Phishing Awareness

🤖 AI-Generated Phishing Emails: How to Detect Deepfake Messages

By Sophie Laurent, Hobbyist with a keen interest in password security and online safety, Trusty Password · 1 June 2026 · 7 min read · 1327 words

AI-Generated Phishing Emails: How to Detect Deepfake Messages

Traditional phishing detection relied on broken English, spelling errors, and generic greetings — red flags that even casual users could spot. AI-generated phishing emails eliminate all of these telltale signs. A May 2026 study by the Anti-Phishing Working Group found that AI-written phishing emails bypass traditional spam filters 87% of the time, compared to just 52% for human-written phishing emails. The implications are stark: every organisation that still relies on "spot the typo" training is actively vulnerable.

Critical shift: The era of "spot the typo" security training is over. AI-generated phishing has perfect grammar, natural language, and contextually appropriate messaging. Detection must shift from language analysis to behaviour analysis.

The problem is compounded by the sheer volume of AI-generated messages. With large language models, attackers can generate thousands of unique, personalised phishing emails in minutes — each one tailored to the recipient's role, company, and recent activity. This is not a theoretical future threat. It is happening now, and the data shows it is working better than traditional phishing ever did.

How Attackers Use AI to Craft Phishing Emails

Attackers leverage LLMs (Large Language Models) like ChatGPT, Claude, Gemini, and open-source models such as Llama and Mistral to automate every stage of phishing campaign creation. The workflow typically follows three steps:

Step 1 — Reconnaissance: The attacker feeds the LLM scraped data about the target organisation — employee names, recent projects, annual reports, social media posts, and press releases. This context enables the AI to generate messages that reference real internal initiatives and use authentic company terminology.

Step 2 — Drafting: The LLM generates the email body, subject line, and sender name. Attackers can instruct the model to mimic a specific person's writing style by providing sample emails or LinkedIn messages from the target. The result is an email that reads exactly like the person being impersonated.

Step 3 — Refinement and A/B Testing: Some advanced campaigns use AI to automatically A/B test subject lines and opening sentences, measuring which variants generate the most clicks. The AI then iterates on the highest-performing versions, producing increasingly effective phishing lures with each cycle.

This automation means that a single attacker — or small criminal group — can now operate at a scale previously only possible for nation-state actors. The cost is minimal: GPT-4o or Claude can generate hundreds of convincing phishing emails for under $5 in API credits.

What AI-Generated Phishing Looks Like in Practice

AI-crafted phishing emails share several common characteristics that distinguish them from older, clumsier attacks:

In one documented 2026 case, attackers used Claude to impersonate a CFO and carry on a 12-email conversation with the accounts payable department, ultimately authorising a fraudulent $47,000 wire transfer. The conversation was flagged only because a sharp-eyed employee noticed the CFO's signature font was slightly different — not because of anything the AI wrote.

Detection Methods That Still Work Against AI Phishing

While content-based detection is increasingly unreliable, several technical and behavioural methods remain effective:

Pro tip: Train your team to be suspicious of any email that asks them to bypass normal procedures — even if the language sounds perfectly natural. The request is more telling than the writing quality.

Deepfake Voice (Vishing) Adds Another Layer of Risk

AI doesn't just write better phishing emails — it makes convincing phone calls too. Deepfake voice cloning technology has advanced to the point where 30-60 seconds of source audio is sufficient to create a convincing voice clone. Attackers harvest this audio from:

In the most sophisticated vishing attacks, the attacker calls the victim posing as their CEO or a trusted vendor contact. Because the voice is convincing and the attacker has contextual information (scraped from internal communications or LinkedIn), the victim is far more likely to comply with urgent requests. The 2025 UK case where fraudsters cloned a CEO's voice to authorise a £220,000 transfer is now part of a growing pattern, not an isolated incident.

Some advanced attackers combine AI-generated phishing emails with follow-up voice calls — a technique known as "multi-channel phishing." The email establishes urgency, and the voice call provides the final nudge. Because the two channels appear to confirm each other, victims perceive the request as doubly legitimate.

Building AI-Aware Defences for Your Organisation

Security awareness programs must be redesigned for the AI era. Grammar-spotting is obsolete. Here is what should replace it:

What to Do If You Receive a Suspicious AI-Generated Email

If you suspect an email was generated by AI for phishing purposes, follow these steps:

  1. Do not reply, click links, or open attachments. Engaging with the attacker confirms your email address is active.
  2. Inspect the full email headers. Look for mismatches between the display name and the actual sending domain.
  3. Verify through a separate channel. Call the person allegedly sending the email using a known phone number — not one from the suspicious email.
  4. Report to your IT/security team if at work, or forward to reportphishing@apwg.org if at home.
  5. Enable multi-factor authentication on all accounts. Even if credentials are stolen, MFA can block account takeover if the attacker doesn't have access to your second factor.

The threat landscape has fundamentally shifted. AI-generated phishing is no longer a novelty — it is the new baseline. The organisations and individuals who adapt their detection strategies from language-based to behaviour-based will be the ones who avoid becoming statistics.

Stay Safe with Strong Passwords →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder
We use cookies to improve your experience. Learn more

🔗 Recommended Security Tools

We may earn a commission if you purchase through these links — at no extra cost to you.

🔒 Kaspersky Premium 🔒 Hide My Name VPN

Make us your preferred source on Google