For years, phishing awareness training taught employees to look for the same red flags: awkward grammar, generic greetings, mismatched sender addresses, urgent demands with obvious typos. That advice was genuinely useful when phishing emails were written by humans without native fluency in the target’s language, working from templates that looked slightly off if you knew what to check.
AI has quietly erased most of those tells. A modern phishing email can be grammatically flawless, written in a tone that matches the supposed sender’s actual style, and personalized with details scraped from LinkedIn, company newsletters, or old email threads. The old checklist doesn’t catch this generation of attacks, and training programs still built around it are teaching employees to look for signals that mostly aren’t there anymore. If any of this sounds unfamiliar for your own team’s training, you can speak with a support specialist to see where the gaps actually are.
What Changed, Specifically
The writing itself got dramatically better
AI tools can now draft a convincing, personalized phishing email in minutes, mimicking a specific person’s writing style if enough of their public communication is available to learn from. The generic, poorly worded phishing email is increasingly the exception rather than the rule.
Voice cloning entered the picture
A short audio clip, sometimes just a few seconds pulled from a podcast, webinar recording, or voicemail greeting, is enough to generate a convincing synthetic voice. Attackers are pairing AI-written emails with a follow-up phone call in a cloned executive’s voice to add urgency and legitimacy to a fraudulent wire transfer request.
Video deepfakes have entered live meetings
The most sophisticated version of this attack involves a live video call with what appears to be a real executive, using real-time deepfake technology. An employee at a major engineering firm authorized a $25 million wire transfer after joining a video call where every participant, including the person who appeared to be the CFO, was AI-generated.
The scale has genuinely shifted
This isn’t a rare, exotic threat anymore. The FBI’s Internet Crime Complaint Center added AI-assisted fraud as a standalone tracking category in its 2025 Internet Crime Report for the first time, logging thousands of complaints and hundreds of millions of dollars in losses tied specifically to synthetic voice and video impersonation. That’s a strong signal that this category of attack has moved from emerging risk to established threat.
Why Traditional Training Falls Short Against This
|
Traditional Training Focus |
Why It No Longer Works |
|
Look for spelling and grammar errors |
AI-written phishing emails are typically grammatically correct |
|
Check for generic greetings |
AI can personalize greetings using scraped public information |
|
Distrust unfamiliar senders |
Attackers now impersonate known, trusted contacts convincingly |
|
Rely on visual or audio verification |
Deepfake video and cloned voices can pass a casual visual or audio check |
|
Annual training session |
A single yearly session doesn’t build the habits needed against evolving tactics |
The pattern across this table is that verification methods people have relied on instinctively (does this sound right, does this look right) no longer reliably work, because those are exactly the signals AI-generated attacks are built to replicate.
What Training Actually Needs to Cover Now
Verification habits that don’t rely on how something sounds or looks
Employees need a standing process for confirming unusual requests, especially financial ones, through a separate, pre-established channel rather than relying on how convincing the call or video looked. A callback to a known number, not the one provided in the suspicious message, is a simple habit that defeats even a highly convincing voice clone.
Awareness that video and voice can now be faked convincingly
Training needs to explicitly cover the reality that a familiar voice or face on a call is no longer sufficient verification on its own, something most existing training programs haven’t caught up to yet.
Frequent, realistic simulation instead of annual sessions
Regular phishing simulations that evolve to reflect current AI-driven tactics build habits far more effectively than a once-a-year training video, since recognizing a threat under simulated pressure is a very different skill than remembering a slide from months earlier.
A clear, low-friction reporting process
Employees need to know exactly how to report a suspicious message or call without friction or embarrassment, since hesitation to report a near-miss often means the same attack succeeds against someone else in the organization shortly after.
Building a Program That Keeps Up
The businesses handling this well tend to treat security awareness training as an ongoing program rather than a compliance requirement to satisfy once a year. That includes updating training content as attack methods evolve, running simulations that reflect current tactics rather than outdated templates, and reinforcing verification habits regularly enough that they become automatic rather than theoretical.
If your team wants a clearer picture of where your current training and verification processes stand against these newer attack methods, our security team can walk through what an updated program would actually look like for your business.
Why the Old Playbook No Longer Protects Anyone
The signals employees were trained to spot for years- awkward writing, unfamiliar senders, generic messages- are increasingly absent from modern phishing attacks. Training has to shift toward verification habits that don’t depend on how convincing something sounds or looks, because AI has made convincing the default, not the exception.



