We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ...
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.
Other uncategorised cookies are those that are being analysed and have not been classified into a category as yet.
For years, security awareness training has taught people to spot phishing by its tells: clumsy grammar, generic greetings, slightly-wrong sender addresses, urgent demands that feel a bit off. AI tools have quietly eroded almost all of those tells.
Generative AI makes it trivial for an attacker to produce a flawless, contextually appropriate email in seconds, in fluent English, referencing real details scraped from a company’s website or LinkedIn presence. The “Dear Sir/Madam” giveaway is gone. So is the broken English. What’s left is an email that reads exactly like something a genuine colleague, supplier, or client might send, often timed to coincide with real events, like impersonating a supplier shortly after a genuine invoice has gone out, or referencing a real project name pulled from public job postings or social media.
The same shift is happening with voice and video. AI voice cloning needs only a small sample of someone’s voice, sometimes pulled from a public video or conference recording, to produce a convincing imitation. Combine that with a spoofed caller ID and a pretext built from publicly available information, and the classic “call to verify” advice that used to catch out email-only scams becomes far less reliable.
None of this means awareness training is pointless, but it does mean training built entirely around spotting obvious red flags needs updating. The more effective approach combines technical controls with a different kind of awareness: verifying unusual requests (particularly anything involving payments, credentials, or sensitive data) through a separate, pre-established channel, rather than trusting the channel the request arrived on. Conditional Access, strong MFA, and email authentication (DMARC, DKIM, SPF) all reduce the chance a convincing email translates into a successful compromise, even if a person is fooled.
The honest takeaway is that “spot the scam” is no longer a reliable enough strategy on its own. Layered technical controls, plus a verification habit that doesn’t depend on trusting the message itself, is what actually holds up against AI-generated attacks. If you’d like a review of where your current defences stand against this kind of threat, get in touch.