
You get a text from what looks like your bank. It uses your full name, references your last transaction, mentions the exact branch you visited, and warns you of suspicious activity on your account. The link looks right. The tone is perfect. You almost click it – or maybe you do. That message wasn't sent by a person. It was generated in seconds by an AI system, personalized from scraped data, and sent to thousands of people simultaneously.

This is what modern phishing looks like. And it's a significant departure from the obvious scam emails of ten years ago.
For most of the internet era, phishing attacks were easy to spot if you knew what to look for. Generic greetings like "Dear Customer," glaring spelling mistakes, mismatched email domains, and clunky sentences that read like they'd been run through an early translation tool. The attacks worked anyway – at scale, even a 0.1% success rate on a million emails generated thousands of victims – but a reasonably alert person could identify and ignore most of them.
The friction involved in crafting a convincing phishing email was also a natural limit on quality. Writing personalized, grammatically correct, contextually accurate messages at volume required human time and effort that simply wasn't available. Attackers made up for quality with quantity. As a result, financial institutions, email providers, and security researchers could train detection systems on the obvious patterns these attacks shared.
That calculus has shifted.
The specific capabilities that AI has brought to phishing are not theoretical – they're actively being used and documented by cybersecurity researchers and financial institutions tracking attack patterns.
Language generation is the most visible change. Large language models can produce fluent, grammatically correct, contextually appropriate text in any language, in any tone, at effectively zero marginal cost per message. The same system that can write a business email or a news summary can write a convincing bank security alert, a wire transfer request from your "CFO," or a customer service message from your credit card company. The obvious tells that previously marked phishing emails are simply gone in AI-generated versions.
Personalization at scale is the second major shift. Data from past breaches, social media profiles, public records, and purchased data sets allows attackers to feed AI systems personal details that get woven into generated messages. A phishing message addressed to you by name that references your employer, your city, your recent purchase, or your specific bank – data all plausibly available from public or breached sources – is dramatically more convincing than a generic blast. This used to require a targeted human-crafted attack reserved for high-value victims. AI makes it economically viable for mass attacks.
Voice cloning extends the threat beyond text. AI audio models can clone a voice from a few seconds of publicly available audio – a YouTube video, a podcast appearance, a voicemail. Security researchers have demonstrated convincing bank representative impersonations built from minimal training data. The Federal Trade Commission and FBI have both documented cases of voice-cloned fraud calls, including cases where people were deceived by synthesized voices of people they actually knew.
Automated multi-channel coordination means attacks now run simultaneously across email, SMS, phone calls, and even WhatsApp or messaging apps, with consistent messaging across channels. Receiving a "security alert" by email and then a follow-up "call from your bank" within minutes – both generated by the same automated system – creates a convincing urgency that's harder to dismiss than a single suspicious email.
A few of the documented attack patterns targeting bank accounts specifically are worth understanding in concrete terms.
Smishing (SMS phishing) with spoofed sender IDs has surged. Attackers spoof the sender ID to appear as the same shortcode your bank uses for legitimate alerts, meaning the fraudulent message appears in the same conversation thread as your real bank messages on some phones. The message flags unusual activity and includes a link or asks you to reply to verify. The link routes to a convincing replica of your bank's login page that captures your credentials in real time.
Real-time credential relay attacks are technically sophisticated but increasingly accessible. When you enter your credentials on a fake bank site, an automated system immediately uses them to log into your real bank account, initiates a withdrawal or wire transfer, and may even prompt you for the two-factor authentication code that your bank then sends to your actual phone – because the system triggered the real login. You enter the code into the fake site thinking you're verifying your identity, and you've just handed over the final piece needed to complete the transfer.
Spear phishing of business banking customers targets the specific combination of business account access and transaction authority. A message appearing to come from a vendor, a senior colleague, or a business service provider – personalized with accurate details – requests a funds transfer or change of payment details. Business accounts are a higher-value target and often have less friction in the transaction flow than consumer accounts.
The instinctive response – "just be more careful and look for red flags" – is less useful than it used to be precisely because AI has removed many of the red flags. A message with no spelling errors, perfect brand formatting, accurate personal details, and appropriate urgency doesn't trigger the same skepticism that a visibly crude phishing attempt does. The cognitive shortcuts people use to quickly dismiss obvious scams don't apply in the same way when the attack is well-crafted.
Two-factor authentication (2FA) remains a meaningful defense but is not a complete one. As the real-time relay attacks above illustrate, 2FA codes can be phished just like passwords when the attack is sophisticated enough to prompt you for them immediately. Hardware security keys (physical devices like YubiKeys) are significantly more resistant to this kind of attack because they bind authentication to the specific website domain – a fake site can't receive the authentication signal even if you click the link.
Financial institutions are deploying AI-based detection systems on their end as well, analyzing transaction patterns, login behavior, device fingerprints, and behavioral biometrics (how you type, how you move the mouse) to flag suspicious activity. These systems add meaningful protection, but they're playing a continuous catch-up game against attack methods that are also improving.
The most reliable protection against phishing attacks – AI-enhanced or otherwise – is making the core defenses automatic rather than dependent on correctly identifying a sophisticated attack in the moment.
Use a password manager and unique passwords for every financial account. If an attacker captures your password for one service and it's reused elsewhere, credential stuffing gives them access to everything that uses the same combination. Unique passwords contain the damage to a single compromise.
Enable the strongest available 2FA on your bank accounts. An authenticator app (Google Authenticator, Authy) is meaningfully better than SMS codes, which can be intercepted through SIM-swapping attacks. A hardware security key is stronger still if your bank supports it.
Never follow a link from an email or text to log into your bank. Go directly to your bank's website by typing the address or using a saved bookmark, then check for the alert from within your authenticated session. If the alert is real, it will be there. If it's not, you've safely avoided the attack.
Call your bank on the number on the back of your card if something feels off. Not the number in the message, not the number that called you. The number on your card routes to your bank's real customer service line. If someone claiming to be your bank calls you, hang up and call back on the verified number.
Be skeptical of urgency. AI-generated phishing messages are specifically designed to create urgency that bypasses deliberate thinking. "Your account will be suspended in 24 hours" and "unauthorized transaction in progress" are pressure tactics. Your bank will not actually close your account in 24 hours without extensive prior communication, and a few minutes of verification won't make anything worse if the threat is real.
The phishing threat landscape will continue evolving as AI capabilities develop. Deepfake video is becoming accessible enough that video verification – sometimes used to confirm identity in financial contexts – is increasingly less reliable as a defense. Regulatory responses are emerging: the EU's AI Act includes provisions relevant to synthetic media, and the FTC has issued guidance on AI-generated fraud. Financial institutions are investing heavily in behavioral biometrics and device-level authentication as defenses that are harder to replicate from a distance than passwords and codes.
For consumers, the practical reality is that the arms race between attack and defense will continue, and staying protected will require more than just awareness. The structural defenses – unique passwords, strong 2FA, avoiding link-clicking – remove most of the risk without requiring you to correctly identify every sophisticated attack that comes your way. That's a more realistic standard than expecting to out-detect a well-built AI system on every attempt.
How do attackers get the personal details used in personalized phishing messages? Most commonly from data breaches, purchased data sets, and public sources like social media, LinkedIn, and public records. The combination of information available from multiple breaches – email addresses, phone numbers, partial financial data, employer details – is enough to build a convincing personalized message for millions of people.
Can my bank actually be spoofed in the text message thread? Yes. Sender ID spoofing allows attackers to display the same alphanumeric sender name (like "MyBank") that your bank uses for legitimate alerts. Some carriers and phone operating systems are improving defenses against this, but it remains technically possible and actively exploited.
Is AI-generated voice fraud already happening? Yes, it's documented. The FBI and FTC have both published warnings about AI voice cloning fraud, including cases targeting bank account holders and business banking customers. The attacks range from calls impersonating bank representatives to calls impersonating family members in fabricated emergency scenarios.
If I got phished and entered my credentials, what should I do immediately? Call your bank immediately on the number on the back of your card. Change your password for that account and any other account using the same password. If you shared a 2FA code, inform your bank that the code may have been used. Monitor your accounts closely for several weeks and place a fraud alert with the major credit bureaus if you're concerned about identity theft beyond the banking credentials.
Does AI also help banks detect phishing attacks? Yes. Financial institutions use machine learning systems to detect unusual login patterns, flag transactions that don't match behavioral norms, and identify suspicious device or location changes. These systems provide a meaningful layer of protection on the institutional side, though they work best in combination with user-level defenses rather than as a substitute for them.
FBI – Voice Cloning and AI Fraud Warning: https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-scams-and-crimes/spoofing-and-phishing
Federal Trade Commission – Impersonation Scams and AI Voice Fraud: https://consumer.ftc.gov/articles/what-know-about-family-emergency-scams
CISA – Phishing Guidance for Organizations and Individuals: https://www.cisa.gov/topics/cyber-threats-and-advisories/malware-phishing/phishing
Anti-Phishing Working Group – Phishing Activity Trends Reports: https://apwg.org/resources/apwg-reports/
Financial Crimes Enforcement Network (FinCEN) – AI-Related Financial Fraud Alerts: https://www.fincen.gov/resources/advisories




















