AnyLearn
All lessons
Businessbeginner

The Tells Are Gone: What Actually Changed About Attacks

Security awareness training taught people to spot bad grammar, odd domains and generic greetings. Those signals are gone. This lesson covers what generative tools changed about attacks, what they did not change, and why detection-based defence was always the weaker half.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

The advice that stopped working

For two decades, security awareness training taught a set of signals. Look for spelling mistakes. Watch for awkward phrasing that suggests a non-native speaker. Check for a generic greeting like Dear Customer. Hover over the link and look for a misspelled domain.

That advice worked because it described real constraints on attackers. Writing fluent, personalised messages at scale was expensive. A criminal sending a hundred thousand emails could not tailor them, and one working in a second language produced text that read wrong.

Those constraints have gone. Fluent text in any language is now free, and personalising each message to its recipient costs almost nothing.

What that means for the training most people have received. The specific signals it taught are no longer diagnostic. Worse, they are actively harmful, because someone who has learned to check for bad grammar and finds none concludes the message is genuine. The training now produces false confidence, which is a worse position than no training.

This is the same structural problem the journalists cursus described about deepfake tells. Any published detection signal is a defect being engineered away, so a defence built on recognising the current generation of attacks decays continuously.

What has not changed is the shape of the request, which the executive assistants cursus set out and which this lesson develops. Attacks still need you to do something. That requirement is what defences should target, because it is structural rather than cosmetic.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. The advice that stopped working

For two decades, security awareness training taught a set of signals. Look for spelling mistakes. Watch for awkward phrasing that suggests a non-native speaker. Check for a generic greeting like Dear Customer. Hover over the link and look for a misspelled domain.

That advice worked because it described real constraints on attackers. Writing fluent, personalised messages at scale was expensive. A criminal sending a hundred thousand emails could not tailor them, and one working in a second language produced text that read wrong.

Those constraints have gone. Fluent text in any language is now free, and personalising each message to its recipient costs almost nothing.

What that means for the training most people have received. The specific signals it taught are no longer diagnostic. Worse, they are actively harmful, because someone who has learned to check for bad grammar and finds none concludes the message is genuine. The training now produces false confidence, which is a worse position than no training.

This is the same structural problem the journalists cursus described about deepfake tells. Any published detection signal is a defect being engineered away, so a defence built on recognising the current generation of attacks decays continuously.

What has not changed is the shape of the request, which the executive assistants cursus set out and which this lesson develops. Attacks still need you to do something. That requirement is what defences should target, because it is structural rather than cosmetic.

2. What the evidence shows

The claim that AI-generated phishing is more effective is often asserted by vendors. There is also research, and it is worth knowing what it actually found.

A study by Fred Heiding, Simon Lermen, Andrew Kim, Bruce Schneier and Arun Vishwanath tested fully automated spear phishing against real participants. AI-generated personalised messages achieved a click-through rate of around fifty-four percent, against roughly twelve percent for a generic control. Messages produced by human experts performed comparably to the automated ones, at roughly thirty times the cost.

Two findings there matter more than the headline.

First, the automated messages matched expert humans rather than beating them. The change is not that attacks became cleverer than the best attackers. It is that the best quality of attack became available at negligible cost, which means it can be used against everyone rather than against high-value targets only.

Second, the study found the models could build accurate profiles of targets from public information for the large majority of people tested. The personalisation that made spear phishing effective was always the expensive part, and it is the part that got cheap.

Vendor data points the same way. Hoxhunt, which runs phishing simulations commercially, reported from its own simulation programme that AI-generated attacks moved from less effective than elite human red teams in 2023 to more effective by early 2025. That is vendor data about vendor simulations, and it should be weighed accordingly, but the direction is consistent with the independent research.

The practical conclusion. Assume every employee, not just executives, can now receive an attack of a quality previously reserved for targeted operations.

3. Personalisation from public information

The mechanism worth understanding, because it explains why a message can be convincing without any breach having occurred.

A great deal about most working people is public. Their employer, role and career history from professional networking sites. Colleagues, and who reports to whom. Conference talks and the topics they cover. Published articles. Company announcements. Social posts about a holiday, a house move, a child starting school. Photographs of an office. Local news.

Assembling that into a profile used to take an attacker hours per target, which limited targeted attacks to targets worth hours. Now it takes minutes, and the profile is accurate for most people.

What that enables, concretely. A message referring to the project you actually work on, from the colleague who actually sits next to you, mentioning the conference you actually attended, arriving on the day your manager is actually on leave, which was visible from their out-of-office or their social posts.

None of that requires any compromise of your systems. It is all published.

Two practical consequences.

The first is that internal knowledge in a message is no longer evidence of legitimacy. That signal, they knew about the project so it must be real, was always weak and is now worthless.

The second is about what organisations and individuals publish. This is worth deciding rather than drifting into, particularly for the things that provide timing: announcements of who is travelling, out-of-office messages naming the person's whereabouts, and posts about senior people being unreachable. The attack arrives during that window, and it is not a coincidence.

The realistic position is not to stop publishing. It is to stop treating specificity as authentication.

4. What changed and what did not

Sorting the attack into the parts that moved and the parts that are the same, because the defence should target the second.

What changed. The quality of the writing, which is now fluent in any language. The degree of personalisation, which is now individual rather than generic. The cost per target, which fell far enough that everyone is worth attacking. The available channels, since convincing voice and video are now cheap. And the languages, so organisations that were partly protected by operating in a less common language no longer are.

What did not change, and this is the important column. The attacker still needs you to take an action. That action is still something irreversible: a payment, a credential, a change of bank details, access to a system, or a document. There is still a reason you must act quickly. There is still a reason not to check with anyone. And the request still arrives through a channel the attacker controls.

The conclusion the diagram is built to support. Every defence in the left column is a losing race, because those properties improve continuously. Every defence targeting the right column holds regardless of how good the generation gets, because it addresses the structure of the fraud rather than its presentation.

That is why the next lesson is about verifying requests rather than about recognising fakes.

flowchart LR
A["The attack"] --> B["What changed"]
A --> C["What did not change"]
B --> D["Fluent writing, any language"]
B --> E["Individual personalisation from public data"]
B --> F["Cost per target near zero"]
B --> G["Convincing voice and video"]
C --> H["Needs you to take an irreversible action"]
C --> I["Needs urgency"]
C --> J["Needs you not to check with anyone"]
C --> K["Arrives on a channel the attacker controls"]
D --> L["Defending here is a losing race"]
H --> M["Defending here holds no matter how good generation gets"]

5. Voice, video, and the collapse of recognition

The change with the widest consequences is not text. It is that recognising someone is no longer evidence of who they are.

Voice cloning now works from a small amount of source audio, and most people with any public presence have provided it. Video is further behind but has demonstrably crossed the threshold for live use, which the executive assistants cursus covered through the Arup case: an employee was deceived by a video conference populated entirely with synthetic colleagues, built from publicly available footage.

What that invalidates. Every process, formal or informal, that relied on recognising a voice or a face. Calling someone back and recognising them. Joining a video call and seeing the person. Approving something because you spoke to them.

Those were reasonable authentication factors for a century, and they are not any more.

The versions that matter in ordinary working life.

A call from a colleague, senior person or supplier requesting something urgent.

A voice note, which people trust more than text and which carries no more assurance.

A video call where the request is made live and the pressure is immediate.

And the personal version, which is worth naming because it is being used at scale: a call from a family member in distress, asking for money urgently. Households need the same protocol as organisations, and agreeing a family phrase costs nothing.

The reframing that follows, and it is the central idea of this cursus. Identity can no longer be established from the media. It has to be established from the channel, which is the subject of the next lesson.

6. Why phishing simulations may be making things worse

Most organisations run simulated phishing exercises, and it is worth examining whether they achieve what is claimed, because the evidence is weaker than the industry suggests.

What they typically measure. Click rates on simulated messages, before and after training. Those rates usually improve, which is reported as success.

Why that is a weak measure. Click rates on simulations reflect how hard the simulation was, and simulations are generally easier than real targeted attacks. Improvement can reflect people learning the pattern of your simulations rather than becoming harder to attack.

And there are documented costs.

Under-reporting. Where clicking has consequences, being publicly named, mandatory retraining framed as punishment, people who click a real attack become less likely to report it. Reporting speed is the single most valuable thing a workforce provides, because it determines whether the incident is contained, and punitive simulation programmes work directly against it.

Erosion of trust. Simulations that mimic redundancy notices, bonus announcements or health information have caused real anger in organisations that ran them, and they damage the relationship the security team needs.

And the wrong lesson. A programme that rewards spotting fakes teaches detection, which this lesson has argued is the decaying defence.

What is worth measuring instead. How fast a real or simulated attack gets reported, rather than how few people clicked. Whether people report after clicking, which is the behaviour that limits damage. And whether the verification habit is actually used, which can be observed in whether callback checks happen on payment changes.

A workforce that clicks occasionally and reports within two minutes is in far better shape than one that clicks rarely and hides it.

7. What the attacker is actually after

Knowing what these attacks are trying to obtain sharpens where the defences should be, because the list is short.

Money, directly. A payment made to an account controlled by the attacker, usually framed as an urgent invoice, a supplier's changed bank details, or an executive instruction. This is the largest category by loss.

Credentials. A username and password, and increasingly a multi-factor code, entered on a page that looks like your login. Note that multi-factor authentication raised the bar without closing this: attackers relay codes in real time through a proxy page, so entering a code on a page you reached from a message provides no protection.

Session access. Increasingly the target is not your password but your active session, obtained by persuading you to approve a prompt or install something. This bypasses authentication entirely because you already authenticated.

Data. Customer records, documents, or the contents of a mailbox, which enables the next attack against someone else.

And a foothold. Something installed that provides access later, where the phishing message is only the first step of an intrusion that develops over weeks.

What that implies for where to concentrate.

Anything that moves money needs verification that does not depend on the requesting channel.

Anything asking for credentials should be reached by navigating there yourself rather than by following a link, which defeats the proxy page entirely.

And any unexpected approval prompt should be denied and reported, because a prompt you did not initiate means someone else has your password already.

That last one is worth internalising. An unexpected multi-factor prompt is not an annoyance. It is a live report that your credentials are compromised.

8. What to take from this lesson

The reframing, stated plainly, before the next lesson builds the practice.

The signals you were taught are gone. Bad grammar, generic greetings and awkward phrasing described attacker constraints that no longer exist. Checking for them and finding nothing tells you nothing, and the confidence it produces is the actual danger.

Specificity is not authentication. A message that knows your project, your colleagues and your calendar can be assembled from public information in minutes, without anyone breaching anything.

Recognition is not identity. A familiar voice or face is no longer evidence of who you are dealing with, which invalidates a great many informal processes nobody wrote down.

The quality of attack once reserved for high-value targets is now available against everyone, because the cost fell rather than because the technique improved.

And the structure did not change. The attacker still needs an irreversible action, still needs urgency, still needs you not to check, and still controls the channel they contacted you on.

That last point is the whole of the good news. A defence aimed at the presentation of attacks has to improve continuously and will lose. A defence aimed at the structure works regardless of how convincing the message becomes, because it never examines the message.

The next lesson is that defence: verifying the request rather than the person, and building it into how an organisation and a household actually operate.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why is 'check for bad grammar and odd domains' now worse than no training?
    • It takes too long to apply under time pressure
    • Finding no errors produces confidence that the message is genuine
    • It only applies to email, not other channels
    • Attackers deliberately insert errors to seem authentic
  2. What did the Heiding, Lermen, Kim, Schneier and Vishwanath study find?
    • AI phishing was less effective than generic phishing
    • AI could not build accurate profiles from public data
    • Automated spear phishing matched human experts at roughly a thirtieth of the cost
    • Personalisation made no difference to click rates
  3. Why is internal knowledge in a message no longer evidence of legitimacy?
    • Internal systems are frequently breached
    • Colleagues routinely share project details externally
    • Attackers guess project names from industry conventions
    • Detailed profiles can be assembled from public sources in minutes, with no compromise required
  4. Why can entering a multi-factor code on a page reached from a message fail to protect you?
    • Codes are reused across sessions
    • Attackers relay codes in real time through a proxy page
    • Multi-factor codes are transmitted unencrypted
    • The codes expire too slowly
  5. What should phishing simulation programmes measure instead of click rates?
    • Number of employees completing training modules
    • Time spent reading each simulated message
    • Reporting speed, and whether people report after clicking
    • The proportion of messages deleted unread

Related lessons

Business
beginner

Verifying the Request, Not the Person

If recognition no longer establishes identity, verification has to move to the channel. This lesson builds the practice: out-of-band confirmation, which requests need it, designing protocols people will actually follow under pressure, the household version, and what to do in the first hour after something goes wrong.

8 steps·~12 min
Business
beginner

Why This Role Is the Target, and How to Not Be the Story

Assistants sit where authority, access and urgency meet, which is exactly what impersonation fraud exploits. This lesson covers why the role is targeted, what changed when voice and video became cheap to fake, and the verification habits that hold up when a convincing executive is asking you to move quickly.

8 steps·~12 min
Business
beginner

The Risk You Bring In: Your Own AI Tools

The other direction of the problem. Employees using AI tools create exposure through data leaving the organisation, prompt injection turning an assistant against its user, malicious extensions, and code suggestions nobody verified. This lesson covers what to worry about and what is overstated.

8 steps·~12 min
Programming
advanced

The Runtime Stack, and What Isolation Is Worth

One command hides four layers of software and a set of standards that made them interchangeable. This lesson takes the stack apart, then asks the question the whole path has been building toward: given a shared kernel, how much is container isolation actually worth, and what has to be added before it is a security boundary.

8 steps·~12 min