Cyber Security Speaker | Media Commentator

AI-Powered Phishing: Why Your Inbox Is Now the Frontline

For years, the advice to spot a phishing email was simple

By Francis West, Security Everywhere

Scaring is caring — so let’s start with the scary bit.

For years, the advice to spot a phishing email was simple: look for the typos, the clumsy grammar, the “Dear Customer” that never quite sounds right. That advice is now dangerously out of date.

AI has taken the one weakness criminals always had — poor English, generic messaging, obvious fakes — and quietly fixed it for them. Today’s phishing emails are grammatically perfect, personalised with details scraped from LinkedIn and your own website, and written in a tone that matches how your suppliers, your bank, or your own MD actually writes. Some are generated in seconds, in bulk, tailored to hundreds of individual targets at once. A few are now built using voice-cloning tools to follow up a fake email with a fake phone call, just to add pressure.

I’ve delivered well over 500 talks since COVID — everything from five-minute lightning sessions to four-hour workshops — and this is the single biggest shift I talk about on stage right now. Not because it’s dramatic, but because it’s exactly the kind of change that catches ordinary, careful businesses off guard.

Email is still the number one way criminals get into a business. It doesn’t matter how good your firewall is if someone in your finance team clicks a beautifully faked invoice email and hands over banking details, or a fake “IT department” login page harvests a password that opens the door to everything else.

That’s precisely why email security and access control sit right at the centre of the National Cyber Security Centre’s recommended approach to protecting a business — and why they’re two of the pillars we build every Security Everywhere client around.

Before anything else, here’s what you and your team can do today, regardless of who you use for IT:

  • Slow down on urgency. AI-written phishing is designed to sound calm and legitimate, but it still relies on urgency — “approve this today,” “your account will be suspended.” Treat urgency itself as a red flag, however well-written the message.
  • Verify payment or bank detail changes out of band. Never confirm a change to bank details by replying to the email that requested it. Phone the person on a number you already have on file — not one supplied in the message.
  • Check the actual sending address, not just the display name. AI can perfect the wording; it can’t always perfectly fake the underlying email address.
  • Use unique passwords everywhere, with multi-factor authentication switched on. Even a perfectly convincing phishing email is far less dangerous if a stolen password alone isn’t enough to get in.
  • Assume your own public information is being used against you. Bios, org charts, and “who’s who” pages on your website are exactly what AI tools now use to make a fake email sound like it knows your business.

Here’s the honest truth I give every audience: no amount of staff training will catch 100% of AI-generated phishing, because the whole point of the technology is to remove the tells people are trained to spot. At some point, vigilance has to be backed up by tools that are watching every message before your team ever sees it.

This is exactly what our Email Security service is built for — stopping phishing and spoofing attempts before they land in an inbox, rather than relying on someone spotting them under pressure. It sits alongside our Email Deliverability and anti-spoofing service, which stops criminals impersonating your domain to attack your customers and suppliers — a growing tactic now that inbound filtering has improved. And because stolen credentials are so often the actual prize, our Password Security service alerts you the moment your team’s details show up in a data breach, so a stolen password gets shut down before it’s used against you.

Together, these map directly onto the NCSC’s recommended approach: strong access control, and protection against malware and malicious content, working as layers rather than a single point of failure.

Our mission at Security Everywhere is to protect 1,000,000 businesses from cybercrime. We hit our first milestone — educating and protecting 1,000,000 people — in October 2025, and we’re now roughly a third of the way to doing the same for businesses. AI-powered phishing is one of the clearest reasons that mission matters more each year, not less: the barrier to launching a convincing attack has never been lower.

If you want to know how exposed your business really is, our free Cyber Security Health Quiz takes a few minutes and gives you a clear, honest picture — no sales pitch attached. And if you’d like Francis to bring this topic to your team, conference, or panel, get in touch — it’s one of the most requested talks on the circuit right now.

Francis West is CEO of Security Everywhere and Westtek Solutions, and has delivered 500+ talks on cyber security since COVID, sat on 7 security panels including for the Home Office, and holds 181+ LinkedIn recommendations from clients and peers.

Share:

More Posts

Get in touch