SOCIAL ENGINEERING
AI Phishing Guide: How To Spot and Stop Machine-Written Scams

AI can remove many of the sloppy clues people once used to recognise phishing. A message can be polished, personal and convincing while still trying to steal a password, payment or one-time code.
This page focuses on protection, continuity and recovery. It does not provide instructions for carrying out cyber intrusion.
The immediate answer
Do not ask whether a suspicious message “looks AI-generated.” Ask what it wants you to do. Any unexpected request to sign in, transfer money, reveal a code, install software or act under pressure should be independently verified through a known channel before you touch the link or follow the instruction.
Stop judging only by writing quality
Spelling mistakes and awkward language are no longer reliable warning signs. Modern scam messages can copy tone, formatting and public information about a person or company. Instead, judge the request: is somebody asking you to sign in through a link, change bank details, reveal a code, install software or act under unusual time pressure? The more consequential the action, the more important it is to verify through a separate route.
Check the channel independently
Do not use the phone number, link or reply address supplied inside the suspicious message to verify it. Open the organisation’s official app, type the known website yourself or call a number from an existing statement or card. For a colleague or relative, contact them using a saved number. The goal is to break the attacker’s control of the conversation rather than trying to outsmart the wording.
Use login methods that are harder to phish
Where supported, passkeys substantially reduce the risk of credential phishing because there is no reusable password to enter into the fake page. Otherwise use a unique password and two-step verification. Never approve an unexpected login prompt or read a one-time code to an unsolicited caller. If a service offers login alerts, enable them and review unfamiliar sessions promptly.
Create a payment-change rule for the household or business
Changes to bank details, urgent transfers and unusual purchases should require independent confirmation. Small businesses can require a second person or a known-number callback before changing supplier payment information. Families can use the same principle for emergency money requests. AI makes a convincing impersonation easier; a fixed process makes the attacker’s performance less relevant.
If you clicked, act quickly without hiding the mistake
Close the suspicious site, run an appropriate security scan if software may have been installed, and change any password you entered from a trusted device. If the password was reused, change it on the other accounts too. Contact the bank immediately if money or card details are involved. Reporting early is more useful than feeling embarrassed. Attackers benefit when victims delay because they hope the problem will disappear.
Reduce the information attackers can use against you
Review what personal and business information is publicly visible. Job titles, supplier names, travel plans and family relationships can all make a phishing message more believable. You do not need to disappear from the internet, but unnecessary detail increases the material available for social engineering. Combine sensible privacy settings with a verification routine so even a highly tailored message still meets the same barrier before action.
Continue from here
Build this topic into a wider plan, then see how the same dependency could fail in an AI-collapse scenario.
Evidence desk
The defensive guidance on this page uses current UK cyber-security advice. Where the page discusses AI-driven escalation or autonomous attack chains, that material is labelled as scenario analysis rather than presented as a guaranteed future event.
OFFLINE FALLBACK
Cyber resilience is part of household resilience.
The 72-hour field manual covers power, communications, money, food, water and the paper information you need when digital systems stop cooperating.
Continue
More Cyber & Digital Resilience guides → · Cyber and preparedness tools →