Skip to content

WHT Cyber  /  Field Notes  /  Threat Education

Threat Education

AI phishing is here: why your “spot the typo” training no longer works.

The old phishing tells are gone. Typos, broken English, weird email signatures, addresses that don't quite look right — AI fixed all of it. Here's what phishing looks like in 2026, and what your team actually needs to do instead.

By WHT Cyber Engineering June 30, 2026 8 min read

For the last fifteen years, security awareness training has rested on one premise: phishing emails look wrong. Misspellings. Bad grammar. A Gmail address pretending to be the CEO. Weird URLs with extra letters. Teach people to spot the wrong-looking emails and you've covered most of the threat.

That premise is broken in 2026. Generative AI doesn't make typos. It writes in the voice of whoever it's pretending to be. It clones a CFO's speech patterns from a single quarterly earnings call. It runs a real-time deepfake video of your CEO in a Zoom meeting. The cues your team was trained to spot — the ones that were the entire job of awareness training — aren't there anymore.

If your last training video tells your staff to “look for typos and bad grammar,” you have a problem.

What AI phishing actually looks like now

A few patterns we're seeing repeatedly across our client base in 2026:

The perfectly-written vendor email

The accounts payable clerk gets an email from a real vendor, on the right domain (sometimes spoofed, sometimes from a genuinely compromised mailbox). The thread shows previous real conversations — because the attacker is replying inside a stolen mailbox and has read the entire history. The new email says the vendor's bank routing number has changed. The language matches the vendor's prior emails. The signature block is correct. The clerk updates the payment record. The next $42,000 wire goes to the attacker.

There is nothing visually wrong with this email. It is grammatically perfect. It uses the right tone. It quotes a real prior invoice. The only “tell” is that the request itself — change banking info — should always require a callback on a known phone number. Awareness training that focused on visual cues missed this entirely.

The deepfake voice call

The CFO is on vacation. The controller gets a phone call from the CFO's number (spoofed) or a similar number. The voice is the CFO's voice — same cadence, same accent, same verbal tics — built from 30 seconds of public audio off a podcast or LinkedIn video. The CFO “needs” an urgent wire transfer to close a deal before market open. The controller does it.

The FBI's Internet Crime Complaint Center has been flagging vishing and deepfake-enabled fraud as a growing share of BEC losses (IC3 Annual Report), and the consumer protection bureau has warned that a few seconds of cloned audio is enough. The technology is no longer expensive or rare.

The lookalike domain that's actually correct

The classic phishing tell — a domain with an extra letter or a wrong TLD — still exists, but attackers have moved beyond it. We're now seeing real compromised mailboxes used to send phishing internally. The domain is right. The sender display name is right. SPF, DKIM, and DMARC all pass. The email is coming from a real person at the real company — whose account was taken over an hour earlier.

The AI-generated “chain of trust”

An attacker uses AI to generate a complete fake supplier — website, LinkedIn profiles for three “employees,” portfolio of past work, customer testimonials, even a Google Business listing with reviews. Your sourcing team finds them, gets a quote, signs a contract. The deliverable never comes. Or worse, the “vendor” sits in the supply chain long enough to start invoicing for nothing.

Why old-school training fails

Three structural problems with the awareness-training model most SMBs still run:

  • It's annual, not adaptive. One 45-minute video in January doesn't change behavior in October when the email actually lands.
  • It teaches surface tells. Typos, fake-looking URLs, generic greetings. AI has neutralized all three.
  • It puts the entire defense on the human. Security that relies on every employee making the right judgment every time is security that fails on the busiest day of the quarter.

The honest truth: you cannot train your way out of AI phishing. You can reduce the click rate, but you cannot get it to zero. A defense built on “don't click” is a defense that lost the moment the email looked real.

The 2026 defense: process, not posters

What works now is a layered defense where the human is one control among many — not the only one.

1. Pre-defined out-of-band verification for money and credentials

Any request to change banking information, wire funds outside the normal pattern, share credentials, or grant access — regardless of who it appears to come from — requires a callback on a number from your own records (not a number in the email). This rule is non-negotiable and applies to executives too. The CFO doesn't get to skip it because they're “in a hurry.”

2. A safe word for executive impersonation

Pick a word. Tell your leadership team and your finance team. Any voice or video call requesting an out-of-pattern action must include the safe word. No safe word, no action. This is the most effective control against deepfake voice that we've seen, and it costs nothing.

3. Phishing-resistant MFA on the accounts that matter

SMS codes and basic app-push MFA can be defeated by adversary-in-the-middle attacks that proxy the login in real time. For email, finance systems, and admin accounts, move to FIDO2 hardware keys, Windows Hello for Business, or number-matching push with geographic anomaly detection. CISA has been pushing phishing-resistant MFA as the baseline for any role that handles money or sensitive data.

4. Email security that actually inspects content, not just sender

DMARC enforcement, plus a third-party email security gateway that does behavioral analysis — flagging emails that ask for banking changes, that come from a never-before-seen sender claiming to be a known executive, that have urgency markers. Microsoft Defender for Office 365 Plan 2 or a third-party tool like Abnormal, Proofpoint, or Mimecast.

5. Continuous, scenario-based simulation

Replace annual training with monthly micro-simulations. Use scenarios that match what's actually happening — deepfake voice voicemails, AI-written vendor emails, fake LinkedIn outreach. Measure click rate and report rate. The goal isn't zero clicks. The goal is that the third person who saw it reported it within ten minutes.

6. Detection and response, not just prevention

Assume something will get through. The question is how fast you see it. An EDR/MDR with mailbox-rule monitoring, anomalous-sign-in alerting, and a SOC behind it can catch the next step — the inbox rule that hides incoming replies, the impossible-travel login, the new OAuth grant — before the wire goes out.

What WHT recommends

If you have one hour this quarter to harden your business against AI phishing, do these things in this order:

  1. Write the out-of-band rule today. One paragraph, signed by the owner, sent to every employee. “Any request to change banking info, send a wire outside our normal pattern, share credentials, or grant new access — from anyone, including me — requires a callback on a number from our own records. No exceptions, including from me, including when it's urgent.”
  2. Pick a safe word with leadership and finance. Take five minutes. Write it down once. Memorize it. Use it.
  3. Audit who's still on SMS-based MFA. Move anyone with admin, finance, or payroll access to phishing-resistant MFA within 30 days.
  4. Enforce DMARC on your domain. If you're at “p=none,” you're not enforcing anything. Get to “p=quarantine” and then “p=reject” with proper monitoring.
  5. Set up one monthly simulation. Doesn't need to be elaborate. Pick a scenario from the news that month and send a simulated version to your team. Measure who reports it.
  6. Have a written escalation path. If someone clicks, who do they tell? In what minute? Most of the worst breaches we see started with a click and a six-hour delay before anyone reported it.

The bottom line

AI didn't kill phishing. It killed visible phishing. The email looks fine. The voice sounds real. The video on the Zoom call shows the right face. The defense can no longer be “notice that something is off,” because nothing will look off.

The defense is process: a callback rule that survives a perfect email, a safe word that survives a perfect voice, MFA that survives a perfect login page, and a SOC that catches the step after the click. None of it is glamorous. All of it works.

Want to see how your team would do against today's AI phishing?

We'll run a no-cost phishing assessment using current AI-generated scenarios, score your team's reporting rate, and walk you through the gaps. 45 minutes.

Book the assessment More Field Notes →