AI Killed the Typo Time to Rewrite Phishing Training
AI Killed the Typo: Time to Rewrite Phishing Training
Source: SC Magazine
Date Published: August 31, 2026
“Look for spelling mistakes and bad grammar.” For years, that was one of the defining pieces of advice for spotting phishing attempts. Today, anyone can use generative AI to create polished, personalized phishing emails in seconds, rendering that advice increasingly irrelevant. The generic, blasted-out email is being replaced by one that’s well-written and appears crafted specifically for its recipient, referencing their employer, a recent purchase, or even a coworker’s name.
The problem isn’t simply that phishing emails are getting better. It’s that many techniques employees have been taught to identify phishing are becoming less reliable in the AI era. Generative AI allows attackers to create phishing emails with flawless grammar, localized language, and personalized messaging in seconds, reducing the skill and effort required to execute convincing attacks. 🚀
Recent Barracuda research found that 90% of high-volume phishing campaigns use phishing-as-a-service kits, making sophisticated phishing campaigns easier to launch and scale. PhaaS has done for phishing what SaaS did for business software. Instead of building phishing infrastructure themselves, attackers subscribe to ready-made kits that include templates, fake login pages, hosting, and automation, enabling even relatively inexperienced attackers to launch sophisticated campaigns. AI improves quality, while PhaaS improves scale. Together, they have changed the economics of phishing in favor of attackers. Now consider the force multiplier effect of AI and PhaaS: more attacks, sent faster, at a barrier to entry near zero, against the same number of defenders.
Generative AI has shifted phishing from a language problem to a decision-making problem. Organizations need to shift security awareness training from evaluating how an email is written to evaluating what it asks an employee to do, because the social engineering techniques phishing relies on persist in the AI era. Organizations should train employees to recognize:
- Urgency designed to bypass normal processes;
- Requests that break established business workflows;
- Pressure to stay within the attacker’s communication channel.
This shift also has implications for phishing simulations. Simulations should reflect today’s threat landscape by testing employees against attacks they are likely to encounter.
Perhaps the most important habit organizations can teach is to independently verify unusual or high-risk requests through a trusted channel. If an email appears to come from HR, finance, or IT and requests an unusual action, employees should confirm it using a different known contact method, not by replying to the message itself. For instance, taking a minute to call their manager exposes the scam. The phishing message may be flawless, but the verification process breaks the attack.
The goal isn’t to eliminate every click. It’s to build a security culture where employees pause before acting, confirm unusual requests through trusted channels, and know what to do when something doesn’t feel right. The organizations that successfully manage phishing risk will build security habits that remain effective even when the malicious email looks perfect.