6 min read
AI-written phishing
The tell that stopped working
For years the easiest way to spot a scam email was to read it. Phishing messages, the fake emails and texts that try to trick you into clicking a link or handing over a password, used to give themselves away: clumsy grammar, odd phrasing, a greeting like "Dear valued costumer". If the writing felt wrong, you deleted it and moved on.
That tell is gone. AI writing tools now produce clean, natural text in any language, including fluent Albanian. The message that once read like a bad translation now reads like it came from a real colleague or a real bank. Grammar is no longer evidence of anything.
What AI changed about the scam
Three things got worse at the same time.
- Fluent. The text is correct and natural. Spelling and tone no longer betray it.
- Personalised. A public profile, a job title, a recent post or a company page is enough for the attacker to reference your role, your manager, or a project you are actually working on. The message feels aimed at you because, in a shallow way, it is.
- Mass-produced. One person can now generate thousands of unique, tailored messages in the time it used to take to write one. Each victim gets a slightly different version, so warnings that describe "the scam email" no longer match what lands in your inbox.
Put together, this means a scam can be both wide and convincing at once, which used to be a trade-off attackers had to make.
Stop proofreading, start verifying
If polish can be faked, then polish cannot be your filter. Shift your attention from how a message is written to what it asks and whether the request makes sense.
Ask yourself:
- Is this pushing me to act fast, quietly, or outside the normal process?
- Does it want money moved, a password entered, a code shared, or bank details changed?
- Would this person normally reach me this way?
A well written message asking you to do something sensitive deserves more suspicion, not less. When the request touches money or credentials, confirm it through a separate, trusted channel, for example by calling a number you already have on file, not one supplied in the message itself.
Warning
A message can be perfectly written and completely fake. Judge the request, not the spelling. Anything urgent about money, passwords or one-time codes should be confirmed on a channel you chose, not the one the message arrived on.
A quick example
You get an email that greets you by name, mentions your manager, and refers to a project your team is genuinely working on. The language is clean and natural, and it asks you to open a shared document by following a link and signing in. Everything about it fits your week.
Under the old rules you would have hunted for a spelling slip or an odd greeting to give it away. There is none: the attacker lifted your role, your manager and the project from public profiles and had AI write a message tailored around them. What should stop you is not the writing but the ask, an unexpected link that wants your login, wrapped in details that only make it feel more legitimate. Before you sign in anywhere, confirm the request on a separate, trusted channel, such as a quick word with your manager on a route you already use.
The lesson is not that every personalised message is a scam. It is that the details which seem to prove a message is genuine are now cheap for an attacker to gather.
Where this lesson comes from
Built from
- Workshop 5: AI Security Tools and Defending Against AI-Enabled Threats (V3.0): AI-powered phishing
- Workshop 7: Social Engineering, Phishing and Deepfakes (V3.0): the evolution of deception
alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement