
AI Phishing Emails Get Clicked 4x More: Training Your Team for the New Normal
Adam Gleason
Founder & President
May 21, 2026
4 min read
AI Phishing Emails Get Clicked 4x More: Training Your Team for the New Normal
For years, the advice for spotting a phishing email was simple. Look for typos. Watch for clunky grammar. If it reads like it was written by someone who barely speaks the language, delete it. That advice is now actively dangerous, because the attackers stopped writing the emails themselves.
The old tells are gone
Phishing messages generated by AI get click-through rates more than four times higher than the human-written ones they replaced. That is not a small bump. That is a different threat.
The reason is straightforward. Large language models write clean, fluent, professional copy on demand, in any language, in seconds. The misspelled-prince emails are being replaced by messages that read exactly like a note from your bank, your vendor, or your boss. Worse, attackers use these tools to personalize at scale: pulling details from your website, social media, and past breaches to craft a message aimed at one specific person, then doing that across thousands of targets at once. The old trade-off between "convincing" and "high volume" is gone. Attackers now get both.
It is not just email anymore
The same technology that writes flawless emails can clone a voice or fake a face. Deepfake voice and video phishing is climbing fast, and the stakes are not theoretical. In one case, a deepfake video call impersonating company executives convinced an employee to transfer roughly 25.6 million dollars. The employee was on a video call with people who looked and sounded like leadership. Every one of them was fake.
If "I heard their voice" and "I saw them on the call" are no longer proof, your team needs new habits. That is a training problem, not a software problem.
A training playbook for the new normal
You cannot patch human judgment, but you can build better reflexes. Here is the playbook we use with clients.
Retire "look for typos." Teach the team that a perfectly written, professional message is not evidence that it is real. The new red flags are about context and pressure, not spelling.
Teach the real warning signs:
- Urgency and pressure ("do this in the next hour or else").
- Any request to move money, change payment details, or buy gift cards.
- A request that bypasses normal process ("do not loop in accounting yet").
- Sender addresses and links that are almost right but slightly off.
Build a verification habit. This is the single most valuable thing you can install. For any request involving money or sensitive data, verify through a second, known channel. Call the person back on a number you already have, not one in the message. Confirm in person or over a chat tool you trust. Make this the boring default, not a special case.
Make reporting easy and blameless. Your people are your best sensor, but only if they will speak up. Give them a one-click report button and a culture where reporting a suspicious message is praised, even when it turns out to be nothing, and where clicking by mistake gets a calm response, not punishment. Fear makes people hide mistakes, and hidden mistakes are how a small problem becomes a breach.
Run simulated phishing. Send your own safe, realistic test emails on a regular schedule. People learn far more from a controlled "gotcha" than from a slide deck. Track who clicks, give them a quick refresher, and watch the numbers improve over time.
Address the deepfake angle directly. Set a standing rule: large or unusual money transfers always require a verified confirmation through a separate channel, no matter how convincing the call or email. Make it policy so no one has to feel awkward asking.
The quick checklist
- Stop teaching "spot the typo."
- Train on urgency, money requests, and out-of-process asks.
- Verify money and data requests on a second known channel, every time.
- Make reporting one click and blame-free.
- Run regular simulated phishing tests.
- Require verified confirmation for any significant transfer.
The bottom line
The attackers upgraded their tools. Your defenses have to upgrade too, and the most important upgrade is in your people. Technology filters a lot, but the message that slips through is now polished enough to fool a careful person on a busy day. A team with strong verification habits and a healthy reporting culture is the control that actually holds.
Contact G8 at g8support.com and we will help you set up security-awareness training and simulated phishing that fits your team, so a four-times-better attack does not get a four-times-better result.

Adam Gleason
Founder & President
With 27+ years in the IT industry, Adam founded G8 IT to deliver the kind of proactive, reliable, and personal technology support businesses truly deserve. He leads our managed IT, cloud, and cybersecurity engagements.
Talk to a human about this.
We do the work the article describes. Two ways in: