How generative AI has changed what a convincing scam looks like, and what businesses can do about it:
For years, the advice for spotting a phishing email was fairly reliable: look for poor spelling, awkward phrasing, generic greetings, and a mismatched sender address. That advice is quickly becoming outdated. AI tools have made it trivial for scammers to produce polished, personalised, and well researched messages at a scale that simply wasn’t possible a few years ago.
What’s actually changed
Modern phishing attempts increasingly reference real details, a genuine supplier name, a recent invoice, an actual staff member’s name and role, pulled together from public information like LinkedIn, company websites, and data from previous breaches. The result reads like it came from someone who actually knows your business, because in a sense, it does.
Voice and video are catching up too. Deepfake audio, a synthetic but convincing recreation of someone’s voice, has already been used in real world scams where an attacker impersonates a CEO or manager on a phone call to authorise an urgent payment or password reset. It no longer takes a large amount of sample audio to produce something convincing enough to fool a distracted staff member on a busy day.
Why staff training still matters, but isn’t enough on its own
The old rule of thumb, look for the red flags, needs an update, because the red flags themselves have changed. Staff need to be trained to be suspicious of unusual requests based on the nature of the request itself (an urgent payment, a request to bypass normal process, pressure to act quickly and quietly) rather than relying on spotting a mistake in the message.
That’s why training on its own is no longer sufficient. It needs to be paired with technical controls that don’t rely on a human catching every attempt: email filtering that inspects links and attachments rather than just sender reputation, multi factor authentication so a stolen password alone isn’t enough to get in, and clear internal processes (like verifying payment changes by phone through a known number, not by replying to the email itself) that don’t depend on someone remembering to be suspicious in the moment.
Practical steps for your business
- Run regular phishing simulations so staff build the habit of pausing and verifying, not just a one off training session
- Put a verification process in place for any request to change payment details, bank accounts, or make an urgent transfer, verified by phone through a known number, never by replying to the email or message
- Use multi factor authentication everywhere it’s available, so a convincing phishing email that captures a password still isn’t enough on its own
- Layer technical filtering on top of staff awareness, treating people and technology as two parts of the same defence rather than relying on either alone
AI has lowered the cost and effort required to run a convincing scam, which means the volume and quality of attempts your staff will see is only going to increase. The businesses that stay ahead of it are the ones treating awareness and technical controls as a package, not a choice between one or the other.
If you’d like to put phishing simulation, staff training, or stronger email filtering in place, get in touch with the Pure Logic team






