Spotting AI-generated phishing at work
Spotting AI-generated phishing
Spotting AI-generated phishing today means treating the writing as a clue, not a filter. Large language models produce error-free Swiss business German or English, polite openings, and industry terms. Criminals still attach wrong links, wrong channels, and false urgency. The national “SUPER, or?” campaign in 2026, run by BACS with police, Swiss Post, SBB, and partners, focused on that shift (BACS, 13 April to 10 May 2026). NCSC reporting still shows fraud as the largest category of voluntary reports; CEO-style fraud reports rose from 719 in 2024 to 971 in 2025, with more AI-written text and synthetic audio in some cases (BACS weekly review).
This article is for staff and managers in a Swiss SME. Classic checks such as sender domain and link targets sit in how to spot phishing e-mails. Deepfake voice calls are a separate topic.
CEO fraud reports to BACS in 2025, up from 719 in 2024, per the NCSC weekly review. External statistic, not your firm’s count.
What AI changed in the inbox
Speed and variants. New messages appear faster than static training slides age. IT often sees three slightly different texts on the same morning, not one copied template with typos.
Research plus text. Attackers read LinkedIn, your website, and trade register entries, then fill templates with real names. The story feels internal even when the channel is wrong.
Media beside mail. BACS has warned about deepfake pictures and video in fraud cases (week 30/2026). That sits next to mail phishing; voice-led fraud is covered elsewhere.
Signs that often fit AI-written mail
These hints do not replace link checks. They help when grammar is perfect.
Tone that does not match your firm. Finance internally sends two short lines. The mail delivers five polite paragraphs and phrases like “I hope this message finds you well” from someone who is usually blunt.
Explanations a colleague would not need. “As a responsible professional, you understand the importance of data protection” before a link to “review the document”. Real IT notices point at a portal you already use, without textbook wording.
The same shape in several mails. Three messages to different people with the same structure: question subject, one context paragraph, one urgency paragraph, one button. People vary; automated drafts repeat.
Details almost right. Project name correct, department wrong. Title “Leiterin Finanzen” when the person goes by “Head of Finance” on your site. Logo in the signature, phone number from an old imprint.
Language switch without reason. The thread was German; suddenly a polished English paragraph when the other party normally keeps one language.
- Does the mail sound like your IT, HR, or leadership, or like generic business prose?
- Do names and titles come from public sources while the usual channel (Teams, portal, phone) is missing?
- Did several colleagues receive same-shaped mail on the same day?
- Does the text ask for actions your payment or login process forbids?
Links, attachments, and layout despite perfect prose
AI improves the sentence, not the destination. Hover the link or long-press on mobile. “Microsoft” in the visible text and login-microsoft-secure.ch in the URL remain a stop signal even when the paragraph is flawless.
HTML copies Post, bank, or Microsoft 365 layouts. Still check: tax tasks belong on cantonal portals you bookmark, not on a button in unexpected mail. Parcel notices come via the shop or carrier from the purchase, not as urgent mail to info@.
Attachments sometimes have tidy names (“Invoice_Q3_Final.pdf”) but carry macros or “enable content”. Treat them like any other unexpected attachment, regardless of fluency.
Spear phishing with AI: when the story fits too well
Targeted mail names your project, a conference, or a real colleague. AI makes those texts cheaper at scale. Your defence is process, not guessing the tooling.
CEO-style threads often hit finance or assistants. The mail may be flawless. Control stays: second signature, call-back to a known supplier number, no secrecy (“do not tell accounting”). HR and recruiting are another lane: “update payroll details” on a stranger’s link. Keep hiring data in your applicant system.
Mail aimed at one named person in the company is its own pattern. The signs above still apply: check the tone, the structure, and where the link goes before you open it.
A made-up example
A made-up example: At a manufacturing firm in eastern Switzerland, four people receive a “from the CEO” mail on the same morning. Each text is grammatically clean, names a live project from the website, and asks for “discreet” review of a “confidential supplier portal”. Reception notices the CEO never mails from that address, and “discreet” is not in internal payment rules. She forwards to IT without clicking. IT sees the same link domain in all four messages and blocks it. The company is invented; the pattern matches reports where research and AI text combine.
Checks that still work after SUPER 2026
- Open documents and tax tasks only in apps or portals you already bookmarked
- Call back on the number on your contract, not the one in the mail
- Treat any request to bypass four-eyes payment rules as suspicious
- Report internally even when the writing looks perfect
Public material sits on s-u-p-e-r.ch. Your company still needs a reporting line people trust: who owns it, which mailbox applies, how fast IT responds.
What this is not
This is not a guide to blocking ChatGPT in the office. It is not technical filtering advice for Microsoft 365 admins. It also does not replace legal review of monitoring or phishing simulations.
Who can skip the detail
If your organisation already runs frequent simulations with clear rules, use this page as background for new hires. If you have no reporting channel yet, fix that before debating AI nuances.
SMS and voice are part of the same wave
AI text in mail often pairs with smishing or vishing the same week: a parcel SMS after a mail lure, or a follow-up call “from IT”. Treat channels together in awareness, even when training slides still show only e-mail screenshots.
Orientation, not fear marketing
Art. 8 of the Swiss FADP expects appropriate measures for data security; awareness is one organisational measure (fedlex). Training does not by itself make a company “compliant”, but it reduces clicks that lead to breaches. This is orientation, not legal advice.
Still useful
- Wrong domain on the link
- Wrong channel for the topic
- Urgent payment or credential request
Weak on its own
- Obvious spelling errors
- Generic “Dear customer” with no context
- Short lazy templates with no personalisation
Can we trust spell-check and translation tools to spot fakes?
No. Attackers use the same tools. Process and reporting beat proofreading.
Does blocking external mail solve AI phishing?
Suppliers, clients, and job applicants still need to reach you. Training and reporting remain necessary.
Do we have to prove the text is “AI”?
No. Report when the link, channel, or process does not fit. IT needs the .eml file, not your guess about the author.
Awareness session
Security awareness training includes AI-assisted phishing, smishing, and what to report, tailored to your team in a live session.
Written by
Aurum Avis Labs
Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.
Related Articles
You might also be interested in these articles