Recognizing Phishing in the Age of AI-Generated Scams
AI tools have made phishing messages more convincing and personalized than ever, and prompt injection adds an entirely new angle. Here's what's changed, and what still works to defend against it.
How has AI made phishing harder to spot?
AI removes the old tells, spelling errors and generic greetings, and adds fluent writing, social-media-scraped personalization, and even cloned voices or video.
Phishing↗ used to be identifiable by obvious spelling errors and generic greetings. AI tools have changed that, attackers can now generate fluent, personalized, convincing messages at scale, drawing on publicly available social media information to make them feel authentic.
How AI has changed phishing
- Better writing quality. The old advice "look for spelling mistakes" is far less reliable than it used to be.
- Personalization at scale. Information scraped from social media (your employer, job title, recent posts) can be woven into a message automatically, making it feel specifically targeted at you.
- Voice and video cloning. Scams increasingly use AI-generated voice or video to impersonate a real person, a colleague, a family member, an executive, requesting an urgent transfer or action.


What still works as a defense
Despite these changes, the fundamental defense hasn't changed: verify unexpected or urgent requests through a separate, known channel before acting on them. If a message asks you to transfer money, share credentials, or take urgent action, contact the supposed sender directly through a phone number or channel you already know is genuine, not one provided in the suspicious message itself.
Prompt injection↗: phishing aimed at AI, not people
A related, newer risk is prompt injection, where malicious instructions are hidden in content specifically to manipulate an AI system reading it, rather than to trick a human. As AI assistants increasingly process emails and documents on people's behalf, this becomes a phishing-adjacent risk worth understanding even for non-technical users.

Reducing your exposure on social media
Since much of this new personalization draws on public social media information, reviewing your own privacy settings and limiting what's publicly visible (employer, real-time location, family details) directly reduces how convincing a targeted phishing attempt against you can be.
AI hasn't invented a new type of scam, it's made the old ones more convincing. The core defense (verify before you act) remains exactly as effective as it always was.
Frequently Asked Questions
How has AI made phishing harder to spot?
AI removes the old tells, spelling errors and generic greetings, and adds fluent writing, social-media-scraped personalization, and even cloned voices or video.
What's the single best defense against AI-generated phishing?
Verify unexpected or urgent requests through a separate, already-known channel, never one provided in the suspicious message itself, regardless of how convincing the message sounds.