We've all seen them: the prince with the frozen inheritance, the undeliverable parcel from a company calling itself Amazoon, the bank that asked us to confirm our details and misspelled its own name.
They taught a generation of us to look for the seams, and for twenty years that worked.
In January 2024 the National Cyber Security Centre (NCSC) published an assessment saying that generative artificial intelligence (AI) would let attackers write lures "without the translation, spelling and grammatical mistakes that often reveal phishing". A peer-reviewed study of 481,558 malicious emails put at least 51% of spam and 14% of business email compromise as machine-written by April 2025, and its authors call that a floor.
There is no bad English left to find.
An email arrives on a Tuesday afternoon at the desk of somebody in accounts. It refers to a document they are expecting, in the tone of the colleague who usually sends it, and there is nothing in the writing to catch.
The link opens a sign-in page for a service they use every day. They type the password. A prompt arrives on their phone and they approve it, because they are the one signing in. Both of those things are genuine and both are satisfied.
The page is a relay. While they were signing in to it, it was signing in to the real service, and what it keeps is not the password. It is the session, the token the service issues to say this person has already proved who they are. Their browser is then handed the document they came for, because from where they are sitting nothing has gone wrong.
Changing the password that afternoon would not have helped. The session was already issued, and it does not care what the password becomes.
The Tuesday and the person in accounts are an illustration. The relay is real, and works the way these kits are published as working.
The prince was not written by an idiot.
In 2012 a Microsoft Research paper by Cormac Herley asked why advance-fee scam emails were so absurd. His answer was that the absurdity was deliberate. Every reply cost the scammer time, so an implausible story worked as a filter and discarded everybody except the few who would go all the way. The bad writing was never incompetence. It was cost control.
Kits and generated text have taken the cost of an attempt close to zero, so the filter has no job left. The cue disappeared because it was never there for our benefit.
The thing to expect, then, is not a flood.
Phishing was the initial access vector in 16% of breaches in Verizon's 2026 report, unchanged on the year before. In the UK, 38% of businesses identified phishing in the last year, down from 42% two years earlier. Verizon's own reading is that AI "can uplift less-experienced groups to a higher baseline" of English, "but that new baseline might not be enough for a higher success rate."
The peer-reviewed trial of automated spear phishing found it drew a 54% click rate against 54% for human experts. It matched them without beating them, on 101 participants in a lab.
The price changed. Expert-quality phishing used to require an expert.
Three things, none about reading the email more carefully.
Sign-in that cannot be phished, on the accounts that would hurt. A relay can pass on a code or a prompt. It cannot pass on a key bound to the device in front of it.
A call to a number already on file before any payment detail changes, and never the number in the email.
A report button that earns thanks rather than blame, because the alternative is somebody who was not sure and said nothing.
A randomised trial across more than 19,500 hospital staff found that annual awareness training had no significant effect on whether people failed a phishing simulation. Over half of the sessions ended within ten seconds. Training straight after a click did better, by 1.7 percentage points. The trial ran in hospitals and counted simulated clicks rather than money.
That is the strongest evidence in this piece, and it cuts at us too. Nobody has run the same test on what we have just told you to do. There is no trial showing that a call-back or unphishable sign-in reduces losses at a thirty-person firm. The case for them is mechanism: a relay cannot pass on a key it does not hold, and a number already on file cannot be changed by an email. That is a better reason than training ever had. It is not the same as proof, and it is worth saying so when a customer asks.
The open question is the one none of this research answers.
Every study here counted the email or the click. None counted the invoice that got paid. If losses to payment diversion are rising while phishing holds at 16% of breaches, the threat has concentrated rather than grown, and the control that matters lives in the finance process rather than the inbox. If those losses are flat, much of what is being written about phishing is a marketing cycle.
UK Finance and the cyber insurers hold the data. We do not.
CMS Distribution distributes the vendors listed here. They appear alphabetically, and none paid for placement or reviewed this article.
The NCSC quotation is from its January 2024 assessment of AI and cyber threat. Machine-written shares are from Hao et al. (Association for Computing Machinery, Internet Measurement Conference 2025), stated as the minimum its authors give. Its emails came from Barracuda's detection data, and Barracuda appears in the panel above. Breach shares are from Verizon's 2026 Data Breach Investigations Report, UK figures from the Department for Science, Innovation and Technology's Cyber Security Breaches Survey 2025/26 (2,112 businesses, self-reported), the click-rate trial from Heiding et al. (Expert Systems with Applications, 2026) and the training trial from Ho et al. (Institute of Electrical and Electronics Engineers, Security and Privacy, 2025). The Tuesday email is an illustration. The photograph is generated rather than taken. No real person appears in it.