Artificial intelligence (AI) is an exciting technology that has the power to do things we never thought possible. Its rapid growth in such a short time suggests an even more promising future for technology.
However, as AI improves, its potential for harm in the wrong hands also increases. The National Cyber Security Centre states AI will almost certainly increase the volume of cyber attacks in the next two years
One of those threats is AI-powered phishing emails.
In this blog, weâll take a look at what phishing is, how AI makes it stronger, and how to spot it to avoid potential damage to your business.
What is phishing?
Phishing is a type of cyber-attack where criminals attempt to deceive you into disclosing sensitive details, like passwords, bank details, or any sort of confidential information.
They usually do this by sending fake emails, text messages, or creating fake websites that look legitimate.
Their goal is to get you to click on a malicious link, download an infected attachment, or reveal personal information, so they can then use it for fraudulent purposes.
Read more: Phishing 101: Can you get hacked by opening an email?
How is AI making phishing a bigger problem?
Traditional phishing emails can be easily spotted if you know what to look for. Obvious errors in terms of spelling or grammar usually offer some indication that the email isnât legitimate.
Now, with AI tools like ChatGPT and Google Gemini, these tools are making phishing emails much more sophisticated and harder to distinguish from genuine emails. AI can also increase the volume in which these emails can be sent out, autonomous AI agents can create, send and reply to emails 24/7/365 without any break, unlike a human operator.
AI is being used by cyber criminals to remove any sort of giveaway. Most AI models, like the two already mentioned, can generate highly convincing email copy that doesnât include any errors or areas of suspicion, making it harder to spot phishing emails.
Not only does it fix grammatical errors, but AI can also craft personalised attacks. Publicly available information on a companyâs website, such as a personâs name or job role, gives AI the ability to craft an email that looks believable.
This doesnât mean that you canât have information about your business or your employees on your website; it just means that you need to be aware of potential AI-powered phishing attacks – and not just be aware of them but know how to spot them.Â
The most important thing to remember about phishing is that if you suspect an email isnât genuine, do not click on the links or attachments contained within it.
How to spot AI-powered phishing?
AI-powered phishing emails are harder to spot than traditional phishing attempts, but itâs not impossible! So, how would you spot one?
Check the URL and the domain against the actual company domain is step one. If itâs a sender that you donât recognise, itâs probably worth reporting this to your IT team or whoever is responsible for IT/security.Â
Some domains can be âlookalikeâ domains. They may look like legitimate senders, but often with small changes such as slight misspellings or extra characters, in the hope you’ll just skim over them and not spot the problem. So, it’s really worth taking a moment to double-check every URL or domain for these little slip-ups, because they often get missed.
What if you open an AI phishing email?
If you have accidentally opened an email that you believe is a phishing scam, it is crucial that you donât reply to the email or forward the email to anybody else.
For best practice, follow these three simple steps to ensure youâve made the right decision with the email.
- Report the email using your email providerâs reporting button. In most cases, this will remove it automatically and help protect other users who received the same message.
- Notify your IT team or IT security consultant so they can help prevent others in your organisation from falling victim to the same scam.
- If you clicked a link or opened an attachment, contact your IT team immediately. If you entered your username and password on a linked site, reset your password straight away and, where possible, revoke any active sessions. Many online services allow you to sign out of other logged-in sessions.
It only takes one wrong click to open the door to cyber criminals, so act promptly and calmly.
Read more: Phishing 101: What to do if you click on a phishing link
Is AI-powered phishing a serious threat?
Recent threat intelligence suggests AI is now used in the majority of phishing attacks and is an area of significant concern.Â
AI phishing emails are much more sophisticated and powerful than traditional attempts, and therefore much more likely to compromise your email accounts.Â
A final thought
AI-powered phishing is on the rise, and itâs important to your business that you are aware of the possible threats that come along with this advanced version of phishing.
Stay up to date on the advancements in AI and stay ahead of the cyber-attackers.Â





