
The Spelling Mistakes Are Gone — And That’s the Problem
For years, spotting a scam email was straightforward: look for dodgy spelling, clumsy grammar, and a greeting like “Dear valued customer.” Real businesses write properly, so a message full of errors was almost certainly fake. It was easy to teach, and it worked — for a while.
It doesn’t anymore.
Scammers now use AI to write their phishing emails, and AI writes well. The typos and awkward phrasing that once gave phishing away have vanished. Messages landing in your team’s inbox read as professionally as anything from a legitimate supplier or bank. The UK’s National Cyber Security Centre (NCSC) has warned that generative AI can produce convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says the same thing: criminals use AI to eliminate the errors that used to make scam emails obvious.
The one thing most people were trained to look for no longer tells you much at all.
Why These Emails Are So Convincing Now
Three things have shifted at once:
The writing is clean. A scam email reads like a normal business email, because a machine produced it in seconds, in whatever tone the attacker wanted.
It’s personal. Attackers pull public details — your website, LinkedIn profiles, press releases — and feed them into an AI tool to craft a message with the right names, the right job titles, and a believable reason to be in touch.
There’s far more of it. AI makes each message faster to produce, so attackers send at much higher volume. The FBI’s Internet Crime Complaint Center linked AI-assisted fraud to more than 22,000 complaints and nearly $893 million in reported losses in a single year.
The result? Instead of an obvious “your account is suspended” email, someone in your finance team receives a message that appears to come from a supplier they genuinely deal with, references a real project, and asks to update bank details before the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.
Your Email Filter Won’t Catch Everything
Microsoft Defender for Office 365 does a solid job of filtering threats, and you should absolutely keep it enabled. But a well-written, personalised email that asks a perfectly normal-sounding question doesn’t always look dangerous to a filter — especially when it carries no suspicious link or attachment. The NCSC and FBI both expect AI to push more of these messages through. That means your last line of defence is a person who knows what to look for.
It’s Not Just Email
AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip — enough to leave a voicemail that sounds like your manager or a colleague asking for an urgent payment. If a call or voicemail asks for money or login details, hang up and call the person back on a number you already have.
The Warning Signs That Still Work
If you can’t trust how an email is written, focus on what it’s asking you to do. AI hasn’t changed these red flags:
- It asks for a payment, gift cards, or a transfer to a new account
- It asks for a login, verification code, or personal details
- It creates urgency — a deadline, a threat, or a “do this now”
- It asks you to change bank details for an invoice or supplier
- It includes a link or attachment you weren’t expecting
- The display name looks right, but the actual email address doesn’t match
The rule to teach your team is simple: when a message is about money, logins, or payment details, slow down before you act.
Practical Steps to Protect Your Team
- Verify payment changes by phone. If an email asks you to pay a new account or update a supplier’s bank details, call the supplier on a number you already hold — not one from the email.
- Update your training. Stop telling staff to look for bad spelling. Teach them to question what an email is asking for.
- Enable phishing-resistant MFA. Microsoft Entra ID supports passwordless and phishing-resistant authentication, so a stolen password is far harder to exploit — even if someone does get tricked.
- Make reporting easy. Nobody should feel embarrassed for flagging a suspicious message. Microsoft Defender lets staff report emails directly from Outlook with one click.
- Have a quick conversation. A five-minute team chat about current scam tactics beats a poster nobody reads.
Frequently Asked Questions
Can you still spot a phishing email by bad spelling?
Not reliably. Attackers use AI to produce clean, correct emails. Judge a message by what it’s asking you to do, not how it’s written.
Will my spam filter stop AI-generated phishing?
It will catch a lot, and you should keep it on. But a well-written, personalised email with no obvious bad link can still slip through. A trained person remains the critical backstop.
What should staff do if they’re unsure about a message?
Slow down, verify through a trusted channel (call a known number or ask the person directly), and report it — even if it turns out to be genuine.
If you’d like help reviewing your team’s phishing awareness, enabling phishing-resistant logins through Microsoft Entra ID, or tightening your email security posture with Microsoft Defender, we’re happy to have that conversation. Get in touch with the team at IT TechNinjas — we’ll help you work out what’s right for your business.
