Every morning, millions of people perform the same ritual without giving it much thought: open the inbox, scan the subject lines, and decide which messages deserve attention. It’s a process built almost entirely on instinct. We recognize familiar names, trust company logos, and assume urgent requests are legitimate.
For years, obvious spelling mistakes, awkward grammar, and generic greetings made phishing emails relatively easy to spot. Artificial intelligence is removing many of those telltale signs, allowing cybercriminals to produce polished, personalized messages in seconds. The malware hasn’t necessarily become more sophisticated. The deception has.
Better bait, lower barriers
The Dutch Data Protection Authority’s latest data breach report shows just how effective that deception has become. Organizations in the Netherlands reported more than 39,000 data breaches in 2025, while breaches caused by cyberattacks increased 58% compared to the previous year. Even more concerning, successful account takeover incidents nearly tripled. According to the Dutch regulator, artificial intelligence is helping criminals create personalized phishing emails that are far more convincing than the generic scams many employees have learned to ignore.
The biggest shift is in how attackers get people to install the malware. Generative AI can pull together publicly available information from company websites, LinkedIn profiles, press releases, and social media to create emails that sound like they came from a colleague, executive, customer, or trusted partner. The FBI has warned that criminals are increasingly using AI-generated content to make phishing attempts and other fraud schemes appear more legitimate.
Authority sells
A recently discovered ransomware campaign demonstrates how little technical sophistication is required when the story is convincing enough. Researchers at Bitdefender found attackers who were impersonating Interpol’s cybercrime division. They would send fake investigation notices claiming the recipient’s organization is connected to suspicious activity. The email directed victims to download what appears to be evidence. Instead, the password-protected file installed ransomware that encrypts systems and instructs victims to negotiate payment.
As Bitdefender researchers noted, “One of the biggest red flags in this campaign is the delivery method itself.” Legitimate law enforcement agencies do not distribute password-protected evidence files through unsolicited Proton Drive links.
Why you should care: For years, cybersecurity awareness training taught employees to look for obvious mistakes. That advice is becoming less useful as AI removes many of the clues that once gave phishing emails away. Today, the better question isn’t, “Does this email look suspicious?” It’s, “Was I expecting this request in the first place?”
Organizations should encourage employees to verify unexpected requests through a trusted communication channel, especially those involving credentials, payments, downloads, or sensitive information. Regular phishing exercises, multifactor authentication, endpoint protection, and tested backups remain important layers of defense, but they work best alongside a workforce that knows when to slow down and verify. As the technology continues to improve, organizations that pair strong technical controls with clear communication procedures and well-trained employees will be far better prepared when the next convincing email lands in someone’s inbox. |