How to Spot AI Phishing Emails That Read Perfectly

TL;DR: AI phishing emails no longer carry the spelling and grammar mistakes businesses were trained to spot. The FBI added AI as a crime category for the first time in 2025, tied to nearly $893 million in losses. The warning signs that still work are in what a message asks you to do. Build one callback habit for money and login requests, and turn on the Microsoft 365 setting most businesses never enabled.

AI phishing emails don’t look like scams anymore. They look like a normal Tuesday.

In July 2025, Ireland’s national debt agency sent 5 million euro to a criminal. The request looked like a routine capital call from a company the fund had already paid, and it arrived exactly when a real payment was due. Six people inside the agency signed off on it at different stages, and as of this spring, half the money still hasn’t come back.

Not one of those six people was careless. They checked the message. They just checked the things they’d been taught to check, and none of those things were wrong anymore.

For twenty years the advice was simple: watch for bad spelling and clumsy grammar. It worked, because many attackers were writing in a language that wasn’t their own. AI erased that tell. The email in your controller’s inbox this morning reads as well as anything your bank sends.

Can you still spot a phishing email by bad spelling?

No. Attackers now use AI to write clean, correct, well-formatted email, so spelling and grammar tell you almost nothing. A message can be flawless and still be fraud. The reliable signal is what the message asks you to do, not how well it’s written.

The UK’s National Cyber Security Centre said this plainly: generative AI lets attackers produce convincing lures without the translation, spelling, and grammar errors that used to give phishing away. Its updated assessment expects that to keep growing through 2027.

The FBI’s numbers back it up. In its 2025 Internet Crime Report, the Bureau added an AI-related category for the first time in the agency’s 25-year history, logging 22,364 complaints and roughly $893 million in losses. The same report puts business email compromise losses above $3 billion, averaging around $123,000 per incident. Those aren’t lottery scams. They’re invoices.

Your team isn’t careless. They were trained to check the wrong thing.

Go back to those six approvers in Ireland. When the agency was questioned in May 2026, a committee member’s summary was that they hadn’t checked properly. The agency’s own answer was closer to the truth: people checked it, and the check wasn’t effective.

That’s the whole problem in one sentence. “Be more careful” is not a security control. If your anti-phishing program is a poster telling staff to look closely, you’ve handed a judgment call to someone processing forty emails before lunch, with no way to tell a real message from a good forgery.

What works is narrower and more boring. You replace one habit with another, and you put something on the system that catches the miss. The habit is a phone call. The catch is layered tooling, which is why security awareness training and advanced email filtering belong together, not as separate line items.

What warning signs still work?

The request itself. Money moving to a new account, a change to bank details, a login or verification code, an unexpected link, and pressure to act fast. AI changed how these messages read. It didn’t change what the criminal needs from you.

The short list worth teaching:

  • It asks you to pay a new account, or to change bank details on an existing one.
  • It asks for a password, a verification code, or personal details.
  • It pushes urgency: a deadline, a threat, or a quiet “keep this between us.”
  • It carries a link or attachment nobody told you was coming.
  • It arrives at a moment when a payment was already expected.

That last one is the sharpest and the least taught. Attackers sitting in a mailbox learn your billing cycle. The Ireland payment landed exactly when a drawdown was due, which is why it sailed through.

The sender address check that stopped working

Most phishing advice still says to hover over the sender and confirm the address matches the display name. Keep doing it, because it catches the cheap attempts. Just don’t treat it as proof.

In the strongest version of this attack, the address matches. Criminals break into your supplier’s mailbox first, read real threads for weeks, then reply inside an existing conversation with new banking details. That’s vendor email compromise, and it’s what happened in Ireland: the investee company’s email had been breached, so the fraudulent request came from a valid address.

No spoofed domain. No lookalike spelling. No link to inspect. Nothing for a filter to flag. If your only defense is examining the message, there is nothing left to examine.

Will your spam filter catch AI phishing emails?

Partly. A good filter blocks the high volume attempts and most malicious links, and you should keep it on. But a well written, personalized message with no bad link, sent from a real mailbox, looks like ordinary business mail to a filter.

There’s one setting worth checking today. In Microsoft 365, external sender identification is off by default. Once an admin enables it with the Set-ExternalInOutlook cmdlet, Outlook adds an “External” tag to mail from outside your organization and shows the real sending address. It takes a day or two to appear and costs nothing.

It won’t stop a compromised supplier. It will instantly expose the “urgent request from your CEO” sent from a Gmail account, still one of the most common versions of this scam. Microsoft’s first contact safety tip, inside your anti-phishing policy, is the same kind of setting and is also off by default.

What should a small business change this month?

Pick a verification rule and make it non-negotiable. Every change to bank details, every new payee, and every unusual payment gets confirmed by phone, on a number you already have on file. That one rule stops the attack that costs the most.

Then work through these:

  1. Retire the spelling advice. Tell your team to slow down when a message involves money, logins, or how you pay someone.
  2. Turn on phishing-resistant MFA or passkeys, so a stolen password is much harder to reuse.
  3. Make reporting a suspicious email easy, and make sure nobody feels foolish for asking.
  4. Ask who owns the check when a request comes from a supplier rather than a colleague.

If you have internal IT, this fits into co-managed IT support, where the process work and the tooling get handled alongside your team.

Where this leaves you

The tell you were taught is gone, and it isn’t coming back. Your staff didn’t get worse at their jobs. The test they were given stopped working.

Two things fix most of it: teach people to react to the request instead of the writing, and put controls underneath them so one bad judgment call doesn’t move money out the door. That’s the core of managed IT services in Louisville and any serious cybersecurity consulting engagement.

Not sure your email settings, payment process, and staff training would hold up against a well-written fake? That’s worth an hour. Schedule an intro call and we’ll walk through it with you.

Frequently Asked Questions

Can you still spot a phishing email by bad spelling and grammar?

Not reliably. Attackers use AI to produce clean, correct email, so perfect writing proves nothing. The NCSC and the FBI have both warned this tell is gone. Judge the message by what it asks of you.

What phishing warning signs still work in 2026?

The request itself. Watch for payments to new accounts, changes to supplier bank details, requests for logins or codes, unexpected attachments, and pressure to act immediately. These don’t depend on how the message reads.

Will my spam filter stop AI-generated phishing?

It stops a lot and should stay on. But a personalized message with no malicious link, sent from a compromised mailbox, looks like normal business mail. A trained person following a verification rule is the backstop.

What is vendor email compromise?

It’s when criminals break into a supplier’s mailbox, read genuine threads, then reply inside them with altered invoices or new banking details. Because the message comes from a legitimate address inside a real conversation, sender checks and filters often miss it.

What should staff do if they aren’t sure about an email?

Slow down and verify through a channel they already trust, such as calling a known number for the sender, never a number supplied in the message. Then report it, even when it turns out to be genuine.

Talk It Through With Someone Who Does This Daily

Most businesses find the gap in their verification process at the worst possible moment. A short conversation now is cheaper than a wire transfer you can’t reverse. Get in touch with Z-JAK and we’ll review how your email security, payment approvals, and staff training fit together.