How to Spot the Next Generation of Scam Emails

Email Spoofing

For years, spotting a scam email was as simple as looking for bad spelling and grammar. So, if an email was full of mistakes then it was probably a fake. This was easy to teach and for a long time it worked. The issue is that due to AI, scam emails now don’t have these errors. The spelling errors and awkward phrasing that used to give phishing away are now gone and the messages landing in your inbox read as well as anything from a real person and / or company. They can also be written to sound exactly like they came from someone you already know.

Why the old advice is no longer the main telltale sign

The spelling-and-grammar tell worked because the scammers were writing in a language that wasn’t native to them and the mistakes showed. AI took that away as they can now put their message through a prompt and get the “proper” English version. The FBI says the same: cyber criminals now use AI to limit the grammar and spelling errors that used to mark a message as fake. The UK’s National Cyber Security Centre says AI can now create convincing phishing emails “without the translation, spelling and grammatical mistakes that often reveal phishing”. That means the one thing most people were trained to look for no longer tells you much.

Why these emails are now so convincing

  • The writing is correct: A scam email reads like a normal business email, because a machine wrote it in seconds, in whatever tone the attacker asked for.
  • It is personal: Attackers can feed public details about your company into an AI tool, pulled from your website, your team’s LinkedIn profiles or from a press release. They can then tailor a message to you: the right names, the right job titles and create a believable reason to be in touch.
  • There is a lot more of it: AI makes each message faster to produce, so attackers can send a lot more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, due to more than 22,000 complaints and nearly $893 million in reported losses.

These days, the scam email is not the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in your finance team gets a message that looks like it is from a supplier that they really deal with, mentions a real project and even asks to update the bank details for the next invoice. It reads exactly like a real email from the supplier. The only thing wrong is that the supplier never sent it.

It is not just email anymore

AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip, this is enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defence is the same: if a call or voicemail asks for money or login details, hang up and call the person back on a number you already have.

Your spam filter is not 100% foolproof

It’s tempting to assume your email security will handle this. Yes, it can catch a lot of fake emails and you should definitely keep it switched on. But a well-written, personalised email that asks normal-sounding questions don’t always look dangerous to a filter, especially when it carries no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these messages through, this is why the last line of defence is a person who knows what to check.

Here are the signs you should still pay attention to

If you can’t trust how an email is written, look at what it’s asking you to do. That’s where the real warning signs are, and AI hasn’t changed them:

  • The email asks for a login, a verification code or personal details.
  • It creates pressure: a deadline, a threat, or a “do this ASAP.”
  • They ask for money, gift cards or a payment to a new account.
  • They with a link or attachment you were not expecting.
  • It asks you to change the bank details for an invoice or a supplier.
  • The display name looks right, but the actual email address doesn’t match it (look for small changes in letters).

Every one of these is about what the email is asking for. If an email or message is about money, logins or how you pay someone, slow down, think and confirm with the sender before you act.

How to protect your team

Here are some tips on how you can protect yourself and your business:

  • Double check money and login requests another way: If an email asks you to pay a new account or change a supplier’s bank details, call the person on a number you already have. Don’t reply to the email or use a number given in the message.
  • Make one rule for payment changes: confirm every change to bank details by phone, especially when it is urgent.
  • Turn on phishing-resistant MFA or passkeys: This makes things harder even if someone gets tricked and gives away a password.
  • Stop telling staff to just watch for bad spelling or grammar: Tell them to look at what the email is asking for and to slow down when it is about money or logins.
  • Make it easy to report a suspicious email: make sure nobody feels like an idiot for checking.
  • Remind the team now and then that scam emails look perfect these days: A quick five-minute chat beats a poster that nobody reads.

Frequently Asked Questions

Can you still spot a phishing email by bad spelling and grammar?

Not reliably. Attackers use AI to write clean, correct emails, so a message with perfect spelling and grammar can still be a scam. Judge it by what it asks you to do.

What are the warning signs that still work?

The request itself: paying money, changing bank details, sharing a login / code or being pushed to act urgently. Those signs do not depend on how the email reads.

Is AI-generated phishing really more effective?

Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal, plus the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions of dollars in losses. Emails that are cleaner, contain tailored messages get opened and clicked more often.

Will my spam filter stop AI phishing?

It will catch a lot, and you should keep it on. But a well-written, personalised email with no obvious bad link can look legitimate to a filter, so don’t rely on it alone. A trained person is the backstop.

What should staff do if they are not sure about a message?

Slow down and check through a channel they trust, like calling a known number or asking the person directly. Also report it, even if it turns out to be genuine.

If you are an Australian business and need help improving your security or with cyber security training, please contact us here at DP Computing.

Scroll to Top