Phishing emails used to be easy to spot: clumsy grammar, generic greetings, a sender address that didn't quite match the company it claimed to be from. That era is ending. Security researchers say generative AI has closed most of the gaps that once gave phishing attempts away, and the result is a wave of messages that look and read like they came from a real colleague, vendor, or bank.
What's actually changed
Large language models let attackers produce fluent, error-free text in seconds, in any language, tailored to a specific target. Instead of blasting out one generic template to thousands of addresses, criminals can now scrape a company's website, press releases, and social media, then generate a message that references a real project name, a recent executive hire, or an upcoming event. Some campaigns go further, using AI-generated voice clips or video clips — commonly called vishing or deepfake-assisted social engineering — to follow up a suspicious email with a phone call that sounds exactly like a real manager or IT technician.
Why this matters for defenders
Traditional phishing training leaned heavily on teaching people to spot red flags: bad spelling, urgent language, mismatched links. Those cues are disappearing. Security teams say the shift means training has to move from "spot the fake" to "verify through a second channel," regardless of how convincing a message looks.
Some of the trends security teams are tracking include:
- Hyper-personalization — messages referencing real internal details pulled from public sources or previous breaches.
- Multi-channel attacks — an email followed by a text message or phone call to build false credibility.
- Brand impersonation at scale — AI-generated clones of login pages that are visually identical to the real thing.
- Faster iteration — attackers testing and refining messages against spam filters far more quickly than before.
What organizations are doing about it
Email security vendors are responding with their own AI-based detection, looking less at obvious red flags and more at behavioral signals: whether a sender has ever emailed the recipient before, whether a link's destination matches its displayed text, and whether the request (a wire transfer, a password reset) fits the sender's normal pattern.
On the policy side, many companies are accelerating a move toward phishing-resistant authentication, such as passkeys and hardware security keys, on the theory that even a perfectly crafted phishing email is far less dangerous if it can't be used to harvest a reusable password. Combined with stricter verification procedures for anything involving money or credentials, security leaders say the goal isn't to make every employee a forensic email analyst — it's to make the underlying systems less exploitable even when a message gets through.