Blog/Phishing

AI-Written Phishing: What Has Changed

AI lets attackers write fluent, personalised phishing in any language. What has changed, what has not, and the checks that still catch AI-written phishing.

CyberWatch AI1 October 2026 · 2 min read
A cluttered desk with a computer, notes and a person typing

For years, the advice was to look for spelling mistakes and awkward grammar. AI writing tools have made that advice much less useful. Attackers can now produce fluent, polite, personalised messages in any language within seconds. Here is what has changed, and what still works.

What AI changes

BeforeWith AI
Clumsy grammar and spellingFluent, natural language
Generic "Dear Customer"Personalised with your name, role and context
Mostly EnglishAny language, including local phrasing
One template for allMany variations that dodge filters
Slow repliesInstant, convincing conversations. See AI chatbot scams

What has not changed

The message still has to get you to do something: sign in on a fake page, pay, share a code, call a number or open a file. That request is where you catch it.

Checks that still work

  1. Was I expecting this?
  2. Where does the link really go? See how to read a URL.
  3. Who really sent it? See checking the sender's real address.
  4. Can I verify it another way? Open the app or call a known number.

Technology helps where eyes cannot. Password managers refuse to fill passwords on fake sites, and passkeys cannot be phished at all. See passkeys vs phishing.

Received a polished message you are unsure about? Paste it into CyberWatch AI Scan for a free check.

For more, read our complete guide to phishing.

Frequently asked questions

Can I still spot phishing by spelling mistakes?

Less and less. AI tools produce fluent text, so good spelling and grammar no longer suggest a message is genuine.

Is AI phishing harder to stop?

It is more convincing to read, but the request is the same: click, sign in, pay, share a code or open a file. Checks based on the request still work.

Do AI detection tools help?

Tools can help flag suspicious messages, but verification habits and phishing-resistant sign-in remain the strongest defences.

Sources

  1. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
  2. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  3. Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.