If phishing scams are supposed to trick people, why do so many of them still feel clumsy?

In short: the latest phishing is AI-written, personalised and genuinely convincing, so the old advice about spotting a typo no longer protects you. Here is what the new attacks look like and the controls that actually stop them.

Key takeaways

  • Phishing has moved from mass-produced spam to AI-written, personalised messages that read like the real thing.
  • The old advice, spot the typo or the odd greeting, no longer reliably catches them.
  • Attackers now copy writing styles, brands and even voices, and aim at named individuals.
  • The defence shifts from spotting fakes to layered controls: MFA, conditional access, email authentication and tested backups.
  • Train the team on the new reality and verify any unusual money or data request through a second channel.

For years, the answer was simple. Most scams were mass-produced. The same email, the same fake website, sent to thousands of people in the hope a few would fall for it.

That approach is still around, but it is starting to evolve.

The mass-produced era is ending

When generative AI first appeared, there was a lot of talk about “dynamic websites”. Instead of one fixed site for everyone, pages would be generated on the spot, shaped by who you are, where you are and what device you’re using. That future never really arrived for everyday businesses. It was complex and rarely worth the effort.

Cyber criminals, however, do not need perfect systems. They just need something convincing.

What next-gen phishing actually looks like

Security researchers have shown how this idea could be used for phishing. While it’s still largely experimental, it gives a clear picture of where scams are heading.

Imagine a victim clicks a link and lands on a webpage that looks harmless. There is no obvious malicious code sitting on the page. Once it loads, the page asks a legitimate AI service to help generate content. That content is then assembled and run directly in the person’s browser.

The result is a phishing page that has been created especially for that visitor. The wording, layout and code can all be different every time. There is no single fake website for security systems to spot and block, because the scam does not fully exist until someone opens it.

Don’t panic, but pay attention

Before you panic, this method is not widespread yet. But the building blocks are already in use. AI is being used to write malicious code. Malware is increasingly assembled as it runs. AI-assisted scams are becoming more common across the board.

For your business, that changes the rules slightly. Phishing is no longer just about spotting bad spelling or sloppy design. Future scams may look polished, personalised and completely legitimate.

Why the playbook has to shift

That is why modern protection focuses less on “don’t ever click the wrong thing” and more on limiting the damage if someone does. The thinking has shifted from prevention alone to containment. The tools that do the heavy lifting are the ones we’ve been recommending for years:

  • Multi-factor authentication so a stolen password isn’t enough on its own
  • Conditional access policies that question logins from unusual locations or devices
  • Modern email filtering that catches the majority of attempts before they reach an inbox
  • Endpoint protection that watches what’s actually happening on the device, not just what arrives in the inbox

So what should you do about it?

Phishing is not going away. It’s getting smarter. To stay protected now you have to assume the next scam will look professional, and make sure your defences don’t rely on people spotting obvious mistakes.

If you’d like a second pair of eyes on what your business has in place today, book a 30-min IT review and we’ll walk through where the gaps are and the highest-impact moves to close them.