warning signs: bad grammar, strange formatting, generic greetings, or suspicious-looking links. Generative AI makes those signals much weaker.
Attackers can generate polished, fluent messages in multiple languages and adapt tone to a specific audience.
AI can help tailor a message around a role, business process, current event, or believable request.
A failed lure can be rewritten quickly. Attackers can test different subject lines, tones, and calls to action.
The same campaign can be customized across many recipients without manually writing every message.
Phishing is becoming a trust problem, not just a spelling problem. A message can be grammatically perfect and still be malicious. The safest approach is to evaluate the request itself: Is it unusual? Is it urgent? Does it ask for access, money, credentials, or sensitive information?
Sometimes. But don't rely on appearance alone. Instead, look for behavioral clues and verify the request through a separate trusted channel.
DISPLAY NAME
Your Finance Team
REQUEST
"Please approve this payment before 3 PM."
CONTEXT
Mentions a real project or supplier
PRESSURE
"I'm in a meeting — please handle it urgently."
Phishing is no longer limited to email. AI-generated voice, images, and video can increase the credibility of a social-engineering attempt — especially when combined with information gathered from public sources.
VOICE
A familiar voice may be used to create urgency or impersonate a manager, supplier, or family member.
VIDEO
Real-time or pre-recorded video can create a stronger sense of presence during a high-pressure request.
IDENTITY
Public information can be combined to make a fake profile or conversation appear consistent and believable.
Stop. Slow down. Verify. A real executive, colleague, or supplier should not become offended simply because you follow the organisation's security process.
Don't click, approve, transfer, or disclose yet.
Use a trusted channel you already know.
Send the suspicious message to your security team or reporting mechanism.
If you already clicked or shared information, report it immediately. Fast reporting can reduce impact.
Before you trust a message, run this quick mental checklist. It is simple enough to use during a busy workday — and strong enough to stop many social-engineering attempts.
Do I really know who sent this?
What exactly am I being asked to do?
Why does it need to happen immediately?
Could this expose money, credentials, data, or access?
Can I confirm it through a trusted, independent channel?
Security awareness works best when employees have a safe way to question unusual requests. Encourage people to verify without fear of being blamed for "slowing things down." A strong culture makes verification normal.
AI may make phishing more convincing. It does not change the fundamentals of good security: slow down, verify independently, and protect the process.
Security is not about spotting every fake message. It is about making sure one convincing message cannot easily become a successful incident.
Even if it sounds exactly like your boss, your bank, or your mate Dave — that doesn't mean it actually is.
Before you click, transfer money, or hand over a password — double-check using a number or email you already know and trust.
If someone gets cranky because you're being careful, that's a red flag. No legit person minds you being a bit cautious.

New to all this security lingo? No worries — here's a quick cheat sheet so you know what everyone's on about.
A scam where someone pretends to be a trusted person or organisation (like your bank or your boss) to trick you into handing over passwords, money, or personal info. Like fishing — they're casting a line hoping you'll bite.
A fake video, photo, or voice recording made using AI that looks or sounds like a real person. Imagine someone making a video that looks exactly like your manager asking you to transfer funds — that's a deepfake.
Tricking people (rather than hacking computers) to get what you want. Instead of breaking into a system, a scammer convinces you to open the door yourself. It's manipulation, plain and simple.
Computer software that can write text, create images, or even fake voices and videos that look and sound incredibly real. It's the tech behind tools like ChatGPT — and unfortunately, scammers can use it too.
A way of proving it's really you when you log in — usually by entering your password AND a code sent to your phone. Even if a scammer gets your password, they still can't get in without that second step. Think of it as a double-lock on your front door.
An app that remembers all your passwords for you, so you only need to remember one master password. It also helps you use strong, unique passwords for every account — no more "password123" for everything!
Your username and password combo. If a scammer gets these, they can log in as you. Guard them like you'd guard your PIN at an ATM.
A way of contacting someone that you already know is legit — like a phone number saved in your contacts, or an email address you've used before. Not a new number or link provided in a suspicious message.
The bait in a scam — the fake story, urgent request, or tempting offer designed to get you to act without thinking. Classic lures include "your account has been compromised" or "you've won a prize!"
When a security problem actually happens — like someone successfully stealing your password or money. The whole point of this guide is to stop an incident before it starts.
AI Is Changing Phishing