AI Phishing Tells: What Actually Gives It Away Now
The grammar heuristic is dead. See the real tells of AI-written phishing: leftover prompts, hidden CSS, and domain reputation attackers now borrow.
The grammar heuristic is dead. See the real tells of AI-written phishing: leftover prompts, hidden CSS, and domain reputation attackers now borrow.
AI-written phishing has eliminated the tell security training spent two decades emphasizing: bad grammar. What replaced it is a different set of tells, leftover instructions the model never meant to send, code comments that document their own malicious purpose, and a growing reliance on AI website builders that hand attackers a legitimate platform’s reputation for free. None of these show up in training that still says “watch for typos.”
Table of Contents
ToggleThe claim that AI-written phishing beats the old heuristic is not a training program being cautious. It is a measured result. Researchers at Harvard and MIT, including security researcher Bruce Schneier, tested phishing emails generated automatically by GPT-4 against a control group of generic phishing emails sent to 112 real participants. The study, published in IEEE Access in 2024, found the AI-generated emails achieved a 30 to 44% click-through rate, well above the 19 to 28% the generic control group produced. Grammar and polish were never the point of the old heuristic anyway. They were a proxy for effort, and AI removed the correlation between effort and detectability.
Detection tooling built for the old signal has its own documented blind spot. Independent research by email security firm Egress found that most automated AI-content detectors need a minimum sample of roughly 250 characters to work reliably, and a large share of real phishing emails fall short of that threshold entirely. A detector built to flag “AI-sounding” text is of limited use against a short, targeted lure that never gives it enough text to analyze.
Security researchers across multiple vendors have converged on the same finding: AI-generated attacks leave their own signatures, just not the ones training programs have spent years looking for. The anatomy of a phishing email has not changed at the level of intent, only in the specific artifacts it leaves behind.
Discover how Threatcop protects your workforce from modern cyber threats.
None of these tells require inventing new vocabulary. Each one lines up with an existing, named technique in the MITRE ATT&CK framework, the industry-standard catalog of adversary behavior, which matters because it means detection engineering teams can build rules against a known category rather than a vague sense that “something about this looks AI-generated.”
Framing AI-generated phishing against an existing standard, rather than as a wholly new threat category, keeps detection engineering grounded in rules and signatures that already exist and only need retuning for a faster, cheaper method of production.
A natural question is whether a technical provenance standard could simply label AI-generated content the way a nutrition label labels food. The Coalition for Content Provenance and Authenticity, backed by Adobe, Microsoft, Google, and a large industry coalition, has built exactly this for images, video, and audio: a cryptographically signed record of what created a file and what has touched it since.
It does not yet reach plain-text email. The standard was built for media files, not for the body of a message, and even where it applies, most distribution platforms strip embedded credentials during normal processing before a viewer ever sees them. A provenance label on the phishing page’s hero image would not label the AI-generated phishing email that delivered it, and would not survive most email clients’ handling even if it did. Until that gap closes, the specific AI-generated phishing tells this piece documents, leftover generation artifacts, self-documenting code, homoglyph substitution, hidden filler content, are what defenders actually have to work with, not a trust label.
The most consequential shift is not in the email at all. It is in what the link behind it points to.
Proofpoint’s research team documented large-scale abuse of Lovable, an AI-powered website builder that generates a fully functioning site from a text prompt, for exactly this purpose. Campaigns impersonating Microsoft, UPS, and DeFi platforms were built and hosted entirely on Lovable’s own infrastructure, with researchers noting they could recreate convincing fakes of major enterprise login pages without encountering any guardrails from the platform itself. Similar abuse has been documented on comparable no-code builders, including fake CAPTCHA pages designed specifically to look legitimate to automated scanners.
The mechanism is structural, not a gap in one vendor’s filtering. A URL scanner checks a domain’s reputation, and a page hosted on a legitimate, widely used platform inherits that platform’s good standing by default. The attacker did not compromise the platform. They used it exactly as designed, for a purpose the design never anticipated. Email spoofing and impersonation has always exploited a gap between what a system verifies and what it should verify, and this is the same gap wearing an AI-shaped disguise.
The old “look for typos” heuristic has to be retired outright when facing AI-generated phishing, not supplemented. A polished, error-free email is no longer evidence of anything.
None of this replaces email authentication at the infrastructure level. DMARC configured correctly still stops a large share of direct domain spoofing before a polished AI-written email ever reaches an inbox, which is why the two defenses work as layers, not substitutes for each other.
AI did not make phishing harder to catch. It made a specific, widely taught heuristic obsolete while leaving a different set of tells in its place, ones that live in code comments, hidden CSS, and inherited domain reputation rather than in a misspelled word. Training and tooling that have not updated past “look for typos” are testing employees against a threat model that stopped being accurate months ago, which is exactly the gap phishing awareness and simulation programs need to close before the next refresher cycle rather than after it.
No. Academic research testing GPT-4-generated phishing against generic phishing found the AI-generated emails achieved a meaningfully higher click-through rate, in part because grammatical polish removed a cue employees were trained to rely on. The grammar heuristic is not weakened. It no longer applies.
Leftover generation artifacts the attacker forgot to remove, code comments that over-explain their own logic, systematic Unicode character substitution, hidden filler text designed to fool scanners rather than people, and formatting choices with no real purpose in the medium. None of these are visible from a casual read the way a typo once was.
Most detectors need a substantial sample of text, often 250 characters or more, to analyze patterns reliably. Independent research has found a large share of real phishing emails fall below that length, meaning the detector simply lacks enough text to make a reliable determination on many real attacks.
Phishing pages built on AI website builders bypass security filters because the page is hosted on a legitimate, widely used platform’s own domain, which already has clean domain reputation with URL scanners and email gateways. The attacker did not need to compromise anything. They used the platform’s intended functionality to build a convincing fake, and the platform’s good reputation came with it.
With AI-generated phishing, employees should check the actual destination of a link, verified in the address bar rather than inferred from how professional the page looks, combined with out-of-band confirmation for anything involving credentials, payment, or an urgent request. Behavior-based checks hold up where appearance-based ones no longer do.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Loading an open-source AI model can silently run code nobody asked for. See the real pickle exploits security researchers...
New breach notification laws are tightening cyber insurance underwriting across Southeast Asia. See what mid-market organizations actually need to...
CAN-SPAM fines now reach $53,088 per email. Google and Yahoo enforce their own rules too. See what actually satisfies...
Table of Contents
×