“Look for Typos” Was Always Bad Phishing Advice. Now It’s Actively Dangerous.
For decades, phishing awareness training boiled down to a handful of tells: bad grammar, generic greetings, a sender address that almost matched but not quite. That advice was never perfect, but it caught a real share of attempts. It’s now actively counterproductive, because the emails without any of those tells “Look for Typos” are precisely the ones most likely to succeed — and training people to relax once an email reads smoothly is training them to be more vulnerable to exactly the messages doing the most damage.
What the Research Actually Found
This isn’t a hunch about how phishing has evolved — it’s been tested directly, with real participants, in a controlled study. Researchers Fredrik Heiding, Bruce Schneier, and Arun Vishwanath, publishing through Harvard Business Review, found that fully AI-automated spear phishing emails achieved a 54% click-through rate, matching the performance of skilled human expert attackers and vastly outperforming the 12% rate of generic, template-based phishing, while reducing the cost of running such a campaign by more than 95%. That’s not a marginal improvement in attack quality. It’s AI matching the results of a skilled human con artist, at a fraction of the cost and none of the specialized expertise previously required to pull it off.
The mechanism behind that success rate is worth understanding directly, because it explains why grammar and formatting stopped mattering as a defense. The same research found that participants who clicked AI-generated phishing links frequently cited the message’s personalization — details that felt specific and accurate to their actual situation — as the reason they trusted it, a factor essentially absent from generic control emails. The AI wasn’t succeeding by avoiding mistakes. It was succeeding by being genuinely, convincingly relevant to the specific person receiving it, using publicly available information about their role, their projects, and their professional context to construct something that read as legitimately theirs rather than mass-produced.
Why the Old Tells Disappeared
It’s worth being specific about the mechanical reason grammar and formatting stopped being reliable signals. A large language model, given a target’s name, role, company, and some publicly available context, generates fluent, grammatically correct, contextually appropriate prose as its default behavior — it’s not straining to sound convincing, it’s simply doing what these systems do by default when given a clear prompt. The awkward phrasing and generic greetings that used to flag a phishing attempt were artifacts of a human attacker working outside their native language or working from a generic template meant to scale across thousands of targets at once. AI removes both constraints simultaneously: it writes fluently in the recipient’s own language and register, and it can personalize that fluent writing individually for each target at essentially the same cost as a generic blast.
This connects to a mechanism we’ve covered from a related angle. Our piece on how ChatGPT actually works explains that these models generate text by predicting the most statistically plausible continuation of a prompt — which, applied here, means a well-crafted phishing prompt produces exactly the fluent, professional, believable output an attacker wants, with no more effort than any other request to the same tool.
What CISA Actually Recommends Now
Given that content-based red flags have become substantially less reliable, official government guidance has shifted its emphasis accordingly. CISA’s official Recognize and Report Phishing guidance directs people to resist the urge to click on links or attachments that seem too good to be true or create unusual urgency, and specifically recommends independently looking up a company or person’s verified contact information — through their actual website or a number you already have — rather than using any contact information provided within the suspicious message itself. Notice what this guidance is built around: not “check for spelling errors,” but “verify through a channel the message itself doesn’t control.” That’s a meaningfully different skill than proofreading, and it’s the one that actually holds up against AI-generated content.
The Signals Worth Actually Watching For
With content-based tells less reliable, the more durable signals shift toward context and behavior rather than surface polish.
Unexpected requests tied to real details. An email referencing an actual project, a real colleague’s name, or genuine internal terminology feels more trustworthy specifically because it’s accurate — which is exactly the mechanism the Harvard research identified as driving higher click rates. Accuracy about real details is no longer proof of legitimacy; it’s now a signal worth treating with the same scrutiny as a generic request, not less.
Urgency paired with a request to bypass normal process. A message pushing for immediate action, especially one asking to skip a standard verification step, sidestep a usual approval chain, or act before “checking with anyone else,” is a stronger signal than any grammatical tell ever was, because manufactured urgency remains a core manipulation tactic regardless of how the underlying text was produced.
A request for something irreversible. Wire transfers, credential resets, and gift card purchases share a common trait worth treating as its own category of caution: once completed, they generally can’t be undone. Any message driving toward one of these specific actions deserves independent verification regardless of how convincing or contextually accurate it appears.
A mismatch between the display name and the actual underlying address. This remains one of the few genuinely reliable technical tells that AI-generated content doesn’t remove, since it depends on the sending infrastructure rather than the writing quality. Checking the actual email address behind a display name, not just the name itself, still catches a meaningful share of attempts.
Verifying Without Relying on Gut Feel
The practical shift this all points toward is the same one worth building generally for anything suspicious arriving digitally. Our piece on how AI is changing online scams covers the same underlying defense applied to voice-based fraud — calling back through a number you already have, rather than one provided in the suspicious message, defeats a wide range of both AI-generated phishing and AI-generated voice scams, because it routes verification through a channel the attacker fundamentally can’t control, regardless of how convincing their initial contact was.
This is also where organizational habits matter as much as individual vigilance. A workplace culture where pausing to verify an unusual request, even one that looks entirely legitimate, is normalized and never treated as an overreaction protects far better than relying on any individual’s ability to spot a well-crafted message in the moment. CISA’s guidance is explicit that reporting suspicious messages, even ones that turn out to be legitimate, should never be discouraged, precisely because the cost of a false alarm is trivial compared to the cost of a successful attack.
Building the Habit Into Everyday Digital Life
This connects to a broader discipline worth applying across AI interactions generally, not just phishing specifically. Our guide to fact-checking AI answers covers the same underlying instinct — treating a fluent, confident, contextually appropriate message as something to verify independently rather than something to trust because it reads well. And since a meaningful share of what makes AI-generated phishing so personalized comes from publicly available information about you, our guide to protecting your privacy when using AI touches on a related point worth extending here: being deliberate about what personal and professional details are publicly discoverable reduces the raw material available for exactly this kind of targeted attack.
A Concrete Walkthrough of How a Modern Attempt Looks
It helps to see this laid out rather than described abstractly. An attacker researches a mid-level employee’s public LinkedIn profile, finds they recently posted about closing a deal with a specific vendor, and prompts an AI tool to draft a follow-up email from that vendor’s actual point of contact, referencing the real deal terms, written in polished, professional prose with zero grammatical errors, requesting an updated invoice be paid to a “new” account due to a recent “banking transition.” Nothing about the writing gives it away. The names are real. The deal details are accurate. The tone matches how that vendor has always communicated.
The signal that actually matters here isn’t in the writing at all — it’s in the request itself. A banking detail change delivered by email, without independent verification through a phone call to a number already on file, is exactly the kind of irreversible, easily exploited action worth treating with automatic suspicion regardless of how convincing the surrounding email reads. The employee who catches this isn’t the one with the sharpest eye for grammar. It’s the one who’s built the habit of picking up the phone and calling the vendor’s known number before approving any payment detail change, treating that verification step as mandatory rather than optional, independent of how legitimate the request appears on the page.
A Quick Audit of Your Own Verification Habits
A useful, honest exercise: think back to the last unusual request you received by email, whether or not you now believe it was legitimate — a vendor update, an executive asking for something urgent, a colleague requesting access to something sensitive. Did you verify it through an independent channel, or did you evaluate it based on how professional and accurate it seemed? Most people, being honest, still rely heavily on the second method, which the research above shows is now precisely the method AI-generated phishing is specifically optimized to defeat.
Frequently Asked Question
Is looking for typos and bad grammar still a good way to spot phishing?
No, this signal has become substantially less reliable. AI-generated phishing emails are typically grammatically correct and fluently written by default, removing the awkward phrasing that used to help people identify suspicious messages. Verification through an independent channel is a more reliable defense than content-based red flags.
How much more effective is AI-generated phishing than traditional phishing?
A Harvard Business Review study by researchers Fredrik Heiding, Bruce Schneier, and Arun Vishwanath found that fully AI-automated spear phishing achieved a 54% click-through rate, matching skilled human expert attackers and far exceeding the 12% rate of generic phishing, while reducing campaign costs by more than 95%.
Why do personalized AI phishing emails work so well?
Research found participants who clicked AI-generated phishing links often cited the message’s personalization, details that felt specific and accurate to their actual situation, as the reason they trusted it. AI can use publicly available information to construct messages that feel genuinely relevant rather than mass-produced, which increases trust rather than raising suspicion.
What does CISA actually recommend for verifying a suspicious message?
CISA’s official phishing guidance recommends independently looking up a company or person’s verified contact information through their actual website or a number you already have, rather than using any contact information provided within the suspicious message itself, and resisting urgency-driven pressure to act quickly.
What signals are still reliable for spotting phishing attempts?
Checking the actual email address behind a display name remains a reliable technical signal. Behavioral patterns also matter more now than content: urgency paired with a request to bypass normal process, and requests for irreversible actions like wire transfers or credential resets, deserve independent verification regardless of how professional the message reads.
Should I report a suspicious email even if I’m not sure it’s phishing?
Yes. CISA’s guidance emphasizes that reporting suspicious messages should never be discouraged, even when they turn out to be legitimate, since the cost of a false alarm is trivial compared to the cost of a successful phishing attack going unreported.
Conclusion
The advice to look for typos and awkward phrasing in a phishing email isn’t just outdated — Harvard research shows AI-generated messages without those tells achieve triple the click-through rate of generic phishing, matching skilled human attackers at a fraction of the cost, in large part because personalized accuracy builds trust rather than signaling danger. The signal that used to work has become one of the least reliable ones available.
What actually holds up is verification through a channel the message itself doesn’t control — a callback to a known number, an independent lookup of contact information, a pause before acting on urgency or bypassing normal process — regardless of how professional, accurate, or contextually convincing the initial message appears. That shift, more than any updated list of red flags, is what the current evidence actually supports.
