2026-09-01 · Cybersecurity

Phishing and social engineering: what's changed with generative AI

Spelling mistakes and awkward phrasing are no longer reliable signals. What still holds up as a solid indicator when facing a suspicious email or call.

For years, teams were trained to spot a phishing email by its typos and odd tone. Generative AI has made that reflex obsolete: a phishing text written today can be flawless in form.

What's actually changed

Three concrete shifts: flawless phishing emails, in the exact language and tone of the impersonated organization; cloned voices generated from a few seconds of public audio, used for urgent calls impersonating an executive; and personalized campaigns built from public information (LinkedIn, press releases) generated at scale rather than by hand.

What's still a reliable signal

Form no longer gives anything away, but context still does: an urgent transfer request outside the usual process, pressure to bypass normal approval, an unusual contact channel (SMS instead of a work email) remain strong signals, regardless of how polished the text or voice is.

The right organizational response

A dual-validation process for any sensitive financial movement, independent of the request's channel, neutralizes most of the risk — far more effectively than training a team to "spot the signs", which no longer works reliably.

A question about your situation?

Request a free audit, we'll look at your specific case.