What Phishing Looks Like in the Age of AI
A couple of years ago, spotting a phishing email was easy. Bad grammar, a suspicious sender address, a lazy, generic opening you could spot from a mile away. Staff got trained on those red flags every year, and it worked well enough. Then generative AI came along and made all of that obsolete.
The spelling mistakes are gone. The formatting looks professional. And the messages read like they were written by someone who actually knows you, your job title, your projects, even your deadlines. So what happens when the old tells just don’t apply anymore?
The Numbers Haven’t Budged, But the Methods Have
The UK government’s Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced phishing over the past year. Of those affected, 69% said it was the most disruptive type of attack they’d dealt with. And among businesses that reported any breach at all, more than half said phishing was the only attack type involved.
Those numbers have barely moved in years. What’s changed is how the attacks are put together. Generative AI tools can produce convincing, grammatically clean emails in seconds, and they can be tailored to specific industries, job roles, even the way a company talks internally. Mass mailshots haven’t gone away, but they’ve been joined by something far more targeted.
Attackers are scraping LinkedIn profiles and company websites to build messages that mention real projects and real colleagues by name. A finance officer might get what looks like an urgent invoice from a supplier they genuinely work with, timed to land right when a real payment is due. UK cybersecurity firms like Omni Cybersecurity have had to rethink their testing and training services to keep up, because the old “spot the typo” method simply doesn’t work anymore. Thankfully, services like these are now responding to the new threats accordingly and protecting British businesses at a time when it’s never been easier to craft a plausible looking message.
When the Phone Rings and It Sounds Like Your Boss
Email is still the primary channel, but voice phishing has become a genuine problem. AI voice cloning tools can now copy someone’s speech patterns from as little as 30 seconds of recorded audio. Earnings calls, conference talks, podcast appearances, even short LinkedIn videos all give attackers enough material to pull it off.
Help desks and finance teams tend to be the most common targets. An attacker will clone a senior manager’s voice, call the help desk, and walk an employee through a “security update” that actually installs remote access software. Or they’ll phone accounts payable pretending to be a known supplier contact and request a change to payment routing details. These calls don’t sound robotic or off. They sound exactly like the person they’re impersonating.
One widely reported case from early 2025 involved fraudsters cloning a company’s CFO’s voice to authorise wire transfers. The losses hit nearly $12 million before anyone flagged it.
Why “Stay Vigilant” Isn’t Enough Anymore
For years, the go-to advice has been to train staff to spot suspicious messages. That still matters, but when phishing emails look completely legitimate and phone calls sound like real colleagues, you can’t rely on vigilance alone. What actually works is process.
The single most effective defence against payment fraud driven by phishing or voice cloning is a verified callback rule. If anyone requests a change to bank details or a wire transfer, the person handling it should call back on a number they already have on file. Not the number in the email. Not the number the caller gives them. A number that was confirmed independently before any request ever came in.
That one step would stop the majority of these attacks dead. It doesn’t depend on someone recognising a fake. It depends on a process that assumes every request could be a fake until proven otherwise.
Build the Process Before You Need It
AI has made phishing cheaper and harder to catch. The warning signs people trained on for a decade don’t hold up the way they used to. But businesses aren’t helpless here. The defence just has to move away from individual judgement and towards structural controls.
Verified callbacks, dual authorisation for payments, restricted access controls, and regular simulated phishing exercises will do far more to protect a business than any number of “think before you click” posters pinned up in the break room. The attacks have got smarter, and the response needs to catch up.