AI-generated phishing
In plain terms
The same phishing as before, just without the typos. The tell many people relied on — "it's badly written, so it's fake" — no longer works.
Definition
AI-generated phishing refers to fraudulent messages whose wording, personalization, and adaptation to the recipient are produced automatically, without the underlying mechanism of the attack changing.
How it works
The mechanism is that of phishing, unchanged: imitate a sender, fabricate a reason to act, provide a path that bypasses verification. What changes comes down to three things. Language, first: spelling mistakes and awkward phrasing disappear, even though they used to act as a filter for many readers. Personalization, next: what used to require manual work — using a colleague's name, industry-specific vocabulary, a current project mentioned publicly — becomes automatable at scale. Interaction, last: an exchange can be sustained by replying coherently to objections. None of this creates a new danger; it removes clues, which makes structural checks — the domain, the channel — more important than before.
Warning signs
- Perfectly written message whose sender domain doesn't match
- Exact personalization built from publicly available information
- Request for credentials, payment, or a code, regardless of how polished the language is
- Fast, coherent replies to your objections, while never accepting another channel
- Urgency maintained across several exchanges
How to verify
Shift the check from wording to structure, which hasn't changed: read the domain name, and reach the service concerned through a path you choose. Both are indifferent to how well the message is written, and that's exactly why they still hold.
What to do
Stop using writing quality as a criterion, and say so around you: it's the most common advice, and it has become misleading. Never log in from a link you received, however credible the message looks.
If it already happened
As with any phishing: change the affected password immediately from a session you opened yourself, revoke active sessions, and contact your bank if banking details were entered. Report the message in your mail client.
Frequently asked questions
- How can you recognize a message written by an AI?
- That's the wrong question, and trying to answer it leads to mistakes both ways. A legitimate message can be written with AI, a fraudulent one can be written by hand. What still distinguishes them: the domain, the channel, and the nature of the request.
- So should I be suspicious of every well-written message?
- No: writing quality tells you nothing either way. It has simply dropped off the list of criteria. What remains: the sender's domain, and the fact that a request for credentials or payment is never handled through a link.
Related attacks
Official sources
Also known as: AI phishing, AI-written phishing, automated spear phishing.
This article is part of the AI and synthetic content family. Last updated: 2026-09-03.