AI-powered phishing and deepfakes: the new frontier
Artificial intelligence has handed attackers a force multiplier. AI-powered phishing produces flawless, personalised lures, clones voices and faces, and does it all at scale. It is the biggest shift in phishing in years — but the defences that work have not changed as much as the fear suggests.
What AI changes
- Flawless writing — no more tell-tale typos or awkward grammar; lures read like a real colleague wrote them.
- Scale with personalisation — tailored spear-phishing for thousands of targets at once.
- Perfect translation — convincing attacks in any language instantly.
- Deepfakes — cloned voices for vishing and generated video for executive impersonation.
Why "spot the typo" is dead
The classic advice to look for spelling and grammar mistakes assumed attackers couldn't write well. AI erases that tell entirely. Judging an email by how polished it is now tells you almost nothing; a perfect message is no longer a safe message.
AI upgrades the lure, not the logic. The attack still needs you to act on a link, a request or a call — and it still ends at a fake page or a payment. Those are where the defences hold.
What still works
- Behaviour over language — judge the request (urgency, unexpected action) not the writing quality.
- Phishing-resistant auth — passkeys resist even a flawless lure.
- Out-of-band verification — confirm high-value requests and "executive" calls independently, especially against deepfakes.
- Email authentication — SPF, DKIM, DMARC still stop exact-domain spoofing however good the text is.
- Takedowns — AI writes the email, but the link still points to a fake page you can remove.
No matter how convincing the AI-written lure, it usually leads to a cloned page or lookalike domain — which Phish Plug detects, proves and takes down.
The takeaway
AI makes phishing lures flawless and scalable, retiring the "spot the typo" era. But it improves the bait, not the mechanics: the attack still relies on a risky action and a fake destination. Shift to behaviour-based judgement and phishing-resistant controls, and keep removing the pages the lures point to.
Keep reading
Related articles
How to report a phishing site and actually get it removed
Where to send a phishing report, what each abuse desk needs to see, and the evidence that turns a report into a removal instead of a dead-end ticket.
Read article Cloaking · 9 minMobile cloaking explained: one URL, two realities
How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.
Read article Detection · 7 minTyposquatting vs. homoglyph attacks, explained
Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.
Read articleCut phishing off at the source
Run a free clone check on one domain — Phish Plug finds the clones, proves the cloaking and files the takedown.