The Attack That Never Gets Old
Phishing — fraudulent messages that impersonate trusted entities to steal credentials, financial information, or access — remains the most consistently successful attack vector against individual users and organisations in 2026, despite being one of the most widely discussed security threats. The persistence isn’t because users haven’t heard of phishing; it’s because the attacks have evolved significantly from the Nigerian prince emails that established phishing as a cultural reference. Modern phishing is personalised, contextually specific, and increasingly AI-assisted in ways that defeat the ‘look for poor grammar and suspicious links’ advice that was adequate ten years ago.
Understanding how phishing has evolved in specificity and sophistication produces better recognition of current attacks than applying pattern matching to tactics that have been superseded.
AI-Generated Phishing: The Grammar Tell Is Gone
The most reliable historical tell of phishing messages — poor grammar, awkward phrasing, spelling errors — has been largely eliminated by AI writing tools. Phishing messages generated by or edited with AI assistance are grammatically fluent and stylistically appropriate for their impersonation target. The grammatical quality of a message is no longer a reliable signal of its legitimacy.
The practical implication: the old advice to ‘look for grammar errors’ should be deprioritised as a phishing signal in favour of the signals that AI assistance can’t fake. The domain name in the sender’s email address (not the display name — the actual email address), the URL that the message is directing you to (hover before clicking on desktop; copy and paste on mobile to inspect), and whether the request is something the claimed sender would actually send through email (would your bank email you requesting that you confirm your full account number?) are more reliable tells than grammar quality.
Spear Phishing: The Personalised Attack
Generic phishing sends the same message to thousands of recipients hoping some percentage will take the bait. Spear phishing targets specific individuals with personalised messages that use information about the target — their name, their employer, their role, their recent activities — to create a convincing impersonation. The message that says ‘Hi [your name], as discussed in yesterday’s team meeting about the [specific project name] deliverable, please review and approve the attached document by end of day’ is more convincing than a generic IT department message.
This personalisation information comes from LinkedIn profiles, company websites, data breaches that exposed email addresses and organisational affiliations, and social media that reveals activities, connections, and context. The person with a detailed LinkedIn profile, an active Twitter/X presence, and public conference speaker information has provided the ingredients for a convincing spear phish. This isn’t an argument to delete your professional presence — it’s context for understanding why phishing messages are increasingly specific rather than generic.
QR Code Phishing: The Vector That Bypasses Link Scanning
QR codes in phishing messages (quishing — QR code phishing) have grown as an attack vector because they bypass the link-scanning security controls that detect known malicious URLs in email. Email security systems can inspect text hyperlinks; they can’t easily inspect the destination of a QR code image embedded in a message. A phishing email that would be blocked if it contained a direct URL link to a phishing site may not be blocked if it contains a QR code that encodes the same URL.
The recognition approach for QR code phishing: apply the same scepticism to QR codes in emails and messages as to links. Before scanning a QR code in an unsolicited email, ask whether the organisation sending it would use a QR code for this type of request, and use a QR code scanner that shows the destination URL before navigating to it (most mobile QR scanners show the URL before opening the browser — verify the domain is what it should be before proceeding).
Voice and Video Phishing in the AI Era
The emerging phishing frontier is voice and video: AI voice synthesis that convincingly replicates a known person’s voice is now accessible enough to be used in attacks, and AI video synthesis (deepfake video calls) is advancing to where real-time video impersonation is becoming feasible. The ‘CEO fraud’ call that was previously limited by the need to find someone who could convincingly impersonate the target’s voice is now potentially achievable with synthetic audio.
Verification practices for high-stakes requests: any request for financial action or credential sharing received via phone call or video call from someone claiming to be a colleague or executive should be verified through a separately established contact channel before acting. Calling back on a number from the company directory (not a number provided in the call), or sending a message through the organisation’s messaging system to confirm, provides verification that synthetic audio impersonation can’t bypass. The verification step feels unnecessary until it prevents a significant fraud — establishing it as routine before the attack arrives is the right time.
