Threats

AI-powered phishing and deepfakes: the new frontier

Phish Plug ResearchMarch 18, 20268 min read

Artificial intelligence has handed attackers a force multiplier. AI-powered phishing produces flawless, personalised lures, clones voices and faces, and does it all at scale. It is the biggest shift in phishing in years — but the defences that work have not changed as much as the fear suggests.

What AI changes

  • Flawless writing — no more tell-tale typos or awkward grammar; lures read like a real colleague wrote them.
  • Scale with personalisation — tailored spear-phishing for thousands of targets at once.
  • Perfect translation — convincing attacks in any language instantly.
  • Deepfakes — cloned voices for vishing and generated video for executive impersonation.

Why "spot the typo" is dead

The classic advice to look for spelling and grammar mistakes assumed attackers couldn't write well. AI erases that tell entirely. Judging an email by how polished it is now tells you almost nothing; a perfect message is no longer a safe message.

AI upgrades the lure, not the logic. The attack still needs you to act on a link, a request or a call — and it still ends at a fake page or a payment. Those are where the defences hold.

What still works

  1. Behaviour over language — judge the request (urgency, unexpected action) not the writing quality.
  2. Phishing-resistant auth — passkeys resist even a flawless lure.
  3. Out-of-band verification — confirm high-value requests and "executive" calls independently, especially against deepfakes.
  4. Email authentication — SPF, DKIM, DMARC still stop exact-domain spoofing however good the text is.
  5. Takedowns — AI writes the email, but the link still points to a fake page you can remove.

No matter how convincing the AI-written lure, it usually leads to a cloned page or lookalike domain — which Phish Plug detects, proves and takes down.

The takeaway

AI makes phishing lures flawless and scalable, retiring the "spot the typo" era. But it improves the bait, not the mechanics: the attack still relies on a risky action and a fake destination. Shift to behaviour-based judgement and phishing-resistant controls, and keep removing the pages the lures point to.

Cut phishing off at the source

Run a free clone check on one domain — Phish Plug finds the clones, proves the cloaking and files the takedown.