You get an email from your bank. The logo is crisp, the greeting uses your real name, and it references a payment you actually made last week. It asks you to confirm a "flagged" transaction by clicking a button. Nothing about the writing feels off — no clumsy grammar, no "Dear Valued Customer," no obvious misspelled address. Your thumb hovers over the link.

This is the moment that has quietly changed. For years, the advice for spotting a phishing email was simple: look for bad spelling, weird phrasing, and generic greetings. That advice is now close to useless. Attackers have handed the writing over to the same kind of AI models the rest of us use to draft emails, and the results are clean, personal, and convincing.

The old rule — "just look for bad grammar" — is the single most dangerous habit you can carry into 2026.

The good news is that phishing still has a hard limit no amount of polish can hide: it needs you to do something. Understanding what that something always looks like is a far more reliable defense than hunting for typos.

Why the typo era is over

The shift happened fast. According to threat-detection data from the security firm Hoxhunt, the share of reported phishing attacks that were AI-assisted jumped from around 4% in November 2025 to 56% that December, then settled at roughly 40% through early 2026. In plain terms: a large chunk of the phishing hitting inboxes today was written or refined by a machine.

That matters because the machine is good at exactly the things that used to give scams away. It produces fluent, natural sentences in any language. It adapts tone to sound like a coworker, a landlord, or a delivery company. And when attackers feed it details scraped from your public profiles or a company website, it can reference your real job title, your actual colleagues, or a project you're genuinely working on.

The result is a message that passes every instinct built for the old world. You can no longer treat "it reads professionally" as evidence that something is safe. If anything, a suspiciously perfect message that pushes you to act is more worth pausing over than a sloppy one.

The one thing every phishing attempt has in common

Strip away the technology and every phishing attempt, AI-written or not, wants one of three things: your credentials, your money, or your access. To get any of them, the message has to make you take an action — click a link, scan a code, open an attachment, reply with information, or approve a login.

That's the anchor. Instead of asking "does this look fake?", ask "what is this message trying to get me to do, and does that make sense?" A real shipping notice tells you where your package is; it doesn't need your card number. Your bank may alert you to fraud, but it won't ask you to "verify" your full login by typing it into a linked page. When the requested action doesn't match what the sender would realistically need, the polish stops mattering.

This reframing is powerful because it survives every upgrade in the attacker's toolkit. Better grammar, a cloned voice, a spoofed logo — none of it changes the fact that a legitimate organization almost never needs you to urgently hand over secrets through a link in an unexpected message.

Check the sender's real address, not the name

Your email app shows a friendly display name — "Netflix Billing," "IT Support," your boss's actual name. That name is trivial to fake. The part that's harder to fake, and the first thing worth checking, is the actual domain the message came from and the actual destination of any link.

On a computer, hover your cursor over a link (don't click) and read the address that appears at the bottom of the screen. On a phone, press and hold the link to preview it. You're looking at the domain — the part right before the first single slash. mybank.com/login is the real bank. mybank.secure-verify.com is not, because the true domain there is secure-verify.com. Attackers rely on you skimming the familiar word at the front and missing the stranger attached to the end.

Do the same with the sender address itself. A message from support@paypa1.com (with the number one standing in for the letter L) or billing@paypal-support-team.com is wearing a costume. When in doubt, don't trust the address in the message at all — open a new browser tab, type the company's website in yourself, and log in there. If there's a real alert, it'll be waiting in your account.

New tricks: QR codes, texts, and voices

Because email filters and savvier users have made classic email phishing harder, attackers have moved to channels where your guard is lower.

QR codes — sometimes called "quishing" — are a favorite. A poster, a parking meter sticker, or an email attachment shows a QR code that leads to a fake login page. It's effective because there's no text link for a filter to scan, just an image, and because people scan codes without thinking. Treat an unexpected QR code the way you'd treat an unexpected link: with suspicion, and never as a way to log into anything sensitive.

Text messages ("smishing") and phone calls are surging too, often with AI voice cloning. A text about a "failed delivery" with a link, or a call that sounds like your bank — or even a voice resembling someone you know — asking you to move money or read back a code. The specific tell here is a request to act urgently combined with a push to stay in that channel. Which leads to the single most useful habit you can build.

Verify out-of-band, every time

If a message asks you to do something consequential — send money, reset a password, share a code, approve a payment — stop and confirm it through a completely different channel that you choose.

Got an urgent email from your CEO about a wire transfer? Don't reply to the email. Call or message them using a number you already have. Got a call from "your bank"? Hang up and call the number printed on the back of your card. Got a text about a package? Go to the courier's official app or website directly. The key word is out-of-band: never use the phone number, link, or reply button provided by the suspicious message itself, because those lead straight back to the attacker.

If a request is real, verifying it costs you thirty seconds. If it's fake, those thirty seconds save you.

This one habit neutralizes nearly every advanced attack, including the voice clones and flawless emails that break the older rules. It works precisely because it doesn't depend on you detecting the fake — it just refuses to trust any single channel for anything that matters.

A quick mental checklist

When a message asks you to act, run it through four fast questions before you touch anything:

  • What is it asking me to do? Click, scan, pay, log in, reply with info? Name the action.
  • Does the sender realistically need that? A courier doesn't need your password; a bank doesn't need it typed into a linked page.
  • Is it pushing urgency? "Act now or your account closes" is pressure designed to skip your thinking.
  • Have I confirmed it independently? If it's important, verify through a channel you picked yourself.

None of these rely on spotting a typo or a broken logo. They hold up whether the message was scrawled by a careless amateur or generated by a model that writes better than most humans.

The takeaway

Phishing didn't get smarter so much as better-dressed. The scams of 2026 look and sound legitimate in ways that would have been science fiction a few years ago, and the comforting old signals — bad grammar, obvious misspellings, generic greetings — have quietly expired. Clinging to them gives you false confidence, which is exactly what an attacker wants.

The defense that lasts isn't a sharper eye for fakes; it's a steadier set of habits. Read the real domain, not the friendly name. Ask what action a message wants and whether that action makes sense. And when something important is on the line, verify it through a channel you trust and chose yourself. Do those three things and it barely matters how convincing the message is — you've stopped relying on being fooled or not fooled, and started relying on a process that doesn't blink.

Stay a little skeptical of anything that's in a hurry. In a world of perfect-looking messages, calm is your best security tool.