“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
AI phishing attacks are phishing scams where criminals use artificial intelligence to write the message, clone a voice, or fake a face. Generative AI produces flawless, personalized emails, texts, and phone calls at scale, stripping out the typos and awkward phrasing that used to give scams away. The tactic is decades old. What changed is how convincing it has become.
The scale is not theoretical. The FBI’s Internet Crime Complaint Center took in 1,008,597 complaints in 2025 and logged nearly $21 billion in losses, with phishing and spoofing among the most frequently reported crime types. More than 22,000 of those complaints specifically flagged artificial intelligence, accounting for over $893 million in reported losses.
This article covers what these attacks are, how they’re built, why the advice you were taught no longer works, the signals that still do, and what to do if you already sent the money.
An AI phishing attack is any phishing attempt where artificial intelligence produced or personalized the bait. The goal has not changed. Someone wants your password, your money, or your access. What changed is the production quality.
Traditional phishing was a numbers game. Send a million ugly emails, catch the few hundred people who didn’t look closely. AI phishing is a precision game run at volume, which is a combination that did not exist five years ago.
Here is the practical difference:
| The old tell | What 2026 messages actually do |
|---|---|
| Broken grammar, odd spelling | Clean, native-fluency writing in any language |
| "Dear Valued Customer" | Your name, your job title, your manager's name |
| Obviously fake sender address | Lookalike domain with a single swapped character |
| One generic template blasted out | Thousands of variants, each written for one person |
| Email only | Email, text, WhatsApp, phone call, video call |
AI phishing scams show up in three delivery forms: AI-generated phishing emails, cloned-voice phone calls, and deepfake video calls. Most people still picture only the first one, which is exactly why the other two work so well.
AI is used at four points in the attack: research, writing, impersonation, and infrastructure. Each step used to take a skilled human hours. Now each takes minutes.
Research. Attackers feed public information into a language model. Your LinkedIn, your company’s about page, a conference bio, a press release naming your CFO. Out comes a dossier: who reports to whom, who signs off on payments, what your team calls its projects.
Writing. That dossier becomes the message. The email references a real vendor, a real deal, a real deadline. The FBI has warned publicly that criminals exploit generative AI to commit fraud at larger scale and with increased believability, because the tools reduce the time and effort required to deceive a target. You can read the full alert in the FBI’s public advisory on AI-assisted financial fraud.
Impersonation. Thirty seconds of someone’s voice from a podcast, a webinar, or a voicemail greeting is enough to clone it. Video cloning takes more source material but is no longer rare. This is the same category of synthetic media our team examines in investigations into cloned voices and manipulated media, where we run frame-by-frame video inspection, waveform and cadence analysis, and metadata review to establish whether a file was machine-generated.
Infrastructure. AI writes the lookalike login page too. It clones your bank’s CSS, spins up a domain that differs by one character, and sits between you and the real site to capture your session after you pass multi-factor authentication.
A useful way to think about it: AI did not invent the lock pick. It built the factory that turns out ten thousand of them an hour, each one shaped to a specific lock.
Four scenarios account for most of the high-dollar cases that reach us. Phishing and spoofing remain among the most reported complaint categories at the FBI’s IC3, and these are the shapes they take when real money moves.
Real estate closing fraud. An attacker sits inside an email thread between a buyer, an agent, and a title company. Days before closing, updated wiring instructions arrive. The tone matches. The signature block matches. The account number does not. Six-figure down payments disappear this way every week.
Vendor invoice and ACH redirect. A supplier you have paid for years emails to say their banking details changed. The message is written in that supplier’s exact house style because AI was trained on the previous eighteen months of real correspondence pulled from a compromised inbox. Cases like this fall squarely into the wire fraud and business email compromise work our investigators handle.
The executive voice call. A finance manager gets a call from the CEO. Right voice, right accent, right verbal habits. Urgent transfer, confidentially, before end of day. The person on the line is a model running on someone’s laptop.
The credential harvest. A security alert says a suspicious login was detected. The link goes to a login page that is pixel-identical to the real one. You type your password and your one-time code, and the attacker relays both to the genuine site in real time.
Because the typos are gone, and the agency that teaches phishing awareness to the federal workforce now says so directly. CISA’s own consumer guidance notes that poor grammar and misspellings used to be a common sign, but that in the era of artificial intelligence many phishing emails now have perfect grammar and spelling, so people need to look for the other signals instead. That guidance is worth reading in full on CISA’s phishing recognition page.
Security professionals have reached the same conclusion. Sophos global field CISO Chester Wisniewski told Axios that training people to avoid emails that look suspicious no longer works for anything, since real messages contain grammatical errors because humans write badly, while the machines never do.
Every phishing awareness poster printed before 2023 is now teaching a test the attacker passes automatically.
You stop grading the writing and start checking the request. Six signals still hold up:
The single highest-value habit costs about ninety seconds. Ethical hacker Rachel Tobac calls it polite paranoia: when a message asks for money or credentials, you contact the sender through a number or address you already had, and ask whether they sent it. In her red team work, that habit is what catches her.
Call the number on the back of your card, not the number in the email. Walk to the desk. Use the thread you already trust.
Not sure whether the message in front of you is real?
A second set of eyes costs you nothing but a phone call, and it is a lot cheaper than a wire you cannot recall.
Ask an investigator about a suspicious message
Confidential consultation. Southern Recon Agency is a Florida-licensed private investigation agency, License #A-1400197.
Move in this order, and move today. Recovery odds fall sharply after the first 24 to 48 hours.
Often, yes. The AI writes the message, but it does not erase the plumbing underneath it.
We start with email headers and metadata, which reveal originating servers, relay paths, and timing that the visible message hides. From there we look at domain registration and IP ownership for the lookalike site, then follow the money through banking analysis and international fund tracing. When funds convert to cryptocurrency, blockchain analytics and open-source intelligence can connect wallets to exchanges, and exchanges to real names through subpoena.
The credentials behind that work matter when a case ends up in front of a judge. Southern Recon Agency’s forensics team includes Certified Digital Forensics Examiners (CDFE) and Certified Ethical Hackers (CEH), and every finding is documented for court, not just for your peace of mind.
We have been doing this longer than the AI has. Our first identity theft case involved one of our own senior investigators, who found 21 unauthorized attempts to open credit lines in his name. Within a week our team had identified the person responsible and photographed her home and license plate for the police report. The tools have changed since then. The method, follow the trail until it ends at a person, has not. That same discipline drives our work on stolen identities and credential misuse.
Companies get attacked through their relationships, not just their inboxes. Thread hijacking inserts an attacker into an existing conversation, so the fraudulent message arrives inside a chain you have been reading for weeks. Vendor impersonation exploits the fact that your accounts payable team trusts a supplier’s letterhead more than it trusts a verification call.
And sometimes the exposure starts inside. Compromised executive communications, cloud misconfigurations, and unmonitored access logs give attackers the raw material AI needs to sound convincing. That is the reason we pair phishing response with insider threat audits for executive and legal teams.
If the attack involved synthetic video or audio, the legal picture matters too. We covered where federal and state law now stand on synthetic media in a separate guide.
What is an AI phishing attack?
An AI phishing attack is a phishing attempt where criminals use artificial intelligence to generate the message, clone a voice, or produce fake video. The goal is the same as traditional phishing, which is stealing credentials, money, or access. AI simply makes the deception more personalized and much harder to detect.
How do hackers use AI for phishing?
Hackers use AI to research targets from public sources, write flawless personalized messages, clone voices from short audio samples, generate deepfake video, and build convincing fake login pages. Work that once required hours of human effort now takes minutes, which lets attackers run highly targeted campaigns at large volume.
Can AI-generated phishing emails get past spam filters?
Yes. AI-generated phishing emails frequently bypass filters because they contain none of the patterns filters were built to catch. Many are sent from compromised legitimate accounts that pass authentication checks, and each message is unique, so signature-based and reputation-based detection has nothing familiar to flag.
How can I tell if a phone call is a voice clone?
Ask a question only the real person could answer, such as a detail from a recent shared conversation. Cloned voices reproduce tone and accent but cannot improvise from real memory. Then hang up and call back on a number you already had saved, never a number provided during the call.
Can you recover money lost to an AI phishing scam?
Sometimes, and speed decides it. If the fraud is reported within hours, banks may be able to recall or freeze the transfer before funds are moved. Once money passes through multiple accounts or converts to cryptocurrency, recovery becomes considerably harder but is not always impossible.
Should I report an AI phishing attempt, and to whom?
Yes. Report it to the FBI’s Internet Crime Complaint Center at ic3.gov, notify your bank if any financial information was exposed, and file a local police report if money was lost. Reporting creates the documentation your bank, insurer, and any investigator will need.
If money already moved, or you need to know who was behind the message, the first 48 hours matter more than anything you do later.
Our investigators trace the breach, follow the funds, and document findings that stand up in court.
Start a confidential case review
Florida-licensed private investigation agency, License #A-1400197. Call (844) 307-7771 or reach the team online.