Artificial intelligence (AI) is an exciting technology that has the power to do things we never thought possible. Its rapid growth in such a short time suggests an even more promising future for technology.
However, as AI improves, its potential for harm in the wrong hands also increases. The National Cyber Security Centre states AI will almost certainly increase the volume of cyber attacks in the next two years
One of those threats is AI-powered phishing emails.
In this blog, we’ll take a look at what phishing is, how AI makes it stronger, and how to spot it to avoid potential damage to your business.
What is phishing?
Phishing is a type of cyberattack where criminals attempt to deceive you into disclosing sensitive information, like passwords, bank details, or any sort of confidential information.
They usually do this by sending fake emails, text messages, or creating fake websites that look legitimate.
Their goal is to get you to click on a malicious link, download an infected attachment, or reveal personal information, so they can then use it for fraudulent purposes.
Read more: Phishing 101: Can you get hacked by opening an email?
How is AI making phishing emails harder to spot?
Traditional phishing emails can be easily spotted if you know what to look for. Obvious errors in terms of spelling or grammar usually offer some indication that the email isn’t legitimate.
Now, with AI tools like ChatGPT and Google Gemini, these tools are making phishing emails much more sophisticated and harder to distinguish from genuine emails.
AI is being used by cyber criminals to remove any sort of giveaway. Most AI models, like the two already mentioned, can generate highly convincing email copy that doesn’t include any errors or areas of suspicion, making it harder to spot phishing emails.
Not only does it fix grammatical errors, but AI can also craft personalised attacks. Publicly available information on a company’s website, such as a person’s name or job role, gives AI the ability to craft an email that looks believable.
This doesn’t mean that you can’t have information about your business or your employees on your website; it just means that you need to be aware of potential AI-powered phishing attacks – and not just be aware of them, but know how to spot them.
The most important thing to remember about phishing is that if you suspect an email isn’t genuine, do not click on the links or attachments contained within it.
How to spot AI-powered phishing?
AI-powered phishing emails are harder to spot than traditional phishing attempts, but it’s not impossible!. So, how would you spot one?
Check the URL and the domain against the actual company domain is step one. If it’s a sender that you don’t recognise, it’s probably worth reporting that to your IT department, or if you don’t have one, your IT security consultants.
Some domains can be ‘lookalike’ domains. They may look like legitimate senders, but often with small changes such as slight misspellings or extra characters, in the hope you’ll just skim over them and not spot the problem.
So, it’s really worth taking a moment to double-check every URL or domain for these little slip-ups, because they often get missed.
AI checkers are your best friend in this situation. There are plenty of tools that allow you to run a quick search of the email and tell you the likelihood that it’s AI-generated. If it comes back positive, then it’s worth flagging the email.
What if you open an AI phishing email?
If you have accidentally opened an email that you believe is a phishing scam, it is crucial that you don’t reply to the email or you don’t forward the email to anybody else.
For best practice, follow these three simple steps to ensure you’ve made the right decision with the email.
- Flag the email as junk or spam instead of just deleting it. This will help your email provider better identify future phishing attempts.
- Scan your computer for viruses, malware, and ransomware. Refrain from online shopping or banking until your system is clean, as cyber criminals can access your bank information. If you’re unsure how to proceed, your IT department can assist.
- Contact your IT department or IT security consultant to prevent other members of your organisation from falling victim to the same scam.
It only takes one wrong click to land you in hot water, so act promptly and calmly.
Read more: Phishing 101: What to do if you click on a phishing link
Is AI-powered phishing a serious threat?
At the moment, regular phishing emails still dominate the majority of attacks, meaning the current areas of suspicion, like grammatical errors, are what to look out for.
However, with the rapid development of AI in the past couple of years, it’s likely that AI phishing will become the new norm.
While not yet widespread, AI phishing is already a significant concern. The FBI warns Gmail users of sophisticated AI-driven phishing attacks, describing them as the most sophisticated ever.
Not as dominant as phishing emails just yet, but much more powerful than traditional attempts, and much more likely to compromise your email accounts.
A final thought
AI-powered phishing is on the rise, and it’s important to your business that you are aware of the possible threats that come along with this advanced version of phishing.
Stay up to date on the advancements in AI, and how it works, and use the above examples to spot illegitimate emails crafted with AI.
Stay aware and stay ahead.





