All professional firms
How AI changed phishing, and what to look for now
· PS ProTech · 2 min read
For twenty years, staff were taught to spot a phishing email by its mistakes. Clumsy grammar, a strange greeting, an urgent tone that didn't sound like the sender. That advice is now out of date.
What changed
Attackers use the same AI writing tools everyone else does. The FBI warned in December 2024 that criminals use generative AI to commit fraud at larger scale, and that it removes the spelling and grammar errors that used to give scams away (FBI public service announcement).
The scale is now being measured. For the first time, the FBI's annual internet crime report has a section on artificial intelligence: 22,364 complaints in 2025 mentioned AI, with reported losses of nearly $893 million (FBI, April 2026).
Three things are different in practice:
- The writing is clean. Fluent, well punctuated, and in the right tone for a law firm or an accounting practice.
- The details are right. AI can read a firm's website, its staff's public profiles and its court filings, then write a message that names the right partner, client and matter.
- There are more of them. A message that once took an hour to research now takes seconds, so attackers can target a ten-person firm as carefully as a large one.
It isn't only email
Verizon's 2026 breach report found that in phishing tests, messages arriving by voice call and text got 40% more clicks than those arriving by email (Verizon 2026 summary). People are more guarded at a desk than on a phone. A text that appears to come from a managing partner, sent at 6 pm, gets answered.
What to look for now
Since the writing no longer gives it away, look at what the message is asking you to do.
- A change to how money moves. New bank details, a new payee, an urgent transfer.
- A link to sign in. Especially to email, a document portal or tax software.
- An unexpected attachment from someone who says they are a new client.
- Pressure. A deadline today, a request for secrecy, a reason not to call.
- A slightly wrong address. One letter off the real domain, or a personal address for a business matter.
Any one of these is a reason to stop and check through a different channel: call a number you already have.
What firms should do
Your staff cannot be the only defense against messages built to fool them. Three layers work together:
- Filter the email before it arrives. Email security removes most impersonation attempts and flags the suspicious ones.
- Make a stolen password useless. With multi-factor authentication, a password given away on a fake sign-in page isn't enough to get in.
- Practice. Short lessons and simulated phishing teach staff the new patterns. See security awareness training.
Accounting and tax practices get a seasonal version of this problem, which we cover in tax season phishing.
If you'd like to know how your firm would hold up, our free IT and cybersecurity review covers exactly this.
