The Old “Bad Grammar” Trick Is Dead

You know the drill. An email arrives with a misspelled company name, a link to a slightly off domain, and three typos in the first paragraph. Easy to spot. Easy to delete.

People attending an in-person internet safety education session
Image: U.S. Air Force photo by Senior Airman Tiffany Troeger via Wikimedia Commons (Public Domain)

That world is gone. AI has solved the cybercriminal’s biggest hurdle — sounding like a real person. Large language models now draft phishing emails that are grammatically flawless, contextually aware, and often indistinguishable from legitimate messages at a glance.

The numbers back this up. AI-generated phishing emails achieve click-through rates more than four times higher than human-crafted ones, according to Vectra AI. Hoxhunt’s 2026 phishing trends report logged a 14x end-of-year surge in AI-generated attacks. The old training that told people to “look for typos” is setting them up to fail.

Here’s what to look for instead — and what you can actually do about it.

What Changed When AI Entered the Picture

Before generative AI, a targeted spear-phishing email took an attacker hours of manual research. They had to find your name, your role, your company’s structure, and craft something believable. That friction mattered — it limited the volume of attacks.

Now, a script calls an LLM’s API and generates thousands of unique, personalized emails in seconds. The AI hooks into data brokers and LinkedIn scrapers, inserting job titles, manager names, and references to recent certifications — all automatically. Zero marginal cost. Infinite scale.

Three things make these emails dangerous:

  • Perfect syntax and grammar. LLMs don’t misspell words or mix tenses unless the attacker explicitly prompts them to. The writing reads like polished corporate communication.
  • Hyper-personalization at scale. The email knows your name, your role, and sometimes your recent projects. It feels real because the attacker fed real data into the model.
  • Context-aware urgency. AI monitors tech news and industry updates. If a major cloud provider has an outage, the model generates a plausible email about it the next day — referencing real events to manufacture panic.

What to Actually Look For Now

If spelling and grammar are no longer reliable indicators, where do you focus? Context. AI is excellent at generating convincing language, but it still struggles with the nuanced reality of how your specific organization operates.

1. Contextual Hallucinations

When an attacker prompts an LLM to draft a phishing email, the model can confabulate — combining real but unrelated pieces of information. The email might reference a genuine internal project but attribute it to the wrong department. It might mention a software vendor your company actually uses but reference a product tier you don’t subscribe to.

These are hallucinations dressed up as credibility. A phishing email from “IT” about a “mandatory security patch for our Salesforce Enterprise instance” looks convincing until you remember your company runs Standard, not Enterprise. The detail is specific enough to feel real but wrong enough to be fake.

The tell: confidence without accuracy. If an email is extremely detailed but the operational context feels slightly off, treat it as suspicious regardless of how polished the writing is.

2. Hyper-Specific Urgency Tied to Current Events

Traditional phishing used generic threats: “Your account will be suspended in 24 hours.” AI-generated phishing news-jacks. It monitors major tech headlines and generates urgency tied to what’s actually happening.

A real example: after a widely reported cloud outage, an AI-generated phishing email arrives the next day saying, “Due to yesterday’s AWS outage, please run this specific IT patch immediately to restore your database access.” The reference to a real event makes the email feel timely and legitimate. The request is fake.

This tactic works because it exploits a genuine moment of concern. When something real just went down, you’re already thinking about it — and the email rides that wave.

3. Multi-Channel References

AI syndicates now coordinate across channels to build artificial credibility. A phishing email might state, “I just pinged you on Microsoft Teams about this wire transfer,” or “You’ll receive an SMS verification code from IT in exactly two minutes.”

The email references a second channel to prime you — even though no such Teams message or SMS exists. When you check and find nothing, you might assume you missed it rather than question the email. The attacker counts on that hesitation.

The tell: cross-channel claims you can’t verify. If an email references another channel, check that channel independently — through its official app or interface, not through any link in the email itself.

4. Sender Behavior That Doesn’t Match the Norm

Since the message content can be nearly perfect, the most reliable indicators are often behavioral rather than textual. Who sent it, when, and what they’re asking for.

  • Unexpected sender. An email from someone you don’t normally hear from, especially if it asks for something sensitive.
  • Unusual timing. A “urgent” message from your CEO at 11 PM on a Saturday.
  • Unusual request. A message asking you to bypass normal processes — wire a payment outside procurement, share credentials over email, download an attachment you weren’t expecting.

These are the same red flags that worked a decade ago. AI changed the writing, not the underlying psychology. The request is still the tell.

How Amazon Is Tackling This From the Source

Amazon recently rolled out a feature in Alexa for Shopping that tackles this problem from a different angle. Instead of asking users to spot subtle clues, it lets them verify a message directly.

You show the message to Alexa — an email, text, or even a screenshot — and the AI checks it against Amazon’s record of every communication it has sent globally. It analyzes sender information, content, timing, and message metadata. Within seconds, you get a clear answer: confirmed from Amazon, not from Amazon, or unable to verify — along with guidance on what to do next.

What makes this different from generic scam-detection tools is that only Amazon can definitively confirm whether a message originated from its systems. Other tools analyze patterns like suspicious URLs or common scam language. Amazon’s tool compares the message against an authoritative internal record. It only confirms a message is genuine when it’s completely certain.

The approach is worth noting even if you’re not an Amazon customer, because it points to where this is heading: verification at the source, not detection in the inbox.

What You Can Do Today

You don’t need enterprise security tools to significantly reduce your exposure. These steps work for anyone:

Verify Out-of-Band

If an email asks you to do something sensitive — click a link, download a file, approve a payment, share credentials — verify it through a separate channel. Call the sender. Message them on a platform you already use. Check with your IT team. The key is to use a channel independent of the one the request came through.

Question Specificity That Feels Slightly Wrong

AI phishing emails are specific — but sometimes the specificity is wrong. A reference to a project that doesn’t exist, a tool your team doesn’t use, a process that doesn’t match how your organization actually works. Train yourself to notice when an email’s operational details don’t line up with your reality, even if the writing is perfect.

Treat Urgency as a Flag, Not a Reason to Act

Urgency is the attacker’s oldest tool and still one of the most effective. AI just makes the urgency more believable by tying it to real events. When an email demands immediate action, pause. The 30 seconds you spend verifying is never worth the risk of acting on a fake.

Use Official Apps and Websites, Not Email Links

If an email claims to be from your bank, your email provider, or any service you use, don’t click the link. Open the official app or type the website address directly into your browser. Log in there and check for any notifications. If there’s a real issue, it will show up in your account. If your personal data has already been exposed in a breach, the verification steps are even more critical: — not just in your inbox.

Report Suspicious Messages

Every report helps. Email providers and companies use reported messages to improve their detection and take down malicious infrastructure. Amazon’s tool, for example, uses every verification report to identify emerging scam tactics and protect more customers. Your report is a small action with a real downstream effect.

AI Detection Tools: What They Can and Can’t Do

The same generative AI that powers phishing has also spawned a detection industry — part of what’s become a multibillion-dollar AI security market. Companies like Pangram build AI detectors trained to distinguish human-written text from AI-generated content. Pangram’s approach is notable: it trains on human writing paired with AI-generated doubles matched by topic, length, and tone, then learns to spot the subtle differences in word choice, syntax, and grammatical structure.

In independent evaluations, Pangram performed best at identifying fully AI-generated, mixed, and humanized text. The New York Times’ Brian X. Chen reported in August 2026 that Pangram correctly distinguished human and generated writing across dozens of tests, including attempts to imitate his personal style.

But here’s the catch: AI detection is a spectrum, not a binary test. No detector is perfectly accurate, and false positives carry real consequences — especially when a detector flags legitimate human writing as AI-generated. The technology is useful as one signal among many, not as a definitive answer.

For individual email recipients, AI detection tools are mostly irrelevant. You’re not going to paste every email into a detector. The practical defense is the human one: verify before you trust, question urgency, and check context.

The Bottom Line

AI didn’t invent phishing. It made it cheaper, faster, and harder to spot by eye. The old heuristics — typos, bad grammar, generic greetings — are no longer reliable. The new defense is contextual: does the operational detail match reality? Does the urgency feel manufactured? Can you verify this request through a channel the email didn’t control?

The technology will keep advancing — and the security risks go beyond just email. Attackers will get better at mimicking specific writing styles, referencing real projects, and coordinating across channels. But the core defense hasn’t changed: pause, verify independently, and don’t let urgency override your judgment.

An email that demands immediate action and can’t survive a 30-second verification isn’t worth the risk — no matter how well it’s written.

Filed under Tech & Gadgets
Last Update: September 26, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted