Security News

Generative AI Is Making Phishing Emails Harder to Spot, and Old Warning Signs Are Fading

The Register · 9 Oct 2026
Key Takeaway Do not rely on spotting bad spelling or odd formatting to catch phishing; train staff to verify unexpected requests through a separate, trusted channel and review your email security tools accordingly.

Phishing emails have been used to steal information and deliver malware since the mid-1990s, and they remain a favourite tool for criminals posing as trusted people or organisations. According to the latest figures from the US Federal Bureau of Investigation (FBI), about 26 percent of all cybercrime complaints filed with it are now phishing-related, and use of the technique is rising.

The article, a sponsored feature in The Register, argues that generative AI is changing the picture. Attackers once had to choose between carefully targeted "spear phishing", which takes a lot of effort, and mass campaigns that lacked finesse. Large language models can now produce polished, contextual text in any language, along with realistic brand graphics and convincing web addresses. That lets attackers send thousands of tailored messages with little expertise and at low cost.

This undermines the traditional clues many people rely on. Dave Baggett, SVP Cybersecurity at software developer Kaseya, notes that poor grammar and misspelt words, long the telltale signs of a scam, are now "ironed out and replaced with perfect language". He adds that AI can help craft emails using authentic industry terminology to target a specific sector, such as a pharmaceutical company. The result is a more difficult environment for defenders, and email security is at a tricky turning point.

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.