AI & Cybersecurity

How to Spot an AI-Written Phishing Email

Arpit TripathiArpit TripathiLinkedIn·September 21, 2026·11 min read

AI erased the typos that used to flag phishing. Here is what a small business owner can actually still check for.

For years, the standard advice for spotting a phishing email was to look for typos, clumsy phrasing, and grammar that read like it came from a non-native speaker translating on the fly. That advice is not just outdated now, it is actively counterproductive. AI writing tools produce fluent, professional, error-free text by default, at no extra effort to whoever is sending the message, which means the one signal small business owners were trained to look for is the one signal that no longer separates a scam from a real email.

The Old Advice Doesn't Work Anymore, and Security Researchers Know It

The clearest evidence that this shift is real does not come from a vendor blog trying to sell software. It comes from a footnote in Verizon's 2026 Data Breach Investigations Report, the 19th edition of an annual study that examined more than 31,000 real-world security incidents and over 22,000 confirmed data breaches across 145 countries, the largest dataset the report has ever analyzed. Explaining a change to its own methodology, the report states plainly: "Given the reported increase of AI assistance in phishing emails, we are changing the detection guidance from 'does it contain many typos' to 'does it contain em dashes.'" The line is written with a wink, but the underlying point is not a joke. The report also notes that AI-assisted text in malicious emails had already doubled compared to prior years, a trend this year's edition describes as continuing.

The same report quantifies how much AI is now involved on the attacker's side generally, drawing on data covering hundreds of tracked threat actors. In the median case, an actor sought AI assistance for around 15 distinct attack techniques, and in extreme cases, actors queried for as many as 40 or 50. Phishing was the largest single category, accounting for 44% of the initial access techniques where AI assistance was documented. Social Engineering as a category, which includes phishing and the related tactic of pretexting, was the third most common breach pattern overall in the report, present in 16% of all confirmed breaches, and the human element, someone clicking, replying, or approving something they shouldn't have, was present in 62% of all breaches this year, up slightly from 60% the year before.

Why the Grammar Tell Disappeared

The mechanics behind this shift are not complicated, and understanding them does not require any technical detail an attacker doesn't already have. A phishing email used to be written, in many cases, by someone working in a second or third language, translating a script by hand or with a basic tool, which is exactly why odd phrasing and grammatical slips used to be a reliable giveaway. A general-purpose AI writing tool removes that constraint entirely. It can produce fluent business English, matched to a specific tone, a specific level of formality, or a specific company's typical style, as easily as it produces any other text. None of that requires any special skill or paid tooling most people don't already have access to. The result is not that phishing got harder to write. It is that the easiest tell got erased, for free, for every attacker, regardless of their own writing ability.

What the Numbers Say This Is Actually Costing People

The FBI's Internet Crime Complaint Center, which marked its 25th anniversary in 2025, received 1,008,597 complaints that year and recorded $20.877 billion in reported losses, a 26% increase over 2024 and the first time IC3's annual losses have surpassed the $20 billion mark. Phishing and spoofing was the single most-reported crime type by complaint count, with 191,561 complaints and $215,843,126 in reported losses. IC3 separately tracked complaints where AI played a documented role: more than 22,000 of them, totaling over $893 million in adjusted losses. Within that AI-linked category, the report specifically flags business email compromise, the scam where an attacker impersonates a company executive or vendor to request a wire transfer, noting that in 2025 businesses reported losses exceeding $30 million to BEC scams that involved AI.

IC3's own description of how this plays out in practice matches what Verizon's data shows from the defender's side: "Chat generators can quickly create official-sounding emails mimicking a company's CEO or other officials. These emails can contain phishing links or directions to wire funds." That is the whole mechanism in one sentence, and it explains why a small business without a dedicated security team is a realistic target. A convincing, well-written email asking someone in accounts payable to process an urgent wire transfer does not need to fool a security analyst. It needs to fool whoever happens to open it on a busy Tuesday.

A Real Example: AI Doing More Than Writing the Email

Anthropic's September 2026 threat intelligence report, which discloses misuse cases the company detected and disrupted on its own Claude models, describes a Russian-linked operation, tracked as GTG-20006, that used AI assistance for more than just drafting messages. Over an eight-month window between December 2025 and August 2026, the operators used AI-driven workflows to research targets, register phishing domains, and configure the hosting infrastructure behind their campaigns, then ran device code phishing that abused legitimate cloud email sign-in flows against more than 20 organizations, mostly government ministries, defense bodies, and diplomatic missions concentrated in Ukraine and Europe. Anthropic states it detected and disrupted the operation rather than let it continue. The target list here is government and defense, not small business, but the underlying pattern, AI doing the infrastructure work as well as the writing, is the same one showing up in the broader IC3 and Verizon numbers at a much larger scale.

A nation-state operation with a dedicated infrastructure team is not the threat model most small businesses need to plan around, but the tooling gap between that kind of operation and a much smaller scam has narrowed. The same IC3 report frames the underlying dynamic plainly: "AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes against individuals, businesses, and financial institutions." The specific techniques described in the Anthropic report, registering domains, configuring hosting, and writing convincing messages, do not require nation-state resources to attempt at a smaller scale. That is the actual reason a solo employee without a security team is a realistic target today in a way that would have required a more skilled attacker five years ago.

What Actually Still Signals Phishing

None of this means phishing became undetectable. It means the useful signals moved away from the writing quality and toward the structure of the request itself, which AI fluency does nothing to disguise.

  • Urgency and pressure. A request that has to happen right now, before you can check with anyone, before the end of the day, before an account gets suspended, is designed to stop you from pausing to verify. This tactic predates AI and still works precisely because it targets a decision, not a sentence.
  • A sender domain that doesn't match the display name. A message can say "Your Bank" or a real colleague's name in the display field while the actual sending address is a domain you don't recognize. Checking the real address, not just the name shown, still catches this regardless of how well the message reads.
  • A request to act outside your normal channel. Being asked to click a link instead of logging in directly, to verify a payment by replying to the email instead of calling a known number, or to wire funds based on a message alone rather than a process your business already uses, is the actual mechanic of the scam. Fluent writing does not change what is being asked of you.
  • A request that skips your normal approval step. If a payment, a password reset, or a data request would normally need a second person's sign-off, and this message is arriving in a way designed to skip that, that alone is worth treating as a flag before the content of the email is even considered.
  • Overly polished formality from someone who doesn't usually write that way. This one is softer and more subjective than the others, but a message that sounds unusually formal or generic for the specific person it claims to be from is still worth a second look, even though it is no longer proof of anything on its own.
SignalOld Advice (Pre-AI)What Actually Works Now
Grammar and spellingTypos and awkward phrasing were the reliable giveawayAI text is fluent and error-free by default; this signal alone no longer separates a scam from a real email
Urgency or pressureRushed deadlines and threats of account suspension were a known red flagStill one of the most reliable tells. AI can write in any tone, but a request designed to stop you from pausing is unchanged
Sender domainA misspelled or obviously fake domain was easy to spotStill works. Verify the actual sending address, not the display name, regardless of how professional the message reads
The channel of the requestA suspicious link or attachment in an unexpected email was the warning signStill the core mechanic. A request to click, verify, or pay outside your normal process is the constant, no matter how it's written

Verifying Through a Separate Channel, Without a Security Team

The single most reliable habit available to a solo employee or a small business owner is also the simplest one: when a message asks for something unusual, money, credentials, sensitive data, verify it through a channel other than the one the message arrived on. If an email claims to be from a vendor asking for updated payment details, call the vendor back using a phone number pulled from a past invoice or your own records, not one included in the email itself. If a message claims to be from a colleague or an executive, a quick message through a separate app or a phone call settles it in under a minute. This habit costs nothing, requires no technical knowledge, and works exactly as well against a fluent, AI-polished email as it does against a clumsy one, because it never depends on judging the writing at all.

The other habit worth building is simply knowing, ahead of time, who your business actually talks to and how those conversations usually go. A request from a vendor you've worked with for two years that suddenly changes their bank details, or a message from an executive whose past emails never mention that particular project, stands out more easily when you have something to compare it against. That is a harder habit to keep consistently in your head alone, especially across every vendor, client, and contact a small business deals with over time.

This is the specific gap a private, running memory layer like MemX is built to help with: a place to keep your own notes on known-legitimate senders, past correspondence patterns, and the vendors and contacts your business actually deals with, searchable across whatever combination of ChatGPT, Claude, and Gemini you already use day to day. It doesn't screen your inbox or claim to catch a scam automatically. It just makes the comparison easier when something looks slightly off, kept private by architecture rather than sitting inside the same account an attacker might already be trying to compromise.

Pro Tip

If a message pressures you to act immediately and skip your normal process, that combination alone is worth a pause, regardless of how well written it is. Verify through a phone number or contact method you already had on file before the message arrived, never one the message itself provides.

Frequently Asked Questions
01Can I still spot phishing emails by looking for typos and bad grammar?

No, not reliably. AI writing tools now let attackers produce fluent, error-free text by default. Verizon's 2026 Data Breach Investigations Report explicitly describes shifting its own detection guidance away from typos for this reason.

02What actually still signals a phishing email now that AI writes fluently?

Urgency and pressure to act immediately, a sender domain that doesn't match the display name, a request to click, verify, or pay outside your normal channel, and a request that skips a normal approval step are all still reliable, because they describe the structure of the request rather than the quality of the writing.

03How much has AI actually increased phishing losses?

The FBI's IC3 recorded more than 22,000 complaints in 2025 involving a documented AI role, totaling over $893 million in losses, and flagged more than $30 million in business email compromise losses specifically tied to AI-generated messages.

04What is business email compromise and how does AI make it worse?

Business email compromise is a scam where an attacker impersonates a company executive or vendor to request a wire transfer or sensitive information. AI lets attackers quickly generate official-sounding emails that convincingly mimic a real executive's tone without needing strong writing skills themselves.

05What is the single best habit for a small business without a security team?

Verify any unusual request for money, credentials, or sensitive data through a separate channel, using a phone number or contact method you already had on file, never one supplied by the suspicious message itself.

Was this article helpful?

Found this useful? Share it with someone who needs it.

Free · iOS, Android & WhatsApp

Stop losing what you save.
Let MemX remember it for you.

Every screenshot, photo, PDF and voice note — captured, encrypted, and instantly searchable. Ask in plain English, get the answer in seconds.

  • Reads text inside images and handwriting
  • Private and encrypted by default
  • Free to start, no credit card

Takes under a minute to set up. Your data stays yours.

Arpit Tripathi
Written by
Arpit TripathiLinkedIn

Founder of MemX. Ex-Google Staff Tech Lead Manager, ex-AWS Senior SDE (Elastic Block Store). Writes about practical AI on the MemX blog.

Keep reading

More guides for AI-powered students.