Watch for Typos and Bad Grammar. (And Other Phishing Advice That’s Now Wrong.)
Watch for typos and bad grammar — that's outdated advice. AI-generated phishing has changed the rules. What your security training needs to teach now.

AI-generated phishing has rewritten the rules. If your security training was written before 2024, it’s teaching your people to spot the wrong things.
In January 2024, a finance employee at the engineering firm Arup joined a video call with his CFO and several other colleagues. The CFO, based in the UK, asked him to process a series of confidential transactions. The colleagues on the call confirmed the request. Over the course of 15 transfers, the employee sent the equivalent of $25.6 million to five Hong Kong bank accounts. Read All About It.
Every person on that video call was a deepfake. The CFO. The colleagues. All of them, AI-generated reconstructions built from publicly available video and audio of the real people. The employee only realized something was wrong when he checked in with Arup’s actual UK headquarters days later.
This isn’t a science fiction scenario. It happened. The investigation is still ongoing as of late 2025. And it’s not even unique anymore. The same year, scammers used a deepfake WhatsApp account to impersonate the CEO of advertising giant WPP. Software company Retool was breached after attackers used a deepfake voice impersonating an internal IT staffer to extract a multi-factor authentication code from an employee. The downstream cryptocurrency theft from that single breach totaled $15 million.
If your company’s security awareness training is still telling employees to “watch for spelling and grammar errors” and “be wary of generic greetings,” it’s teaching them to spot a category of attack that’s rapidly disappearing.
What changed
Until about two years ago, phishing emails had a recognizable signature. Awkward English. Misspellings. Generic openers like “Dear Customer.” Suspicious-looking sender domains. Threats that felt slightly off in a way you couldn’t quite name. Most security awareness training built its red-flag checklist around exactly these markers. The training worked because most attackers couldn’t do much better.
Generative AI has demolished that floor. Today, anyone with a $20-a-month ChatGPT subscription can produce a phishing email indistinguishable from internal corporate correspondence. Specialized criminal tools like WormGPT and FraudGPT (LLMs marketed specifically for cybercrime, with the safety filters removed) can generate thousands of personalized variants in seconds. Voice cloning that used to require ten minutes of audio and a recording studio now needs three seconds of audio off LinkedIn and works in real time.
The numbers tell the story. A 2024 academic study sent four types of phishing emails to 101 participants. The control group of generic scam emails got a 12% click-through rate. Emails written by human security experts got 54%. Fully AI-generated emails, with reconnaissance scraped automatically from each target’s online footprint, also got 54%. The AI emails matched the experts and cost roughly 95% less to produce. Cost per phishing campaign that used to run $50,000 now runs under $5.
More broadly, an estimated 82% of phishing emails detected in 2025 showed signs of AI generation. AI-driven attacks have caused a roughly 1,200% surge in phishing attempts year-over-year. Business email compromise (the category Arup fell victim to) is up 1,760% and now represents nearly 19% of all cyberattacks.
The training advice that’s now wrong
Most security awareness training was written for a threat landscape that no longer exists. Specific things your team has probably been taught that are now actively misleading.
“Watch for spelling and grammar errors.” AI-generated phishing emails are grammatically perfect. They’re also tonally appropriate, written in the voice of the company being impersonated, and free of the awkward phrasing that gave older phishing attempts away. Telling employees to look for typos in 2026 is teaching them to relax when they don’t see any. The absence of typos has become a false reassurance.
“Watch for generic greetings like ‘Dear Customer.’” AI scrapes LinkedIn, company websites, and public databases automatically. The phishing email that lands in your CFO’s inbox now opens with their first name, references a project they actually worked on last quarter, and signs off with the name of someone they actually know. Generic greetings are gone.
“Watch for urgent or pressuring language.” Urgency is still a useful flag, but the urgency has gotten plausible. AI generates pressure that fits the business context. “Can you push this through before the board call at 3?” from a CFO’s name, on a day there actually is a board call, with internal acronyms and project codes the AI scraped from public sources. The pressure feels appropriate because the AI knows enough to make it appropriate.
“Check the sender’s email address.” Lookalike domains have always been a problem. AI just makes them more effective. The phishing email comes from finance@your-company.co (note the .co instead of .com) and the body is so well-written that the employee never thinks to scroll back up and check the address. Combined with display-name spoofing, where the email shows up in Outlook as just “Michael Thompson” and the actual address is hidden by default, this red flag fails for most employees.
“Hover over links to check the URL.” AI-generated phishing increasingly skips the link entirely. The new attack pattern is conversational. An email asks the employee to confirm something, gets a reply, and the conversation continues for several rounds before any malicious action is requested. By the time the request comes, the employee is already deep in a conversation that feels real. There may not be a link to check.
“Call the person to verify.” The advice that used to be the gold standard is the one that’s broken hardest. Voice cloning works in real time. The employee calls the number that’s in their address book, the number is forwarded, and the voice that answers sounds exactly like the person they expect. The Retool breach used this exact pattern. The Arup deepfake video call did the same thing, just visually. Calling no longer reliably proves anything.
What employees actually need to know now
If the old red flags are unreliable, what should training cover instead? The new advice looks like this.
Trust the process, not the message. Any request involving money movement, credential changes, system access, or sensitive data needs to follow a defined process regardless of how legitimate the request looks or sounds. Wire transfers above a threshold require dual approval. New vendor banking details get verified through a previously established channel. MFA codes never get shared, period, even with someone whose voice matches a colleague’s exactly. The process exists specifically so an individual employee’s judgment isn’t the last line of defense when the attack is good enough to fool them.
Use a separate channel for verification. If a request comes in via email, verify it via Slack or Teams or a known-good phone number. If it comes in via voice, verify in writing. Never use the same channel the request arrived in. Attackers who control one channel often don’t control a second one. The Arup employee verified the email request via the video call, which the attackers also controlled. The verification has to happen on a channel the attackers haven’t touched.
Watch for context that doesn’t fit. AI is good at the words. It’s less good at deeper context. A CFO who never asks for confidential transactions suddenly asking for one. A request that bypasses normal procurement. A demand for secrecy. An unusual time or day. The story not quite matching what you know is happening at the company. None of these are conclusive on their own, but together they’re the new red flags.
Pre-shared verification phrases for high-value actions. Some companies are now establishing a code phrase or shared secret used to verify high-stakes requests. “What’s our cricket score?” between two specific people, with an answer that means “this is real,” and a different answer that means “I’m being coerced.” It feels old-school. It also works against deepfakes.
Slow down on anything that pressures you to move fast. The most reliable signal across both old and new phishing is artificial urgency. AI just makes the urgency more plausible. The countermeasure hasn’t changed: any request that pressures you to act before you can verify deserves more scrutiny, not less. The longer the conversation feels rushed, the more likely it’s an attack.
Why annual training doesn’t address this
All of the above is current as of early 2026. By the end of the year, the playbook will have moved again. Real-time deepfake video calls are improving, agentic AI is starting to run multi-step social engineering autonomously, and the cost barrier for attackers keeps dropping. The pattern of attack two years from now will look different from what we’re describing today.
Annual training, even good annual training, can’t keep pace with this. A training module produced in early 2024 talked about voice cloning as an emerging threat. By late 2025, voice cloning was responsible for $5 million in losses just from the “distress call” variant alone. Training content written in 2023 is teaching people to recognize attacks the attackers have already moved on from.
If your platform claims a thousand-module library and the modules haven’t been refreshed since 2023, you’re paying for content that’s teaching your team to spot last generation’s attacks. That problem accelerates. The gap between what training covers and what attackers are doing widens with every quarter.
This is exactly why ClickCerts is built around a quarterly release cadence with annual content refreshes. New modules every quarter to address what attackers are actually doing now. Existing modules updated annually to drop outdated advice and add what’s current. Four certificate-awarding courses per user per year, each one a real training module followed by a quiz, with a verifiable certificate issued on completion. The whole point of the cadence is to keep your team’s training synchronized with the threat landscape, not frozen at the day they were hired.
+++++
The old phishing red flags worked when most attackers couldn’t produce convincing English, couldn’t scrape personal context at scale, and couldn’t clone a voice in real time. None of those things are true anymore. Training that’s still drilling typos and generic greetings is teaching your people to look for things that don’t exist in the attacks they’ll actually face.
The shift is simple to describe and uncomfortable to internalize. Verification has moved from “does this message look real” to “am I following the process that protects me when the message looks real but isn’t.” Trust the process. Verify on a different channel. Watch for context that doesn’t fit. Slow down when something feels urgent. Update the training as the threats update. The companies whose people get this right are the ones whose training keeps pace. The companies whose people don’t are the next Arup.
Email sales@clickcerts.com to see how a quarterly-refresh training program looks in practice, or read our deeper post on “You Don’t Need 1,000 Training Modules. You Need Your Team Trained.” for more on why simpler beats bloated. Related reading: “60% of Breaches Start with a Click. Here’s How to Stop Yours.” for the underlying threat data behind why training matters.



