MBX Networks - IT Solutions for a Stronger Tomorrow
Cybersecurity

How to Spot a Scam Email Now That They All Look Real

AI has removed the typos and awkward grammar that used to give phishing away. Here are the warning signs that still work, and how to train your team on them.

Every phishing training for the past two decades taught the same tell: watch for bad spelling and awkward grammar. Legitimate companies proofread; crooks don’t. It was memorable advice, and it genuinely used to work.

Not anymore. Phishing is now drafted by AI, which never misspells anything. The broken English that once flagged a fake is gone, and what lands in your team’s inboxes is polished, businesslike prose, often mimicking the voice of a vendor or colleague your company deals with every week.

Why the old advice stopped working

That grammar tell existed because many attackers weren’t native English speakers, and their messages showed it. Language models erased the difference. The UK’s National Cyber Security Centre has warned that generative AI produces convincing phishing lures free of the translation and grammar mistakes that used to reveal them, and the FBI has issued the same warning: criminals lean on AI precisely to scrub out the errors employees were trained to catch.

Which means the single indicator most of your staff learned to rely on now proves nothing either way.

Why today’s phishing is more convincing

Three things changed at once:

  • Polish is free. Drafting a flawless email in any tone now takes an attacker seconds.
  • Personalization scales. Details scraped from your website, LinkedIn, or a press release get fed into a model that outputs a message with accurate names, titles, and a plausible pretext.
  • Volume exploded. When each message costs nothing, attackers send far more of them. The FBI’s Internet Crime Complaint Center recently gave AI its own section in the agency’s annual report, connecting it to over 22,000 complaints and close to $893 million in losses.

The dangerous email today isn’t “Dear customer, your account is suspended.” It’s a note to your bookkeeper, apparently from a supplier your company genuinely uses, referencing a live project and requesting updated banking details for the next invoice. Nothing about it reads wrong, except that the supplier never wrote it.

Your spam filter won’t catch all of it

Good email filtering catches a great deal, and you should absolutely have it. But a fluent, personalized message posing an ordinary business question, carrying no malicious link or attachment at all, gives a filter very little to object to. Your real backstop is an employee who knows which requests deserve suspicion.

The warning signs that still work

Since the prose no longer betrays anything, evaluate the request instead. AI hasn’t changed these:

  • Money is involved: a payment, gift cards, or a brand-new account number.
  • Credentials are involved: a password, a verification code, personal data.
  • Urgency is manufactured: a deadline, a threat, a “before end of day.”
  • Banking details on an invoice or vendor record “need updating.”
  • An unexpected link or attachment arrives out of context.
  • The sender’s display name checks out, but the actual address behind it doesn’t.

Every one of these is about the request, not the prose. The rule to teach your team: when a message involves money, logins, or how you pay someone, slow down before acting.

What to put in place

  1. Verify money and login requests through another channel. New account number? Changed banking details? Call the person on a number you already have, not one from the email.
  2. Make one firm rule for payment changes: every change to bank details gets confirmed by phone, even urgent ones. Especially urgent ones.
  3. Retire the old training. Stop telling staff to watch for typos; teach them to look at the request.
  4. Turn on phishing-resistant MFA. A stolen password becomes far less useful.
  5. Make reporting easy and judgment-free. Nobody should feel silly for asking “is this real?” A false alarm costs five minutes; a paid invoice to the wrong account does not.

The same shift applies to phone calls, by the way: AI can clone a voice from a short audio clip convincingly enough to leave a voicemail that sounds like your boss. The defense is identical: hang up and call back on a number you already have.


Phishing defense is part of how we run email security and Microsoft 365 for Mid-Michigan businesses, with filtering, MFA, and account monitoring working together, with training that reflects how these attacks actually look in 2026. If you’d like a review of where your email security stands, start a conversation.

Want help putting this into practice?

MBX Networks works with businesses across Mid-Michigan on exactly these kinds of decisions.