AI-Powered Phishing: When Every Email Sounds Like It Was Written by Someone Who Knows You
Large language models have industrialised the production of highly personalised phishing content. Volume and quality have both increased by orders of magnitude.
The traditional indicators of phishing emails were artefacts of production constraints. Poor grammar, implausible context, generic salutations, and stilted language were not design choices. They were the consequence of attacks produced at scale by operators without the language fluency or contextual knowledge to produce convincing impersonations. Those constraints no longer apply. Large language models have removed both the language fluency barrier and the contextualisation barrier simultaneously, and the shift in attack quality has been immediate and significant.
AI-generated phishing content is now contextually accurate, grammatically perfect, tonally appropriate to the impersonated sender, and personalised to the recipient's known professional context. The open-source intelligence inputs that drive personalisation are the same ones available to any attacker: LinkedIn profiles, company websites, news coverage, earnings calls, and social media. The difference is that AI tools can aggregate and synthesise this material in seconds and produce a convincing impersonation at a marginal cost that is, for practical purposes, zero.
The volume implications are as significant as the quality implications. Spear phishing, historically expensive to produce at scale, is now economically viable at any volume. Organisations that were previously exposed to spear phishing primarily from well-resourced state actors or organised crime groups are now exposed to campaigns by actors with minimal resources and modest technical capability. The democratisation of capability is almost entirely to the attacker's advantage.
The detection challenge this creates for technical controls is acute. Signature-based and pattern-based phishing detection is calibrated, in part, to the quality indicators that AI-generated content no longer exhibits. Detection systems trained on historical phishing samples will underperform against content that lacks the linguistic signatures of previous-generation attacks. The security industry is adapting, but the adaptation lag is real and currently exploitable.
The most durable defence against AI-powered phishing operates at the process level rather than the technical level. Verification protocols that require out-of-band confirmation before acting on any request received by email, regardless of apparent sender identity, cannot be defeated by content quality alone. Culture change, specifically the normalisation of verification as a routine professional behaviour rather than an expression of distrust, is the most resilient long-term control available.
"The quality of a phishing email is no longer a signal of its legitimacy. The assumption that a well-written, contextually accurate message from a known sender is genuine is now a liability."
Custodia One Advisory Perspective
What Your Organisation Should Do
Update your phishing awareness training to remove quality-based heuristics: AI content looks legitimate
Implement mandatory out-of-band verification for all financial, access, and data requests received by email
Review your technical phishing detection for dependence on linguistic quality signals that AI-generated content will not exhibit
Conduct regular AI phishing simulations to test your organisation's actual response to current-generation attacks
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
