AI can now generate emails that look surprisingly normal.
The grammar is clean. The tone sounds professional. The request may even match something your company actually does.
That creates an interesting security problem:
How do we distinguish a legitimate vendor email from an AI-assisted phishing attempt?
Why traditional red flags are becoming less useful
For years, people were told to look for things like:
- Poor grammar
- Strange wording
- Urgent requests
- Suspicious attachments
- Unprofessional formatting
Those checks are still useful, but AI makes some of these signals much harder to rely on.
An attacker can use an LLM to rewrite an email, improve its tone, translate it into another language, and make the message look more natural.
So instead of asking:
"Does this email sound suspicious?"
We may need to ask:
"Can I independently verify what this email is asking me to do?"
A simple verification workflow
When an email requests something sensitive, I think the safest approach is to separate the email itself from the verification process.
1. Check the sender domain
Don't only look at the display name.
For example:
John from Example Company john@example-company-support.com
Top comments (0)