AI phishing and deepfake scams

Why the old warning signs no longer apply.

How generative AI has changed what a convincing scam looks like, and what businesses can do about it:

For years, the advice for spotting a phishing email was fairly reliable: look for poor spelling, awkward phrasing, generic greetings, and a mismatched sender address. That advice is quickly becoming outdated. AI tools have made it trivial for scammers to produce polished, personalised, and well researched messages at a scale that simply wasn’t possible a few years ago.

What’s actually changed

Modern phishing attempts increasingly reference real details, a genuine supplier name, a recent invoice, an actual staff member’s name and role, pulled together from public information like LinkedIn, company websites, and data from previous breaches. The result reads like it came from someone who actually knows your business, because in a sense, it does.

Voice and video are catching up too. Deepfake audio, a synthetic but convincing recreation of someone’s voice, has already been used in real world scams where an attacker impersonates a CEO or manager on a phone call to authorise an urgent payment or password reset. It no longer takes a large amount of sample audio to produce something convincing enough to fool a distracted staff member on a busy day.

Why staff training still matters, but isn’t enough on its own

The old rule of thumb, look for the red flags, needs an update, because the red flags themselves have changed. Staff need to be trained to be suspicious of unusual requests based on the nature of the request itself (an urgent payment, a request to bypass normal process, pressure to act quickly and quietly) rather than relying on spotting a mistake in the message.

That’s why training on its own is no longer sufficient. It needs to be paired with technical controls that don’t rely on a human catching every attempt: email filtering that inspects links and attachments rather than just sender reputation, multi factor authentication so a stolen password alone isn’t enough to get in, and clear internal processes (like verifying payment changes by phone through a known number, not by replying to the email itself) that don’t depend on someone remembering to be suspicious in the moment.

Practical steps for your business

  • Run regular phishing simulations so staff build the habit of pausing and verifying, not just a one off training session
  • Put a verification process in place for any request to change payment details, bank accounts, or make an urgent transfer, verified by phone through a known number, never by replying to the email or message
  • Use multi factor authentication everywhere it’s available, so a convincing phishing email that captures a password still isn’t enough on its own
  • Layer technical filtering on top of staff awareness, treating people and technology as two parts of the same defence rather than relying on either alone

AI has lowered the cost and effort required to run a convincing scam, which means the volume and quality of attempts your staff will see is only going to increase. The businesses that stay ahead of it are the ones treating awareness and technical controls as a package, not a choice between one or the other.

If you’d like to put phishing simulation, staff training, or stronger email filtering in place, get in touch with the Pure Logic team

Related Articles:

Boost business growth with Managed IT

Understand how IT can be flexible and grow with your business.

What is two-factor authentication?

Learn how 2FA can help keep your accounts secure.

Why your MSP’s own security matters

The IT provider protecting your business is also part of your attack surface.

Our relationship with these trusted professionals makes it easy to deliver comprehensive support to you every time.
5 STAR GOOGLE RATING

Hear From Our Happy Customers

We’re proud to share some of the glowing feedback from our delighted clients.