Hacker Hub - September 2026

AI Phishing Is Getting Scarily Convincing. Here's How to Spot It Anyway

The old advice for spotting a phishing email was simple. Look for bad spelling, clumsy grammar, and a weird sense that something's off. That advice is quickly becoming useless.

AI tools can now write a phishing email that reads better than most internal memos. No typos, no broken grammar, no obvious tells. Just a well written message that looks exactly like it came from your supplier, your bank, or your own managing director. The bar for what used to make a scam obvious has effectively disappeared.

What's Actually Changed

Phishing used to rely on volume and luck. Criminals sent out thousands of generic emails and hoped a small percentage of people clicked. AI has changed the economics entirely.

Now attackers can generate personalised, well written emails at scale, referencing real company names, real job titles, and real sounding requests. Some are going further, using AI generated voice or video to impersonate a real person on a phone call or a video message, asking staff to approve a payment or share login details. When the message sounds like your boss and looks like your boss, the old instinct to check for spelling mistakes just doesn't apply anymore.

Why This Matters More for Smaller Businesses

Larger organisations often have layers of approval built into how money moves and how requests get actioned. Smaller businesses tend to move faster and trust more, which is usually a strength, right up until someone convincing asks for something urgent.

A well timed message asking a member of staff to process an invoice, reset a password, or click through to "verify" an account can look completely routine. That's the point. AI phishing isn't trying to trick people who are being careless. It's built to get past people who are paying attention, using the exact language and tone they'd expect.

How to Actually Spot It

Since the writing quality no longer gives it away, the checks need to shift somewhere else.

Slow down on urgency. Scam emails still rely heavily on pressure, a deadline, a threat, a sense that something bad happens if you don't act now. That pressure is a signal in itself, regardless of how polished the email looks.

Check the request, not just the writing. Would this person normally ask for this, in this way, through this channel. A genuine request for a payment change or a password reset almost never needs to happen in the next ten minutes over email alone.

Verify through a second channel. If an email or a call asks for money to move or credentials to be shared, confirm it directly with the person through a method you already know is theirs, not a number or reply address given in the message itself.

Look at where links actually go. Hovering over a link before clicking still works, even when the surrounding email is flawless. A mismatched or unfamiliar web address is often the one thing AI hasn't smoothed over yet.

What This Means for Your Business

Training staff to spot bad grammar is no longer enough. What matters now is training people to notice pressure, verify unusual requests, and pause before acting on anything involving money or access, no matter how convincing it looks or sounds.

Technical controls still matter too. Multi factor authentication, email filtering, and clear internal processes for approving payments all reduce how much damage a single convincing message can do, even if someone almost falls for it.

FAQ

Can you still spot phishing emails by bad spelling?
Not reliably anymore. AI generated phishing emails are often well written, with no spelling or grammar mistakes to flag them.

What is the best single habit to teach staff?
Pausing on urgency. Scam messages still rely on pressure to act fast, and that pressure is often the clearest warning sign left.

Are voice and video scams a real risk for small businesses?
Yes. AI generated voice and video impersonation is increasingly used to pressure staff into approving payments or sharing sensitive information.

Is training alone enough to prevent AI phishing attacks?
No. Training reduces risk but should be combined with technical controls like MFA, email filtering, and clear payment approval processes.

If you are not sure how exposed your business is to this kind of scam, it is worth a proper look at your email security and staff processes. Get in touch with Vorago Security for a straightforward conversation about where to start.

View All Posts
Blog Image

August 16, 2026

Hacker Hub - August 2026

Small businesses aren't too small to be targeted. They're often the preferred target. Here's why the 'we're too small' mindset is one of the most dangerous in business.

Read More