Phishing remains one of the most prevalent and effective cyberattack methods, tricking millions into compromising their data every year. These deceptive messages, often arriving via email, text message (smishing), or phone call (vishing), are designed to look legitimate. They aim to trick you into revealing sensitive information like login credentials, credit card numbers, or personal data, or to click on malicious links that install malware. They may also be the start of a more complex cyber attack as a way into a system.
What's changed in 2026 is the quality of the bait. AI tools have quietly removed the biggest giveaways phishing training has relied on for years, and schools, with their mix of busy staff, urgent payment processes, and publicly available information about who works where, are a prime target.
🚩Always be suspicious, but the old red flags aren't enough anymore
The classic advice still matters. Look out for:
- Unsolicited or unexpected messages: Did you really order that package? Is your bank suddenly asking for your full credit card number via email?
- Generic greetings: "Dear Customer" instead of your name.
- Suspicious sender addresses: Hover over the sender's name to see the actual email address; it often won't match the purported sender.
- Urgent or threatening language: "Your account will be suspended!" or "Click now to claim your prize!"
- Links that don't match the description: Hover over links (don't click!) to see the true destination URL.
Here's the problem: poor grammar and spelling used to be the easiest tell, it no longer is. AI tools can now write fluent, personalised, context-aware messages in seconds, with no awkward phrasing to spot.
How AI has changed the bait
- Perfect grammar as standard. The "written by someone whose first language isn't English" tell is gone. AI-generated phishing reads as naturally as a genuine colleague's email.
- Personalised, researched messages. Rather than a generic blast, AI can scrape publicly available information: a staff page, a LinkedIn profile, a recent school news post, to write a message that references real names, real projects, or real events, making it feel credibly internal.
- Pixel-perfect fake websites. Cloned login pages (for email, finance systems, or cloud storage) can now be generated and deployed in minutes, matching a real site's branding exactly, including the school or trust's own logo.
- Convincing look-alike domains. AI-assisted domain generation makes typosquatted URLs (e.g. a single swapped letter, or a hyphen added) harder to spot at a glance, especially on a mobile screen.
- Combined with voice and video. As covered in Days 6 and 7, AI-crafted phishing emails are increasingly paired with a follow-up voice or video "confirmation", a cloned voice call to reassure someone the email is legitimate.
💡Today's Cyber Tip: Hover and Verify, then go further
Keep practising the "hover and verify" rule: whenever you receive an email with a link, hover your mouse over it (without clicking) to reveal the true destination URL.
But because AI-generated look-alike domains can be very close to the real thing, go one step further for anything involving money, credentials, or personal data: don't trust the link at all, instead navigate to the site yourself, using a bookmark or a URL you already know to be correct, rather than the one in the message.
Recognise and report phishing: updated red flags
- A tone that's urgent or makes you feel scared (i.e. click immediately or your account will be closed)
- The sender email doesn't match the company it's coming from (unusual spellings)
- An email, call, or video you weren't expecting, even if it reads, sounds, or looks exactly right
- A request to send personal information, login details, or make a payment
- A link that goes to a site you don't recognise, or a domain that's almost, but not quite right
- Fluent, well-written, personalised content is no longer a sign of legitimacy on its own
General guidance for preventing phishing attacks
- Install security software on mobile devices
- Avoid browsing certain websites; block if necessary
- Only download reputable mobile applications from legitimate sources, and restrict within an organisation; consider an "approved" software list
- Exercise caution on social media, and be mindful of what's publicly visible about staff and their roles
- Use different passwords for different systems
- Be careful when using public wireless networks
- Consciously keep up with current security trends and threats, including how AI is changing them
Organisational recommendations
Ensure staff are trained on how to recognise a phishing email, and are specifically briefed that AI has removed the old, easy tells. Consider running a phishing campaign as a training exercise, ideally one that includes AI-crafted examples rather than only the traditional, easier-to-spot kind.
Where this sits in the DfE Digital & Technology Standards
This continues to sit under the Cyber Security standard, specifically cyber awareness, user accounts & access, and cyber attack response, now expanded to reflect that awareness training needs to keep pace with AI-driven tactics, not just traditional ones.
