For years, security awareness training taught people to look for the tells: clumsy grammar, generic greetings, a sense of urgency that didn’t quite fit. That advice was good, and it is now obsolete. The tells are gone, because the attackers stopped writing their own emails.
Generative AI produces phishing messages in flawless English, or flawless French, tuned to your industry and referencing things that are actually true about your company, scraped from your website and LinkedIn in seconds. CrowdStrike measured an 89 percent year-over-year increase in attacks by AI-enabled adversaries. What used to require a skilled social engineer now requires a subscription.
It’s no longer just email
The part that catches businesses off guard is that the fraud has moved beyond text. Voice cloning tools can reproduce a person’s voice from a short clip, a podcast appearance, a webinar recording, even a voicemail greeting. There are now regular cases of finance staff receiving a phone call from what is unmistakably their CEO’s voice, asking them to process an urgent payment. Video deepfakes have appeared on live conference calls. The instinct we all rely on, “I know that voice, I know that face,” has quietly stopped being proof of anything.
For a small business this lands harder than it does for a bank. A bank has payment controls layered five deep. A twenty-person firm often has one person who pays the bills and a culture of trusting the boss’s word. That combination is exactly what these attacks are built for.
Spotting fakes is a losing game
We want to be direct about this: training people to detect AI-generated fakes is a strategy with an expiry date, and the date has passed. When the message is fluent, the details are accurate, and the voice is real enough to fool a spouse, “look closer” is not a defence. The people who fall for these are not careless. They are normal people confronting fakes engineered to beat human judgment.
The defence that works doesn’t depend on judgment. It depends on process.
Verification as a habit, not a heroic act
The standard we set with clients is simple to state: no payment, banking change, or credential request gets actioned on the strength of the request alone, no matter who it appears to come from or how urgent it sounds. Verification happens out-of-band, meaning a callback to a number you already had on file, never one supplied in the message itself. Two people sign off on any change to where money goes. And critically, leadership has to make it culturally safe to slow down. If an employee fears looking foolish for verifying the “CEO’s” urgent request, the process fails exactly when it matters.
Alongside process sit the technical layers: email authentication so your own domain can’t be cheaply spoofed, filtering that examines behaviour rather than just content, and MFA so that a stolen password alone gets an attacker nothing.
The uncomfortable truth of 2026 is that seeing and hearing are no longer believing. The comfortable truth is that a business with a verification habit doesn’t need to believe. It checks.