For twenty years, the advice was: look for bad grammar and awkward phrasing. That heuristic is dead. AI now writes phishing messages with flawless English, your bank's exact tone, and personal details pulled from breach data and your public profiles — thousands of unique variants at a time.
This is the least flashy AI scam and by volume the biggest. The result of AI in phishing isn't a new trick; it's the industrialization of the old one. What survives as a defense is structural: not how the message reads, but what it asks you to do and where it sends you.
What changed
1
Perfect language, any language
Grammar, idiom, and brand voice are now machine-perfect — in English, Spanish, or whatever your region speaks. Reading quality tells you nothing anymore.
2
Personalization at scale
AI merges breach data (your name, employer, subscriptions) into individually tailored messages. 'It knew my details' is no longer evidence of legitimacy.
3
Infinite variants
Spam filters catch repeated templates. AI generates a unique message per recipient, eroding filter effectiveness and making 'search the exact text' checks less useful.
4
Full conversations
Reply to probe a scammer and an AI answers — patiently, coherently, in character — for as many rounds as it takes. 'I'll test them with questions' no longer works.
What still gives it away
!The link's real destination
AI writes prose, but the phish still has to send you somewhere. Check the actual domain: chase-alerts-secure.com is a lie no language model can hide.
!The ask itself
Verify credentials, read back a code, pay a small fee, install remote software, buy gift cards. The extraction step hasn't changed — it can't, because it's the point.
!Manufactured urgency
Account suspensions, expiring packages, legal deadlines measured in hours. Real institutions move slower than their impersonators, always.
!Sender address vs. display name
The display name says 'Chase Fraud Team'; the address is a random domain. One header check outlives every writing-quality heuristic.
!Unexpected contact requiring action
You didn't initiate it, and it needs you to click, pay, or confirm something. That combination deserves verification through the company's real app or site, every time.
The new rules
✓Judge the ask, not the prose
Retire 'does this read like a scam?' Ask instead: does this want credentials, codes, payment, or software installed? That's the invariant.
✓Never travel by link
For anything involving money or logins, open the app or type the address yourself. This single habit neutralizes essentially all phishing, AI or not.
✓Treat 'it knows my details' as neutral
Your name, address, employer, and subscriptions are in breach datasets. Personalization proves data access, not identity.
✓Use a checker instead of your gut
Paste suspicious messages into Scambook's free AI checker — it evaluates the request structure, sender, and destination, which are the parts scammers can't launder.
Frequently asked questions
Is it even worth reading emails carefully anymore?
Yes, but read for structure, not style: who really sent it (the address, not the name), where the link really goes, and what it wants you to do. Those three checks survive AI; 'does it sound off?' doesn't.
My spam filter is good. Doesn't it catch AI phishing?
It catches most, and AI-generated variety is specifically designed to slip the remainder through. Filters are a seatbelt, not a force field — the messages that reach you are the ones that beat the filter.
Can AI phishing texts and DMs be checked the same way?
Yes — the structure is identical across email, SMS, and social DMs: an impersonated sender, a link or callback number, and an extraction ask. The same three checks apply, and you can paste any of them into Scambook.
Fight AI with AI.
Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.