QLAN

Phishing Emails Are Getting Harder to Spot

AI-written messages, researched targets, brand impersonation, and deepfake calls: why phishing is harder to spot today and how a business defends against it.

Abed Farah · Co-Founder & President · · 3 min read

Written by the team that has provided Managed IT Services to Orange County businesses since 1999.

Convincing phishing email open in a business email inbox

Why are phishing emails so hard to spot now?

A few years ago, spotting a phishing email was fairly straightforward. Look for bad grammar, a suspicious sender address, an urgent request for your password. Delete and move on. That advice does not work anymore.

Phishing attacks have changed significantly, and the emails hitting your inbox today are far more convincing than anything we saw even two or three years ago. Here is what is driving that change and what your business should know.

Two definitions before going further. Phishing is a message, usually email, that impersonates someone you trust to get you to click a link, open an attachment, or hand over credentials or money. A deepfake is audio or video generated by AI to imitate a real person’s voice or face closely enough to pass a casual check.

The scale is not abstract. The FBI’s Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in 2024, more than any other crime category, plus 21,442 business email compromise complaints with $2.77 billion in reported losses, out of $16.6 billion in total reported cybercrime losses that year (FBI IC3 2024 Internet Crime Report).

Why does bad grammar no longer give phishing away?

Cybercriminals are using the same AI tools the rest of the world has access to. That means phishing emails are now grammatically perfect, professionally written, and often tailored to sound like they came from someone you actually know. The telltale signs that used to give them away are simply gone.

How do attackers know so much about your business?

Modern phishing attacks often start with research. Attackers will look at your company website, your LinkedIn page, your employees’ public profiles, and data from previous breaches. They use that information to craft emails that reference real projects, real colleagues, or real vendors. An email that says “following up on the invoice from last week” hits very differently than a generic request.

Which brands do phishing emails impersonate?

Phishing emails today routinely impersonate Microsoft, DocuSign, QuickBooks, your bank, and even your IT provider. The logos look right. The formatting looks right. The link looks right until you look very closely. Many people click before they think to check.

Are deepfake calls and videos part of phishing now?

Some attacks have moved beyond email entirely. There are documented cases of employees receiving phone calls or video messages that appear to be from their manager or CEO, asking them to transfer funds or share credentials. What sounds like your boss may not be.

The best documented case is the engineering firm Arup. In January 2024 a finance employee in its Hong Kong office joined a video call in which the chief financial officer and several colleagues were all deepfakes, and approved 15 transfers totaling about $25.6 million (HK$200 million). Arup confirmed the loss in May 2024; the initial contact was a phishing email that appeared to come from the CFO.

How QLAN protects your business

At QLAN, email security is built into how we manage IT for every client. As part of our cybersecurity services, we deploy email filtering that scans incoming messages for malicious links, spoofed senders, and suspicious attachments before they ever reach your inbox. We configure email authentication protocols including SPF, DKIM, and DMARC (the email authentication standards that stop attackers from sending mail as your domain) to prevent your domain from being impersonated. We also enforce multi-factor authentication across your accounts so that even if credentials are stolen, attackers cannot get in.

Beyond the technology, we help train your staff to recognize what modern phishing attempts actually look like today, not what they looked like five years ago. And with 24/7 monitoring in place, if something does get through, we catch it fast and respond before it becomes a serious problem.

The businesses that get hit are not always careless. They are often just working with outdated assumptions about what a threat looks like. Having the right protections in place and a team actively watching your environment makes the difference.

Common questions

Why are phishing emails harder to spot than they used to be? +

Attackers use AI to write fluent, personalized messages and research their targets first, so the classic tells (bad grammar, generic greetings, obvious sender addresses) rarely appear. The email often looks exactly like a real notification from a brand you use.

What should an employee do with a suspicious email? +

Do not click links or open attachments. Verify the request through a channel you already trust, such as a known phone number or the vendor website typed by hand, and report the message to IT so filters can be updated and other staff warned.

Does email filtering stop modern phishing? +

Filtering blocks a large share of attempts but not all of them, because well-crafted messages contain nothing obviously malicious. Filtering, multi-factor authentication, and staff who know what current attacks look like work together; no single layer is enough.

Next step

Find your security gaps before an attacker does.

A senior engineer reviews your environment, identifies exposure, and outlines practical fixes. No pressure, no obligation.