AI-Written Phishing
The spelling is perfect. That is the problem.
What Is AI-Written Phishing?
Phishing text is now generated from whatever your company already publishes, so it arrives with no spelling mistakes, the right project name and your manager's own sign-off. In this exercise you watch a campaign being built from two public pages, then receive it yourself by email and by text. You practise judging the request rather than the writing, verifying on a channel you already had, and reporting the half your mail client cannot see.
What You'll Learn in AI-Written Phishing
- Recognise that spelling, grammar and a familiar tone are no longer evidence a message is genuine, because generated text is fluent by default
- Identify what an attacker can build from ordinary public pages: a team directory gives the address pattern and the hierarchy, a department post gives the project name, the deadline and the sign-off
- Treat the same request arriving on a second channel as one unverified sender rather than as confirmation of the first message
- Verify a request through a route you already had, such as a saved number or the team chat, never through a contact detail the message supplied
- Read the sending address rather than the display name, and recognise that a valid certificate on a lookalike domain proves ownership of that domain and nothing else
- Report a suspicious message even when you did not click, and report the channels your mail client never sees, such as a text or a call
AI-Written Phishing — Training Steps
-
Somebody Else's Team Page
Bob is after Ilverstone Logistics, a freight forwarder with a supplier portal its operations desk signs into every day. He does no scanning and breaks into nothing. He starts with the part of the company that is already published.
-
Forty-Six Names and a Pattern
The directory is there so carriers and suppliers can reach the right person. It also hands a stranger the whole department.
-
How He Writes
Daniel Okafor posts a department update most Thursdays. The latest one is linked from his own team page.
-
Project Lantern, and Onwards, D.
Four hundred words of internal detail, published because it is genuinely useful to customers and carriers. Bob reads it as a specification.
-
The Studio
Bob does not write the lure. He rents a service that does, priced per campaign, with the delivery list and the collector built in.
-
Add the Second Channel
Email alone gets read and ignored. A text from a different number, arriving half an hour later about the same thing, makes the email feel answered for.
-
Feed It the Profile
Everything the brief needs came off two public pages, and none of it took longer to collect than reading this step.
-
Read What It Wrote
It takes about four seconds. There is no broken English to notice, because no part of this was written by somebody working in a second language under time pressure.
-
Launch
Ninety-two messages to forty-six people, on two channels, from a domain registered yesterday. The whole job has taken Bob about twenty minutes.
-
Everything Delivered
Nothing bounced and nothing was filtered. The sending domain has no history at all, which is exactly why no reputation system has anything bad on it yet.
Security Framework Coverage
MITRE ATT&CK
- T1566.002 Phishing: Spearphishing Link
- T1566.003 Phishing: Spearphishing via Service
- T1598.003 Phishing for Information: Spearphishing Link
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind