All blogs

Why phishing no longer looks like phishing, and how AI is changing fraudulent emails

2026-08-02 | 10 min Cyber Security

For years, phishing was associated with grammatical errors, awkward phrasing, and suspicious links. However, such indicators are gradually becoming less reliable. Generative AI makes it possible to craft messages with superior language quality, tailor them to specific individuals, and combine email with other communication channels. The result is phishing that increasingly resembles standard corporate communication.

Phishing still works on the same principle. The goal is to persuade a person to take an action that the attacker needs. This may involve, for example:

  • entering login credentials,
  • opening a malicious attachment,
  • clicking a link,
  • approving a sign-in request,
  • sending sensitive data,
  • changing bank details,
  • or making a payment.

What is changing, however, is how attackers establish credibility.

Grammar mistakes are no longer a reliable warning sign

Older phishing campaigns often revealed themselves through language shortcomings. Unnatural Slovak, awkward phrasing, or a generic greeting were reasons to be alert. Generative AI, however, can:

  • correct grammar,
  • adapt the tone of communication,
  • create text in a specific language,
  • tailor a message to a specific job role,
  • or prepare multiple variants of the same campaign.

The result may be a message that is linguistically indistinguishable from ordinary workplace communication. The simple rule that phishing can be recognised by ‘bad Slovak’ therefore no longer applies. The absence of language mistakes is not proof that a message is trustworthy.

AI makes personalised spear phishing easier

With ordinary phishing, large numbers of people may receive the same message. Spear phishing is more targeted. The attacker adapts the content to a specific person, job role, or company. For example, the message may relate to:

  • a specific supplier,
  • an invoice,
  • a job role,
  • a company project,
  • an internal policy,
  • a shared document,
  • recruitment,
  • or a management request.

The information needed to create this kind of context does not necessarily have to come from a compromised system. Much of it is publicly available on:

  • a company website,
  • LinkedIn,
  • social media,
  • job portals,
  • conference websites,
  • press releases.

AI makes it possible to turn such information more quickly into text that matches a specific context. This narrows the gap between mass phishing and an attack that appears to be individually crafted communication.

Phishing can impersonate both a manager and a supplier

An attacker does not have to convince a user that they are communicating with an unfamiliar organisation. It is often more effective to impersonate someone who is already trusted. This may be:

  • a supervisor,
  • the finance department,
  • IT support,
  • a colleague,
  • a bank,
  • an accountant,
  • a carrier,
  • or a business partner.

A typical situation is a request that does not seem unusual in itself.

For example:

  • a supplier announces a change of bank account,
  • management urgently needs a payment to be approved,
  • the IT department requests a new sign-in,
  • a colleague sends a document for approval.

Credibility is created by a combination of a familiar name, workplace context, and time pressure. The human factor remains one of the most important parts of cyber risk. In the interview “Today it is easier to hack a person than a system”, an ANASOFT service technician points out that technical protection alone is not enough if an attacker can manipulate the user.

The attack does not have to remain confined to email

Email may be only the first part of the attack. It may then continue through:

  • a phone call,
  • SMS,
  • Teams,
  • WhatsApp,
  • or another communication platform.

The individual steps then reinforce each other’s credibility. For example, an email announces a change to a payment, and a few minutes later a call comes from someone posing as the supplier. Or a message from ‘IT support’ reports a problem with the account, followed by a request to approve a sign-in. This type of attack is more effective precisely because it does not look like an isolated suspicious email. It looks like a sequence of ordinary workplace events.

AI does not change the principle of the attack, but it lowers the cost of preparing it

Generative AI is not a new type of cyberattack. It is a tool that can speed up some parts of social engineering. An attacker can more easily:

  • create text variants,
  • change the language and tone,
  • prepare content for different roles,
  • respond to current events,
  • or personalise communication.

This means that better preparation no longer has to be reserved only for the most sophisticated attacks. When assessing security risks, it is therefore important to focus not only on new technologies, but also on how existing types of attacks are becoming more convincing.

Which signals remain important

Although grammar is losing significance as the main indicator, phishing is often still revealed by the context of the request. Particular attention should be paid to situations where the message:

  • creates unusual time pressure,
  • asks for a change to the standard procedure,
  • requests sensitive data,
  • changes payment information,
  • requires a new sign-in,
  • asks the user to approve an unexpected MFA request,
  • moves the communication to another channel,
  • or contains an unexpected attachment or link.

The key question is not merely: Does the email look suspicious? The more important question is: Is the request expected in the given workplace context?

Find out how to secure corporate communications and identities so that a single convincing phishing attack does not escalate into a major security incident.

Contact us

User vigilance is important, but it cannot be the only protection

Security training has its place. It helps build habits in which unusual requests are verified and users know when to be alert. However, it is not realistic to expect a person to recognise every attempt. An attack may:

  • come from a genuinely compromised account,
  • continue an existing conversation,
  • use natural language,
  • use real data,
  • or reach the user while they are under time pressure.

One common mistake companies make is therefore to place too much responsibility on employees themselves. The article The 5 most common IT security mistakes companies make examines human, process, and technical shortcomings in greater detail. Cyber protection works better as a system of multiple layers than as an expectation that the user will always make the right decision.

A password may be only the beginning of the problem

A large proportion of phishing attacks are aimed at obtaining login credentials. The user opens a page that looks like a legitimate sign-in page and enters:

  • a username,
  • a password,
  • and possibly another authentication detail.

At that point, the problem is no longer limited to the phishing email. The identity has been compromised. The important question becomes what the attacker can do next with such an account.

They may try to:

  • access email,
  • gain access to cloud applications,
  • search for sensitive documents,
  • send further phishing messages from a trusted account,
  • or gain access to other systems.

This is why the article How to keep your corporate infrastructure from being hacked emphasises not only passwords, but also multi-factor authentication, access management, and continuous activity monitoring.

Even multi-factor authentication is no reason to stop being vigilant

MFA significantly reduces the risk that a stolen password alone will give an attacker access. However, it should not be understood as absolute protection. Attackers may, for example, try to:

  • persuade the user to approve an unexpected authentication request,
  • exploit an already active session,
  • or create a phishing scenario that imitates a legitimate sign-in process.

This is also why identity protection combines several principles:

  • strong authentication,
  • limited permissions,
  • access control,
  • evaluation of unusual behaviour.

Neither a password nor MFA can therefore be assessed in isolation from what happens to the account after sign-in.

It is also important to see what follows phishing

Phishing is often only the entry point. If the attack succeeds, the next steps may take place without any fraudulent email. The attacker may use a legitimate account, and at first glance their activity may not differ significantly from that of an ordinary user.

Warning signs may include, for example:

  • an unusual sign-in time or location,
  • access to systems that the user does not normally use,
  • an unusual volume of downloaded data,
  • changes to rules in the email inbox,
  • attempts to obtain higher permissions,
  • or a combination of several smaller anomalies.

This is also why corporate security needs to monitor not only the entry point, but also behaviour within the environment. The article How to keep your corporate infrastructure from being hacked provides a broader view of combining prevention, authentication, segmentation, and monitoring.

Phishing may be the beginning of a larger incident

Successful phishing does not have to end with a stolen email account. Depending on the type of compromise, it may be the first step towards:

  • financial fraud,
  • a data leak,
  • the compromise of additional users,
  • the takeover of an administrator account,
  • or the deployment of malicious software.

In some cases, phishing may also be one route to a ransomware incident. It therefore makes sense to view it in the context of the broader attack lifecycle. The article How to prevent ransomware and what to do when a company falls victim to it examines prevention and response in greater detail for situations in which an attack has already affected corporate systems.

Protection against phishing combines technology, processes, and people

Phishing cannot be solved with a single measure. Security awareness helps people recognise a suspicious situation. Technical protection can stop some attacks before they reach the user.

Multi-factor authentication can reduce the consequences of a stolen password. Monitoring helps detect situations in which a compromised account begins to display unusual behaviour. Company processes, however, are equally important.

For example, a change to a supplier’s bank account should not be confirmed solely on the basis of a single email. Sensitive financial operations may require independent verification or multiple approvals. The more convincing social-engineering tools become, the more important control mechanisms are that do not depend solely on the user’s impression.

AI raises the bar, but the principles of protection remain

Phishing is unlikely to become easier to recognise in the future. Generative tools remove some of the shortcomings that previously helped identify fraudulent content. Credible-sounding language is therefore no longer an argument for trusting a message. The context matters more:

  • who is sending the request,
  • whether it is expected,
  • what it asks for,
  • whether it follows the established process,
  • and what may happen after it is carried out.

The best response is therefore not to look for a new list of ‘ten signs of phishing’ that will work forever. A more effective model combines:

  • security awareness,
  • verification of unusual requests,
  • identity protection,
  • restricted access,
  • technical prevention,
  • and security-event monitoring.

The combination of technology and human behaviour is also the subject of the interview with ANASOFT’s CIO, “Many risks arise on the human side”, which points out that simply purchasing security technologies does not address how a company manages risk.

Phishing is changing. However, the basic goal of cybersecurity remains the same: to create an environment in which a single mistake or one convincing email cannot easily escalate into a serious incident.

Phishing is changing. Corporate protection must keep pace

More convincing language, personalisation, and the linking of multiple communication channels mean that phishing can no longer be reliably filtered solely on the basis of a user’s impression. More effective protection comes from combining security awareness, verification of unusual requests, identity protection, technical controls, and monitoring of suspicious behaviour.

It is therefore important for companies to assess not only whether employees can recognise phishing, but also what happens if an attack succeeds in passing through the first line of defence. 

Frequently Asked Questions

Generative AI enables the faster creation of messages that are natural-sounding and contextually tailored. It facilitates translation, tone adjustment, and personalization, as well as the creation of multiple variants of a phishing campaign.

Grammatical errors remain a potential warning sign, yet their absence proves nothing. Modern phishing can be linguistically flawless and resemble routine business communication.

Spear phishing is a more targeted type of phishing in which communication is tailored to a specific person, job role, or organization. The attack may utilize information about the company, colleagues, suppliers, or work processes.

No. Security awareness is an important layer, but it must be complemented by technical safeguards, secure processes, identity protection, and monitoring. The user cannot be the only barrier between a phishing message and the corporate system.

Multi-factor authentication significantly reduces the risk of password misuse, but there are attacks targeting authentication processes and active sessions as well. MFA is therefore an important, though not the only, layer of protection.