The Grammar Is Perfect Now: AI-Assisted Spear Phishing at Scale
Threat Intel

The Grammar Is Perfect Now: AI-Assisted Spear Phishing at Scale

November 22, 2025 9 min read Phishing AI Social Engineering Awareness

The tell-tale linguistic markers that security awareness training taught employees to recognize are disappearing. New research on AI-generated phishing campaigns and what detection actually looks like now.

The Training No Longer Works

For the past decade, security awareness training has taught employees to look for spelling errors, awkward phrasing, and cultural inconsistencies in phishing emails. The advice was correct and it helped.

It no longer helps.

The linguistic quality of phishing emails has improved faster than awareness training has adapted. AI language models have eliminated the grammatical tells that identified machine-generated or non-native-speaker-generated phishing. What remains is content — and content can be researched.


What the New Generation Looks Like

In a simulated campaign we ran against a professional services firm in Q4 2025, we used publicly available information from LinkedIn, company press releases, and industry publications to generate spear-phishing emails that referenced:

  • The recipient’s recent projects by name
  • Their reporting manager’s communication style
  • A business context the recipient would recognize as plausible

The click rate was 34%. The firm’s previous benchmark from a generic phishing simulation was 8%.


Detection in a Post-Linguistic World

If linguistic quality is no longer a reliable signal, detection must shift to behavioral indicators: unexpected sender-recipient relationships, requests that deviate from established communication patterns, urgency framing that doesn’t match normal business cadence.

This requires behavioral baselines. Most organizations do not have them. Building them is not technically complex — it requires data collection decisions that are made at the security architecture level, not the incident response level.


The Deeper Problem

The deeper problem is that AI-assisted phishing democratizes sophistication. Techniques that previously required skilled social engineers — researching targets, crafting contextually appropriate lures, adapting to detection — are now accessible to actors without those skills.

The threat is not that AI makes existing sophisticated attackers more dangerous. It is that AI makes previously unsophisticated attackers significantly more dangerous.

All research