Phishing is far from new, but threat actors are constantly reimagining this classic tactic. Artificial intelligence (AI) has made that evolution more complicated by helping attackers produce polished, convincing messages faster and at greater scale.
That changes what people should look for. Poor spelling, awkward grammar, and obviously suspicious wording have traditionally made phishing easier to recognize. AI-assisted messages may contain few or none of those familiar tells.
The more useful question, then, is not necessarily whether AI wrote an email. In many cases, a recipient cannot know that with certainty. Instead, users need to pay closer attention to context, behavior, requests, and the actions a message is trying to make them take.
The rise of AI-assisted phishing
According to the Hoxhunt 2026 Phishing Trends Report, phishing emails showing indicators of AI assistance rose sharply at the end of 2025. In samples from Hoxhunt’s global threat-detection network, they represented 4 percent of reported phishing emails in November before reaching 56 percent in December. The figure fell to 40 percent in January 2026 but remained well above earlier levels.
There is an important qualification to those numbers. Hoxhunt’s analysis looks for surface-level indicators suggesting likely AI involvement, including patterns in email content, HTML, and landing pages. It does not prove that every flagged message was entirely generated by AI, nor does it capture every possible way attackers may use AI behind the scenes.
Still, the broader shift matters. Attackers can use generative tools to improve grammar, rewrite messages in different tones, organize publicly available information, and produce more convincing lures with less effort.
Traditional phishing is not disappearing. It is simply becoming easier to polish.
Spearphishing is especially concerning because it attempts to mimic a trusted person or organization. Criminals have long researched potential targets using social media and other public sources. AI can reduce the effort required to turn that information into a plausible message.
The financial consequences remain substantial. The FBI’s 2025 Internet Crime Report recorded 191,561 phishing and spoofing complaints, with reported losses exceeding $215.8 million.
Why familiar phishing tells are becoming less reliable
Old phishing-detection techniques still matter, but users should no longer assume a well-written message is a legitimate one.
A phishing email may have perfect grammar, use a familiar tone, refer to a real project, or resemble a message from a colleague. Generative AI can make these elements easier for attackers to reproduce.
Large language models can also produce drafts in seconds. At scale, that gives threat actors the ability to test many variations of the same lure without relying on the clumsy templates that once made phishing easier to recognize.
This can create a wider trust problem. As fraudulent messages become harder to distinguish from legitimate communications, employees may begin second-guessing routine emails as well. For businesses, that uncertainty can affect productivity, collaboration, and confidence in digital communications.
Phishing can ultimately contribute to financial fraud, identity theft, data breaches, intellectual property theft, data exfiltration, and reputational damage.
The goal is therefore not to become an expert at identifying whether an email was produced by a human or an AI model. It is to become better at recognizing when the circumstances surrounding a message do not make sense.
Ways to identify suspicious phishing emails
AI can make phishing look cleaner, but it cannot eliminate the need for an attacker to persuade the recipient to do something. That action is often where the strongest warning signs remain.
Look for contextual dissonance
The context of a message may now be more revealing than its grammar.
Suppose a manager sends an email late on a weekend asking an employee to sign a vendor contract before Monday morning. The writing might sound exactly like that manager, but the timing, request, or process may be unusual.
That mismatch deserves scrutiny.
An atypical request does not prove the message was generated by AI. It does, however, provide a good reason to verify whether the communication is genuine.
Watch for unusual urgency or emotional manipulation
Urgency has always been common in phishing attacks.
An attacker may claim a payment must be approved immediately, an account will be suspended, or a confidential task must be completed before anyone else becomes involved.
AI can help make this language more natural and emotionally convincing.
A message that appears to come from a close colleague asking someone to buy gift cards for a surprise celebration tomorrow may sound friendly and plausible. The unusual request and compressed timeline are still reasons to stop before acting.
Question highly specific but unexpected requests
Personalization does not automatically make a message trustworthy.
An employee who normally works in graphic design, for example, should question an unexpected request from a manager to download and review a third-quarter financial report.
Attackers may know enough about an organization to include real names, departments, or projects. The relevant question is whether the request makes sense for the recipient’s actual role and normal workflow.
If it does not, confirm it separately.
Inspect links and sender domains
Traditional email analysis remains important.
Hover over hyperlinks before clicking and check the destination carefully. Look for misspelled domains, extra characters, unfamiliar subdomains, or addresses designed to resemble legitimate websites.
Attackers may be able to create a flawless email body, but they still need a mechanism for stealing credentials, delivering malware, collecting information, or redirecting victims.
Never assume error-free writing means a link or attachment is safe.
Verify requests through another channel
One of the simplest protections is also one of the strongest.
Do not use the suspicious message itself to verify whether it is genuine. Instead, contact the supposed sender through a separate, trusted channel.
If an email from a colleague asks for a financial transfer, message that person through the company’s established collaboration platform, call a known phone number, or speak with them directly.
The same principle applies to vendors, financial institutions, and other organizations.
Cross-channel verification makes a convincing email much less useful to an attacker.
The power of skepticism in the AI age
AI is changing phishing, but it does not require employees to become AI forensic specialists.
The most useful defenses remain grounded in behavior and context. Does the request make sense? Is the timing normal? Is the sender asking for something unusual? Does the destination of a link match what the message claims? Can the request be verified independently?
Threat actors will continue refining their methods, and the visual or grammatical quality of phishing emails will likely continue improving.
Users therefore need to read between the lines rather than depend on simple misspellings or obvious formatting mistakes. A polished message can still be malicious.
Healthy skepticism, paired with independent verification, remains one of the strongest defenses against phishing, whether a message was written by a person, generated with AI, or produced using a combination of both.
Zac Amos is the Features Editor at ReHack, where he covers business tech, HR, and cybersecurity. He is also a regular contributor at AllBusiness, TalentCulture, and VentureBeat. For more of his work, follow him on X (Twitter) or LinkedIn.
Editor’s note: This contributed article has been lightly edited for clarity, length, and style. Where appropriate, TNGlobal may verify, qualify or omit factual claims that cannot be independently corroborated. The views and arguments expressed remain those of the author.
Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archive.
Featured image: Kaptured by Kasia on Unsplash

