SOCIAL ENGINEERING

AI Phishing Guide: How To Spot and Stop Machine-Written Scams

Hands using a laptop with code on screen, transformed into a dark red AI-phishing threat scene
Phishing illustration — convincing machine-written messages can arrive faster, at greater scale and with better personalisation.

AI can remove many of the sloppy clues people once used to recognise phishing. A message can be polished, personal and convincing while still trying to steal a password, payment or one-time code.

DEFENSIVE BRIEFWHEN BAD GRAMMAR DISAPPEARS, PROCESS BECOMES YOUR DEFENCE

This page focuses on protection, continuity and recovery. It does not provide instructions for carrying out cyber intrusion.

The immediate answer

Do not ask whether a suspicious message “looks AI-generated.” Ask what it wants you to do. Any unexpected request to sign in, transfer money, reveal a code, install software or act under pressure should be independently verified through a known channel before you touch the link or follow the instruction.

Stop judging only by writing quality

Spelling mistakes and awkward language are no longer reliable warning signs. Modern scam messages can copy tone, formatting and public information about a person or company. Instead, judge the request: is somebody asking you to sign in through a link, change bank details, reveal a code, install software or act under unusual time pressure? The more consequential the action, the more important it is to verify through a separate route.

Check the channel independently

Do not use the phone number, link or reply address supplied inside the suspicious message to verify it. Open the organisation’s official app, type the known website yourself or call a number from an existing statement or card. For a colleague or relative, contact them using a saved number. The goal is to break the attacker’s control of the conversation rather than trying to outsmart the wording.

Use login methods that are harder to phish

Where supported, passkeys substantially reduce the risk of credential phishing because there is no reusable password to enter into the fake page. Otherwise use a unique password and two-step verification. Never approve an unexpected login prompt or read a one-time code to an unsolicited caller. If a service offers login alerts, enable them and review unfamiliar sessions promptly.

Create a payment-change rule for the household or business

Changes to bank details, urgent transfers and unusual purchases should require independent confirmation. Small businesses can require a second person or a known-number callback before changing supplier payment information. Families can use the same principle for emergency money requests. AI makes a convincing impersonation easier; a fixed process makes the attacker’s performance less relevant.

If you clicked, act quickly without hiding the mistake

Close the suspicious site, run an appropriate security scan if software may have been installed, and change any password you entered from a trusted device. If the password was reused, change it on the other accounts too. Contact the bank immediately if money or card details are involved. Reporting early is more useful than feeling embarrassed. Attackers benefit when victims delay because they hope the problem will disappear.

Reduce the information attackers can use against you

Review what personal and business information is publicly visible. Job titles, supplier names, travel plans and family relationships can all make a phishing message more believable. You do not need to disappear from the internet, but unnecessary detail increases the material available for social engineering. Combine sensible privacy settings with a verification routine so even a highly tailored message still meets the same barrier before action.

Evidence desk

The defensive guidance on this page uses current UK cyber-security advice. Where the page discusses AI-driven escalation or autonomous attack chains, that material is labelled as scenario analysis rather than presented as a guaranteed future event.

OFFLINE FALLBACK

Cyber resilience is part of household resilience.

The 72-hour field manual covers power, communications, money, food, water and the paper information you need when digital systems stop cooperating.

FREE 72-HOUR SURVIVAL GUIDE

Continue

More Cyber & Digital Resilience guides → · Cyber and preparedness tools →

FREE 25-PAGE FIELD MANUAL

Your first 72 hours should not live in your head.

Turn the advice into a written household plan: water, power, food, communications, health continuity, information verification and movement decisions.

FREE 72-HOUR SURVIVAL GUIDE