For years, the advice for spotting a scam email was easy: watch for typos and clunky sentences. If it read badly, it was probably fake.
Unfortunately, that advice doesn’t hold up anymore.
Scammers are using AI to write their emails now, and the messages showing up in your team’s inbox read exactly like something from a real company, because a lot of the time, a machine wrote it by modeling real emails.
Why the Old Trick Stopped Working
The old advice worked because a lot of scammers were writing in a language that wasn’t their own, and it showed. AI eliminated that problem.
The FBI has said generative AI can now produce convincing phishing emails without the translation, spelling, and grammar mistakes that used to give it away.
It’s not just the writing that’s better. Scammers can pull public information about your company (from your website, your team’s LinkedIn profiles, a press release) and feed it into an AI tool. What comes back has the right names, the right titles, and a reason to be in touch that actually makes sense.
What Email Scams Look Like in Real Life
Here’s the subtle but sneaky shift: instead of “Dear Customer, your account is suspended,” someone on your finance team may get an email that looks like it’s from a supplier they work with all the time. It might reference a real project and ask to update the bank details before the next invoice goes out.
It reads exactly like a normal supplier email. The only thing wrong with it is that the supplier never sent it.
Your spam filter is still doing its job, but a well-written, personalized message with no obvious bad link doesn’t always trigger a flag the way an old-school scam email did.
How to Actually Protect Your Team
Judge the ask, not the writing. Good grammar doesn’t mean a request is legitimate anymore. If an email is asking for money, login credentials, or a change to bank details, slow down.
Verify bank detail changes by phone, every time. Use a number you already have on file, not one in the email. Do this even when the request feels urgent – especially when it feels urgent!
Retrain what “suspicious” means. Stop telling your team to hunt for typos. Teach them to pause on anything involving money, credentials, or urgency, no matter how polished it looks.
Turn on phishing-resistant MFA or passkeys. If a password does get stolen, this makes it a lot harder for anyone to actually use it.
Make reporting easy and judgment-free. If someone has to feel silly to report a weird email, they’ll stop reporting weird emails. Build a process where flagging something is just normal and encouraged.
A Few Things Worth Adding
This isn’t only an email problem anymore. The same AI tools behind cleaner phishing emails are also behind voice cloning and deepfake video. If someone gets a call that sounds exactly like your CEO asking for an urgent bank transfer, the same rule applies: verify through a separate, known channel before moving forward.
This is called Business Email Compromise (BEC), and it’s expensive. The FBI’s Internet Crime Complaint Center has tracked BEC losses in the billions annually, and invoice and payment redirection scams like the supplier example above are one of the most common versions.
One verified process beats a hundred suspicious emails caught. You don’t need every employee to become a threat detective. You need one non-negotiable rule: no bank detail changes, no wire transfers, and no credential resets happen without a callback to a known number first.
What Still Gives a Scam Away
Even with AI in the mix, a few things haven’t changed:
- It’s asking for money, gift cards, or payment to a new account
- It’s asking for a login, a verification code, or personal details
- It’s pushing you with a deadline, a threat, or a “do this right now”
- The display name looks right, but the actual email address doesn’t match
The writing got better, but the tells didn’t disappear; they just moved from the sentence to the ask.