GreyFalcon Briefing
The Scam Email Looks Real Now. Here’s What Your Team Should Check Instead.
AI-written scam emails may be polished and convincing. Your team needs a better test than spelling and grammar.
For years, security awareness training taught people to watch for misspelled words, awkward sentences, and strange formatting. That advice was useful. It is no longer enough.
Generative AI can produce a polished email in seconds. It can imitate a professional tone, remove the obvious mistakes, and make a fraudulent request sound entirely reasonable.
The better question is not, “Does this email look real?” It is, “What is this email asking me to do?”
1. The Old Warning Signs Have Changed
A scam email may now have clean grammar, familiar language, a believable signature, and convincing branding. It may refer to a real employee, vendor, project, or invoice.
That does not mean the old warning signs disappeared. They simply moved. The strongest clues are now found in the request, the timing, and the process the sender wants you to follow.
2. Read the Request, Not Just the Message
Slow down when an email asks you to:
- Send money or purchase gift cards
- Change banking or payment instructions
- Open a document and sign in
- Share a password, verification code, or sensitive information
- Install software or approve remote access
- Ignore the normal approval process
- Act urgently or keep the request confidential
If the request involves money, credentials, sensitive information, or a change in established procedure, verify it through a second channel.
3. Check the Actual Sender
Do not rely on the display name. Expand the sender details and inspect the full email address. A message labeled “Microsoft Support” or “Your Bank” can come from an unrelated address.
Look for misspelled domains, extra words, unexpected consumer email accounts, and reply-to addresses that differ from the sender. On a phone, this may require tapping the sender’s name to reveal the address.
4. Verify Through a Channel You Already Trust
If a message appears to come from a coworker, vendor, bank, or client, do not use the phone number or link inside the suspicious message to verify it.
Call a number you already have. Start a new message using a known address. Open the service from a saved bookmark. Ask the person directly through Teams or another established channel.
A two-minute verification is far less expensive than recovering from a fraudulent payment or stolen account.
5. Establish One Firm Payment-Change Rule
Every business should have a simple rule for changes involving money:
No change to a vendor’s payment instructions is accepted solely through email.
Require verification through a known phone number and, when appropriate, approval from a second person. The same rule should apply to payroll changes, wire transfers, bank details, and unusual purchases.
6. Email Security Still Matters
Employee awareness is important, but it should not carry the entire load. Strong email protection should help filter malicious messages before they reach an inbox.
A practical defense includes multi-factor authentication, secure email filtering, domain protection, endpoint security, patching, reliable backups, and monitoring for unusual sign-in activity.
No single control is perfect. The strength comes from layers.
7. Voice Calls and Text Messages Require the Same Discipline
The same tactics are used in text messages and phone calls. A familiar name, a local number, or even a convincing voice does not prove identity.
When a request is unusual or high-risk, stop and verify through a trusted channel. The process matters more than how convincing the message sounds.
8. Make Suspicious Messages Easy to Report
Employees should know exactly where to send a suspicious message and should never be embarrassed for asking. A healthy reporting culture catches mistakes early.
The rule should be simple: when in doubt, report it before acting. Security teams can investigate a harmless message quickly. They cannot always recover money or data after the fact.
9. What Should Your Business Do Now?
- Update security awareness training so it does not depend on poor spelling and grammar.
- Teach employees to identify high-risk requests involving money, credentials, and sensitive information.
- Document a second-channel verification process.
- Require independent verification for payment and banking changes.
- Make reporting suspicious messages fast and blame-free.
- Review the technical controls protecting email and user accounts.
10. Frequently Asked Questions
Can a scam email have perfect spelling and grammar?
Yes. AI tools make it easy to produce polished, professional messages. Writing quality is no longer reliable proof that an email is legitimate.
What is the safest way to verify an email request?
Use a different channel you already trust. Call a known number, start a new message, or contact the person through an established business platform. Do not use contact information supplied by the suspicious message.
Should employees click a link to see whether it is legitimate?
No. If the message concerns an account, open the service through a saved bookmark or type the known address yourself. If the request remains uncertain, report it.
What requests deserve extra scrutiny?
Anything involving money, passwords, verification codes, sensitive data, software installation, remote access, or a change to an established process.
11. Start With the Process You Have Today
You do not need a complicated program to improve your defenses. Start with one clear verification rule, one easy reporting method, and a review of the protections already in place.
For a concise procedure that can be adapted for an employee handbook or internal policy, read the companion Insight: A Scam Email Can Look Perfect. Check the Request Instead.
Adapted with permission from The Technology Press. Supporting guidance: UK National Cyber Security Centre and the FBI Internet Crime Complaint Center.