The phishing email that gave itself away with a typo and a logo in the wrong shade of blue does not exist anymore, at least not the ones causing real damage. AI writes cleaner English than most of the people it is trying to fool, and that single fact has changed what phishing prevention for businesses requires.
I have been doing this long enough to remember when spotting a phishing email took about ten minutes of training, mostly checking the sender address and glancing at the logo to see if it looked slightly off. None of that holds up reliably anymore.
What Changed
A large language model can write a flawless email in the exact tone of your firm’s biggest client, because it was trained on millions of real emails that already sound exactly like that. It can pull someone’s actual name, title, and recent activity into a message that reads like it came from a person who genuinely knows them. There is no broken translation anywhere in the process anymore, so none of the old tells apply.
Voice cloning takes a few seconds of audio, sometimes lifted straight from a firm’s own promotional video, and turns it into a convincing phone call. I have talked to colleagues in this industry who have had a client call in a panic because they got a voicemail that sounded exactly like their managing partner asking for an urgent wire transfer. It was not their managing partner.
Video is not far behind the voice. A convincing deepfake used to require real production time and a decent budget, and a few minutes of footage from a firm’s own website or a conference recording is often enough now. I do not expect video calls to become an unreliable way to verify identity within the next year or two, but firms need to plan for that shift now rather than after it happens to them.
Why Professional Services Firms Are a Better Target Than Ever
Law firms move money for real estate closings and accounting firms move client funds during tax season. Property management firms process rent and vendor payments every single month on top of that. All three run on the same vulnerability: a wire transfer or an ACH request that is one convincing email away from becoming someone else’s payday.
Real estate closing fraud has been a known problem in this industry for years, well before AI made the emails better written. A buyer gets a message that looks exactly like it came from the title company, with wiring instructions changed at the last minute. AI mostly made the email itself harder to catch, which means the same old scam now clears the one filter, sloppy writing, that used to catch a meaningful share of these attempts.
I have watched this play out with a property management client of mine. Someone emailed posing as a tenant, asking to redirect a security deposit refund to a new bank account, and used the tenant’s actual name along with a real unit number pulled from a public rental listing. Our procedure caught it because nobody moves money at that firm without a callback first, but the email itself would have fooled almost anyone reading quickly.
The old advice to trust but verify assumed you could verify by picking up the phone and recognizing a voice. That assumption does not hold anymore, and firms still operating on it are exactly the ones an AI-generated phishing attempt is counting on catching off guard.
Cybersecurity Training for Employees Has to Change Too
Most cybersecurity training for employees still teaches pattern recognition on artifacts that no longer reliably exist. People get trained to spot a bad logo or a misspelled domain, then walk straight past a message that has neither, because the person who wrote it didn’tt make either mistake. Security awareness training in 2026 has to teach a different skill entirely: pausing on urgency itself, regardless of how polished the message looks.
I tell clients the goal is not to become suspicious of every single email. That is exhausting, and nobody sustains it for more than a week. The actual goal is one specific habit around money and access requests: if it involves moving funds or changing account details, verify it through a channel you already know is real before doing anything else.
What This Looks Like in Practice
A callback procedure on a phone number you already have on file, not one provided in the email or voicemail asking for money, stops most of this cold. Dual sign-off on any wire transfer or account change removes the single point of failure that one tired employee represents on a busy Friday afternoon. Multi-factor authentication on every account closes the door that a cloned voice or a well-written email can’t open by itself.
None of this requires new technology most firms do not already have access to. It requires deciding, in writing, what your firm’s actual verification procedure is before you need it, not while someone is on the phone pretending to be your managing partner.
None of this is really new, either. Technology built by humans has always failed in predictable ways once the incentive gets big enough, and I have been saying some version of that for longer than AI has existed. What changed is how good the disguise looks. The underlying con is the same one it always was.
The firms that hold up are not the ones with the fanciest security software. They are the ones who built one boring, repeatable habit around verifying anything involving money, and stuck to it. Pick one financial process at your firm this week – wire transfers, vendor payments, whatever moves the most money – and write down exactly how your team is supposed to verify a request before acting on it.
If you need help with training or have questions surrounding this issue, let’s talk.


