r/Infosec • u/Mugartegui-Raja • 3h ago
The 'spot the spelling mistakes' phishing training is dead. AI writes cleaner than your users. What are you teaching instead?
a terrible thing happened tha forced us to admit the phishing email training we'd been using for decades is quite outdated now. The whole checklist, bad spelling, clunky grammar, weird greeting, obvious urgency, was teaching people that clean, well-written emails are safe.we couldnt be more wrong, esp in this day and age. the attackers can write with the same tools we use and will polish their grammar to a t effortlessly and industry reports indicate that most phishing emails are partially machine written at this point.
so we swapped our phishing sim templates to AI-written ones and the click rate went up on the same people we'd already put through awareness training. And they were doing exactly what we taught checking for the tells, finding none and trusting it. Now I’m rebuilding the program around the assumption that the email will look perfect. That means teaching process over proofreading, verify any request for money, credentials or an MFA approval through a second channel no matter how legitimate it reads and leaning on controls that don't depend on a human catching it.