The advice most people carry — look for bad spelling, be suspicious of odd phrasing — was built for phishing that no longer exists. Here's what's actually changed, and which signals still hold.
What generative AI changed
Poor grammar was never inherently part of phishing. It was an artefact of attackers writing in a second language, and it doubled as a filter: recipients who didn't notice obvious errors were likelier to fall for the rest.
That artefact is gone. Modern phishing is fluent, correctly formatted, and contextually appropriate. Three things followed:
1. Volume with personalisation. Previously, attackers chose between mass generic campaigns and slow, hand-crafted targeted ones. Now a scraped LinkedIn profile produces a personalised message referencing your actual role, colleagues and projects — at scale.
2. Style mimicry. Given a handful of a person's real emails — from a breach, a compromised mailbox, or public correspondence — a model reproduces their tone, sign-off and habits convincingly.
3. Voice and video. Deepfaked voice calls "confirming" an email request have moved from research demo to reported incidents. The callback verification step many businesses relied on now needs a known-good number, not one supplied in the request.
The red flags that still work
Content-based detection is weaker now. Structural signals still hold:
- The actual sending address. Display names are trivially spoofed. On mobile especially, expand the header and read the real address
- Lookalike domains.
tobavarnail.comversustobavamail.com—rnreads asmat a glance. Read domains character by character when money is involved - Hover before clicking. Where does the link actually go? On mobile, long-press to preview
- Unexpected authentication prompts. A login page reached by clicking an emailed link deserves suspicion by default. Navigate there yourself instead
- Urgency plus secrecy. "Do this now, don't discuss it with anyone" is a social-engineering pattern, not a business one
- Any change to payment details. Always, without exception, verified by phone on a number you already had
What actually protects a small team
Verification rules that don't depend on judgment. "Bank detail changes require a phone call to a number already on file" works when someone is tired and busy. "Be careful with suspicious emails" doesn't. See business email compromise for the full set.
MFA on every account. Phishing that captures a password gets far less if a second factor is required — and passkeys defeat credential phishing outright, since the credential won't work on a lookalike domain.
External sender banners. A visible marker on mail from outside your domain makes display-name spoofing obvious immediately.
SPF, DKIM and DMARC at enforcement. These stop attackers spoofing *your exact domain*, which protects your customers and suppliers from messages that appear to come from you. Setup guide here.
A no-blame reporting culture. The worst outcome is someone clicking, realising, and staying silent for six hours out of embarrassment. Early reporting is the difference between an incident and a disaster — so make reporting a mistake explicitly consequence-free, and mean it.
Training that works
Annual slide decks don't change behaviour. What does:
- Short, frequent, specific — five minutes monthly on one real example beats an hour once a year
- Use real attempts your business actually received. Far more effective than generic samples
- Practise the verification call. People hesitate to phone a supplier and ask "did you really send this?" Rehearse it so it feels normal
- Simulations without punishment. Measure improvement, don't name individuals
If someone clicks
- Disconnect the device from the network if credentials or a download were involved
- Change the password immediately, from a different device
- Terminate active sessions on the account
- Check forwarding rules and connected apps — the most commonly missed step
- Tell everyone else what the attempt looked like; the same message is usually sitting in other inboxes
- If money moved, call the bank immediately. Speed determines whether recall is possible
Try Tobava Mail free
Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.
Create your free account