For years, the advice for spotting a scam email was simple: watch for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message riddled with mistakes was probably fake. It was easy to teach, and for a long time it genuinely worked.

It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a legitimate company — and can be written to sound exactly like someone your team already knows.

Why the old advice stopped working

The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed through. AI took that excuse away entirely.

The UK’s National Cyber Security Centre says generative AI can now produce convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says much the same: criminals use AI to eliminate the grammar and spelling errors that used to flag a message as fake, so it reads as genuinely believable. The one thing most people were trained to watch for doesn’t tell you much anymore.

Why these emails are so convincing now

The writing is clean, because a machine produced it in seconds, in whatever tone the attacker specified. It’s personal, too — attackers can feed public details about your company into an AI tool, pulled from your website, your team’s LinkedIn profiles, or a press release, and get back a message tailored precisely to you: the right names, the right titles, a believable reason to reach out.

And there’s simply more of it. AI makes each message faster to produce, so attackers send far more of them. The FBI’s Internet Crime Complaint Center added an AI-specific section to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses.

The scam email isn’t the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in accounts payable gets a message that looks exactly like a vendor they genuinely deal with, references a real project, and asks to update the banking details on the next invoice. It reads exactly like a real vendor email. The only thing wrong is the vendor never sent it.

Your spam filter won’t catch all of them

It’s tempting to assume email security handles this automatically. It catches plenty, and it should stay switched on — but a well-written, personalized email asking a normal-sounding question doesn’t always trip a filter, especially with no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these through, which is why the real last line of defense is a person who knows exactly what to check.

It’s not just email anymore

AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip — enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI-written emails so convincing makes AI-generated calls convincing too. The defense is identical: if a call or voicemail asks for money or login details, hang up and call the person back on a number you already have.

The signs that still actually work

If you can’t trust how an email is written anymore, look at what it’s asking you to do — that’s where the real warning signs live, and AI hasn’t touched them. It asks for money, gift cards, or a payment to a new account. It asks for a login, a verification code, or personal details. It creates pressure — a deadline, a threat, a “do this now.” It asks you to change the bank details on an invoice or a vendor. It arrives with a link or attachment you weren’t expecting. Or the display name looks right, but the actual email address underneath doesn’t match it.

Every one of those is about what the email is asking for, not how it’s written. The rule worth teaching your team: when a message touches money, logins, or how you pay someone, slow down before acting on it.

How to protect your team

Verify money and login requests through a separate channel — if an email asks you to pay a new account or change a vendor’s bank details, call the person on a number you already have. Don’t reply to the email and don’t use a number it provides. Set one firm rule for payment changes: confirm every change to banking details by phone, even when it’s marked urgent. Turn on phishing-resistant MFA or passkeys, so a stolen password is harder to use even if someone gets fooled. Make it genuinely easy to report a suspicious email without anyone feeling foolish for checking. And remind the team periodically that scam emails look flawless these days — a five-minute conversation beats a poster nobody reads.

Getting your domain’s email authentication records configured properly also stops attackers from spoofing your own company name to target your clients — something we check as part of setting up Fortinet-backed network security for a lot of our New York clients, alongside training staff to spot what technical fixes can’t catch.

Frequently Asked Questions

Can you still spot a phishing email by bad spelling and grammar?
Not reliably anymore. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it’s asking you to do instead.

What warning signs still actually work?
The request itself — paying money, changing bank details, sharing a login or verification code, or being pushed to act urgently. None of those depend on how well the email is written.

Is AI-generated phishing really more effective?
Yes. Both the NCSC and the FBI have warned that AI makes phishing more convincing and more personalized, and the FBI has tied it to tens of thousands of fraud complaints and hundreds of millions in reported losses. Cleaner, tailored messages get opened and clicked more often.

Will my spam filter stop AI-written phishing?
It catches a lot, and it should stay on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone — a trained person is the real backstop.

What should staff do if they’re not sure about a message?
Slow down and verify through a channel they trust, like calling a known number or asking the person directly. And report it, even if it turns out to be genuine — nobody should feel silly for checking.

Prepared by the EB Solution team — cybersecurity and managed IT services for businesses across the New York area. Want your team trained to spot these before they cost you? Reach out to EB Solution and we’ll get it set up.

Watch Our Latest Tech Videos From EB Solution

Call Now