Cybersecurity
How AI Is Making Phishing Harder to Spot And What NJ Businesses Can Do About It
For years, the advice on phishing was simple: watch for bad grammar, odd sender addresses, and generic greetings. That advice no longer holds. Attackers are now using generative AI to write flawless, convincing messages at scale, and the old warning signs are disappearing fast.
7 min read
read
·

For years, the advice on phishing was simple: watch for bad grammar, odd sender addresses, and generic greetings. That advice no longer holds. Attackers now use generative AI to write flawless, convincing messages at scale, and the warning signs everyone was trained to look for are disappearing fast. The scale of the problem is not theoretical. The FBI's Internet Crime Complaint Center reported more than $3 billion in business email compromise losses in 2025, second only to investment fraud, and that year's report carried a dedicated section on artificial intelligence for the first time in the center's nearly 25-year history. The tools changed, and the losses followed.
What Has Changed
AI tools let attackers produce clean, professional, personalized messages in seconds. They can scrape a target's LinkedIn, company website, and public posts, then craft an email that references real projects, real coworkers, and real context. The result is a message that reads exactly like it came from someone you know.
The important shift is not that the emails are prettier. It is that the single most reliable tell, the mistake, is gone. For a decade the standard training was "look for the typos," and it worked because the people sending these emails often did not write English well. That is no longer true. The same writing tools your own staff use to polish an email can be pointed the other way, and they produce a message with the right tone, the right signature, and no error to catch. You are no longer looking for a bad email. You are looking for a normal one that happens to be lying.
The New Threats Businesses Are Facing
Flawless wording: no more typos or broken English to tip you off.
Highly targeted spear phishing: messages tailored to a specific person, role, or deal, using details pulled from public sources.
Business email compromise: convincing requests to change banking details or wire funds, timed to land when a payment is already expected.
Voice and video deepfakes: fake calls or clips impersonating an executive or a vendor to authorize a payment or a change.
Lookalike phone numbers: fake support lines sitting on numbers one digit off from a real business, waiting for someone to misdial their way into a scam call center.
Volume at scale: thousands of customized messages sent with almost no effort or cost.
Business email compromise is the one that empties bank accounts. The pattern is consistent: an attacker watches or gains access to an inbox, learns how the company communicates and who approves what, and waits for a real payment to be in motion, a closing, a large invoice, a scheduled vendor payment. Then a single email arrives asking for the wire to go to a new account, or for the banking details on file to be updated. Nothing about it looks out of place, because it was built to look expected. The FBI notes that the large majority of these losses move by wire transfer, which is exactly why a change to payment instructions deserves more scrutiny than almost any other request your business receives.
Phishing is also the front door for most ransomware incidents. Here is what happens after that first click.
Why Awareness Training Alone Isn't Enough
Telling staff to "look for red flags" stops working when the red flags are gone. Training still matters, a team that understands how these attacks work is far harder to fool, but it can no longer be the only line of defense. When a phishing email is genuinely indistinguishable from a legitimate one, expecting a busy employee to catch it at 4:45 on a Friday is a strategy built on hope. Defense has to move off the individual and into your systems and your processes, so that catching the attack does not depend on one person's judgment under pressure.
What Actually Protects Your Business
Real protection is layered. No single control stops every attack, but together they close the paths attackers actually use. The most effective measures fall into two groups: the technical controls a managed IT provider puts in place, and the human process only your business can enforce.
The technical controls
Multi-factor authentication: stops a stolen password from being enough on its own. This is the single highest-value control for the money, and it should be on email and banking without exception.
Advanced email filtering and anti-impersonation: catches malicious and spoofed messages before they reach the inbox, and flags mail that only appears to come from a known contact.
Email authentication (SPF, DKIM, and DMARC): records configured on your domain that make it far harder for an attacker to send email that appears to come from your company. This is one of the most direct defenses against impersonation, and many small businesses have never had it set up.
Endpoint detection and identity monitoring: detects a compromised account or unusual activity early, before a quiet mailbox intrusion becomes a wire transfer.
The human process
Payment verification: any request to move money or change banking details is confirmed by a phone call to a known number, never a number from the email itself. This one habit defeats most business email compromise, because the fraud only works when nobody checks.
A second approver: wires over a set amount require two people, so no single compromised account or rushed decision can move money alone.
Ongoing, realistic training: test staff against the kind of attacks they will actually see, and teach the new reality, that clean, professional wording is no longer any proof a message is genuine.
If you are not sure which of these you have in place today, that uncertainty is itself the finding. An assessment is the fastest way to see where the gaps are before someone else finds them for you.
Who Should Be Concerned
Every business is a target, but the impact is heaviest where money moves and trust is assumed: finance and bookkeeping staff, executives, and anyone with authority to approve payments or access sensitive data. Small businesses are especially exposed, not despite their size but because of it. Attackers know a smaller company often has fewer controls, no dedicated security staff, and a bookkeeper who can send a wire without a second signature. The attacker is not after your size. They are after one payment, and a wire from a ten-person company clears the same as one from a large firm.
Why Act Now
The cost of building AI-generated attacks has dropped to nearly zero, and the volume is climbing every year. Waiting until after an incident means absorbing the loss first, and once a fraudulent wire has left, it is rarely recovered. The businesses that stay protected are the ones putting layered defenses in place before they are tested, not after.
Nexus Ideal Solutions helps New Jersey businesses defend against modern phishing and email-based attacks with layered security, monitoring, and staff training built around real-world threats, starting with an honest assessment of where you stand.
Frequently Asked Questions
How can I tell a real email from an AI-generated fake?
Increasingly, you cannot tell from the email alone, and that is the point. Stop relying on how a message looks and shift to verifying any request that involves money or account changes through a separate channel, a phone call to a number you already trust. Treat the email as unconfirmed until you have verified it by voice.
Isn't multi-factor authentication enough on its own?
It is essential, but it protects against a stolen password, not against a convincing request. An attacker who never gets into your account can still send an email from a lookalike address asking your staff to act. You need both the technical controls and the human verification habit, because they cover different halves of the same attack.
What is business email compromise?
It is a targeted scam in which an attacker impersonates a trusted party, an executive, a vendor, a client, to trick a business into sending money or changing payment details. It relies on convincing communication rather than a technical break-in, which is exactly why AI-written messages have made it more dangerous. It was the second most costly category of cybercrime in the FBI's 2025 report.
What should I do if we've already sent a fraudulent payment?
Call your bank immediately, because funds can sometimes be recalled within a short window and every hour matters. Then report it to the FBI at ic3.gov. Acting in the first hours gives you the best chance of recovering anything.


