Highlights
- Phishing is a cyber scam which tricks individuals into sharing personal information by pretending to be a trusted entity.
- Artificial Intelligence (AI) enables a sophisticated form of phishing, curating persuasive, custom attacks using data readily accessible from public platforms.
- Attackers may mimic an organization's operations or an executive's writing style, using real names, projects, software providers, and events to create fraudulent requests.
- AI reduces the effort and cost of targeted phishing, making it possible to execute personalized scams at a large scale.
- Verification, not believability, should be the new security focus; even if details in a request are accurate, the request can still be fraudulent.
Phishing Attacks
Phishing is the term for a cyber scam where a bad actor pretends to be someone trusted (your bank, a coworker) in order to trick you into revealing private information.
Most of us have learned how to recognize a phishing email. The message begins with “Dear Customer.” And then there is an urgent warning about an account we don’t remember opening. The grammar is strange; a word or two might be misspelled. The logo looks slightly wrong. We’re told to click a link immediately or something terrible will happen.
Those emails aren’t going away, but they’re increasingly the least interesting kind of phishing attack.
Artificial intelligence gives criminals the ability to create much more convincing attacks by combining information that is already publicly available with inexpensive tools for generating emails, text messages, and even voices. The troubling part is that an attacker may not have to hack anything first. Your organization’s website, LinkedIn, Facebook, YouTube, conference websites, press releases, and Google search results may provide most of the information needed to get started.
Consider an ordinary nonprofit called We Care. Its website identifies Susan Miller as the CFO and Mark Daniels as the president. LinkedIn shows that Jennifer works in accounting and has been with the organization for eight months. A recent Facebook post congratulates Mark on being selected to speak at an association conference in Chicago.
None of that information seems particularly sensitive.
But imagine Jennifer receives an email Tuesday afternoon that appears to be from Mark, the president: “Susan is tied up in meetings, and I’m in Chicago for the conference. I need to get the attached invoice handled before I go into the reception tonight. Can you take care of it and send me confirmation?”
Now the message contains three things Jennifer knows to be true. Mark really is in Chicago. Susan really is the CFO. And Jennifer really does handle invoices.
In years past, gathering all those details and writing individualized messages for hundreds of potential victims would have required considerable work. AI can dramatically reduce that effort.
Your Website Can Help an Attacker Write the Email
Organizations often publish precisely the information someone would need to understand how they operate. Staff pages identify executives and responsibilities. News releases announce promotions. Job listings identify software systems. Case studies reveal vendors. Conference pages identify where executives will be next week.
AI makes it much easier to assemble all those individual facts into a coherent picture.
Suppose a company’s careers page says it is looking for someone with experience using Salesforce and HubSpot. Its website identifies the director of marketing. LinkedIn identifies several people working beneath that director.
An attacker now has the ingredients for a plausible message about a Salesforce account, HubSpot campaign, or marketing report. The employee receiving it may think, “How would a scammer know we use HubSpot?”
The answer could be embarrassingly simple: you told them.
The same problem applies to writing style. Executives publish LinkedIn posts, interviews, newsletters, and articles. AI can analyze publicly available writing and generate something much closer to normal professional correspondence than the stereotypical phishing email filled with spelling mistakes.
“Look for bad grammar” therefore isn’t much of a cybersecurity strategy anymore.
The Text Message May Be Even Simpler
A convincing phishing attempt doesn’t need to contain a complicated story.
Imagine an employee named David is attending an industry conference. The organization posts a photograph on LinkedIn that morning: “Our team is excited to be at the 2026 Annual Meeting in Orlando!”
At 4:30 that afternoon, David receives a text:
“David, it’s Karen. I’m heading into the reception and need a quick favor. Are you available?”
That’s it.
The attacker hasn’t asked for money. There isn’t even a link. The first objective is simply to get David to answer.
If David replies, the conversation can continue. Perhaps “Karen” needs him to send something, purchase something, provide a telephone number, or help with an account she supposedly can’t access from the conference.
The public information didn’t have to reveal anything confidential. It only had to make the opening believable.
That distinction is important because employees often think of phishing as someone trying to fool them with false information. Increasingly, the most effective scam may contain a surprising amount of true information wrapped around one fraudulent request.
Then There Is the Telephone
Voice AI introduces another problem.
Organizations put enormous amounts of audio online. CEOs appear on podcasts, executives speak during webinars, companies upload conference presentations to YouTube. Nonprofit presidents record fundraising videos. Pastors post sermons. Association executives appear in promotional videos.
Those recordings can potentially provide material for voice-cloning technology.
Imagine receiving a call from someone who sounds remarkably like your boss. He knows you’re working on the Penske account. He mentions that he’s traveling today, which you already knew. He says he can’t get into the company’s normal system from where he is and asks you to do something unusual for him.
The instinctive reaction is powerful: I know that voice.
Organizations increasingly need to teach employees that recognizing a voice is not the same as verifying someone’s identity.
The same applies to voicemail. An attacker doesn’t necessarily need to maintain a convincing ten-minute conversation. A short voicemail saying, “Tom, it’s me. I’m getting on the plane. Please take care of that payment we discussed, and text me when it’s done,” may provide enough apparent authenticity to support the email or text message that follows.
AI Changes the Economics of Phishing
Highly targeted phishing isn’t new. Security professionals have long used the term “spear phishing” for attacks aimed at particular individuals.
What AI changes is the amount of effort required.
Imagine researching 500 organizations manually. Someone has to visit every website, identify executives, search LinkedIn, find employees, read press releases, discover relationships, and then write individualized messages.
That takes time.
AI is exceptionally good at working with large amounts of ordinary information. It can summarize, categorize, and connect information and generate individualized language from it. Tasks that previously made highly personalized attacks expensive can therefore become much cheaper.
That creates the possibility of something particularly dangerous: personalized phishing at mass-phishing scale.
“But Everything in the Email Was Correct”
This may become one of the biggest challenges for employee security training.
Suppose you receive an email mentioning your boss, your actual software provider, a real project, and a conference your company really is attending next week.
Every one of those details can be correct, and the email can still be fraudulent.
Organizations therefore need to move employees away from asking, “Does this seem believable?” toward asking, “Have I verified this?”
The difference matters.
If your CFO emails unexpectedly asking you to change the bank account used to pay a vendor, call the CFO using the number already in your contacts.
If a vendor suddenly sends new wire instructions, verify them using an established contact.
If the president texts from an unfamiliar number saying he lost his phone and needs something urgently, contact him through another known channel.
If someone who sounds exactly like your boss calls requesting credentials, financial information, or an unusual payment, follow the organization’s verification procedure anyway.
The more convincing the technology becomes, the more important boring procedures become.
Security Now Includes the Information You Publish
This doesn’t mean organizations should stop publishing staff biographies, attending conferences, or posting on LinkedIn. Most businesses and nonprofits need a public presence.
But organizations should begin thinking about publicly available information as part of their security environment.
Before publishing something, it can be useful to ask what the information reveals when combined with everything else already online. Does the website unnecessarily identify exactly who controls payments? Does a staff directory publish direct telephone numbers for every employee? Are executives posting detailed travel schedules in real time? Do job listings reveal more about internal systems than applicants actually need to know?
No single item may represent a serious security problem. The issue is what happens when dozens of small pieces are assembled.
That is exactly the kind of work AI does well.
The New Rule: Accuracy Does Not Prove Authenticity
For years, phishing awareness concentrated heavily on spotting mistakes. Check the spelling. Look at the logo. Watch for strange language. Be suspicious of messages that don’t know your name.
Those remain useful precautions, but they’re no longer enough.
The next generation of phishing may know your name. It may know your boss’s name. It may know where your boss is today. It may know what software your company uses. It may know which conference you’re attending and which vendor you’re working with.
It may even sound like your boss. Yikes!
Accuracy does not prove authenticity.
When a request involves money, credentials, sensitive information, or an unusual change in procedure, independently verify it—even when everything about the message appears to be correct.
Because increasingly, it might be.
AI may be changing the way phishing attacks are created, but the fundamentals of good security remain the same: reduce vulnerabilities, monitor systems carefully, control access, keep software updated, and make it harder for a successful deception to become a successful breach.
New Target Can Help
Phishing protection doesn’t end with teaching employees not to click suspicious links. Organizations also need to prepare for the possibility that eventually someone will. New Target helps clients build that second line of defense through secure managed hosting, continuous website and server monitoring, application and network firewalls, vulnerability scanning, security updates, malware protection, backups, and experienced engineers available around the clock.
If an employee is fooled by an increasingly convincing AI-generated email, text or phone call, strong security around the organization’s website and digital infrastructure can help prevent one human mistake from becoming a much larger incident. In the age of AI-powered phishing, organizations need to protect both the person being targeted and the systems an attacker ultimately wants to reach.
Contact us; we can help.
A global team of digerati with offices in Washington, D.C. and Southern California, we provide digital marketing, web design, and creative for brands you know and nonprofits you love.
Follow us to receive the latest digital insights:
- 6 min read
Phishing Attacks Phishing is the term for a cyber scam where a bad actor pretends to be someone trusted (your bank, a coworker) in order to trick you into revealing...
- 4 min read
Most organizations have a brand long before they have a brand strategy. The problem is that employees describe the organization one way, leadership another, and customers or members may see...
- 12 min read
Headless CMS Freedom Headless CMS implementations are appealing. By separating content management from the presentation layer of a website, organizations gain the freedom to choose how and where their content...
- 6 min read
Marketing automation sounds complicated, but the basic idea is simple: use technology to do repetitive marketing work automatically while making your communications more relevant to the people receiving them....