For years, the easiest way to spot a scam email was the terrible spelling. Not anymore.
AI tools now let scammers write polished, personal, perfectly translated messages in seconds, and send thousands of them. The FBI warns that generative AI can “correct for human errors that might otherwise serve as warning signs of fraud.” So it’s time to update the checklist in your head.
What changed
- No more typos. AI fixes spelling and grammar and translates fluently into any language.
- It’s personal. Scammers can feed AI details from your social media, a data breach or a company website to write messages that mention your name, your boss, your bank or a recent order.
- It’s everywhere. The same tricks now arrive by email, text message, WhatsApp, social media DMs and QR codes.
- It talks back. The FBI says some fake websites now include AI chatbots that keep you chatting and nudge you toward a malicious link.
The new red flags (that AI can’t hide)
AI can make a message look perfect, but it can’t change what the scammer needs from you. So judge a message by what it asks you to do, not by how well it’s written.
1. Unexpected and urgent
A message you weren’t expecting that demands action now: your account will be closed, a payment failed, a package is stuck, a fine is overdue. Urgency is designed to rush you past your own judgment.
2. It asks for something sensitive
Passwords, one-time codes, card details, bank logins, or “just confirm your information.” Real companies don’t ask for these through a link in a message, and nobody legitimate will ever ask you to read back a code they just texted you.
3. The link or sender doesn’t match
Check the actual sender address, and hover over links (or press and hold on a phone) before you tap. Watch for look-alike addresses that swap letters for numbers or bolt extra words onto a real brand name. If in doubt, don’t use the link at all.
4. An unusual way to pay
Gift cards, cryptocurrency, wire transfers or payment apps to someone you don’t know. Payment methods that are hard to reverse are a scammer’s favorite.
5. A change of channel
“Let’s continue this on WhatsApp,” or “Scan this QR code to pay.” Moving you somewhere less protected is a classic step.
6. It plays on emotion
Fear, excitement, curiosity or kindness: a prize, a refund, a romance, an emergency. Strong feelings are the hook.
The one habit that beats AI phishing
Never use the message to check the message. If something seems important, close it and go to the company yourself: type the website address you already know, open the official app, or call the number on your card or statement. AI can fake a message perfectly. It can’t fake your bank’s real app.
Upgrade your defenses
- Use a password manager. It only fills in your password on the real website, so if it refuses to fill on a page that looks right, treat that as a warning sign.
- Switch to passkeys where you can. Passkeys are tied to the real website, so they can’t be phished the way passwords can.
- Turn on two-factor login for your email, bank and social accounts. An authenticator app or passkey is stronger than text-message codes.
- Switch on the free AI protection already built into your email, phone and browser. Our guide AI that protects you walks through each one.
Clicked something you shouldn’t have?
- Stop, and don’t enter anything else on that page.
- If you typed a password, change it right away on the real website, plus anywhere else you’ve used it.
- If you shared card or bank details, call your bank using the number on the back of your card.
- Turn on two-factor login if it isn’t on already.
- If you downloaded something, run your device’s built-in security scan.
- Report it (see below). It helps protect the next person.
How to report phishing
- United States: forward phishing emails to reportphishing@apwg.org, forward scam texts to 7726 (SPAM), and report at ReportFraud.ftc.gov.
- United Kingdom: forward suspicious emails to report@phishing.gov.uk and suspicious texts to 7726.
- Everywhere: use your email app’s “Report phishing” or “Report junk” button instead of just deleting. It trains the filters that protect everyone.
The 10-second check
Before you click, reply or pay, ask yourself:
- Was I expecting this?
- Is it pushing me to act fast?
- Does it want a password, code, payment or personal details?
- Can I check it my own way, without using its link or phone number?
If you weren’t expecting it and it’s urgent or asks for something sensitive, stop and verify it your own way. Every time.
Good writing used to be a sign of a real message. In the age of AI, it’s just good writing. That’s what ShieldNook Superintelligence .si is about: simple habits that still work when scams get smarter. Next, learn how to stop deepfake voice scams with a family code word.
Sources
- FBI Internet Crime Complaint Center: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (December 3, 2024)
- U.S. Federal Trade Commission: How to recognize and avoid phishing scams
- GOV.UK: Avoid and report internet scams and phishing
This guide is general information, not legal or professional advice.