The most consequential email your controller opens this quarter will probably be well written. Consider a plausible version of it: the message arrives inside an existing thread, references a purchase order that genuinely exists, carries the vendor's real signature block, and lands on a Thursday afternoon when the person it appears to come from is on a flight. Nothing in it reads as wrong, because nothing in it is wrong except the bank details.
Security awareness training has long taught the opposite expectation — that fraud announces itself. Broken grammar. Odd spacing. A greeting addressed to no one in particular. Employees were trained as human filters, scoring inbound mail against a checklist of tells.
That checklist has quietly stopped earning its keep, and the reason matters more for how you spend money than the headline version of the story, which is simply that AI writes better email now.
The typos were a budget line, not a mistake
Sloppy phishing was never evidence of incompetence. My read is that it was the visible residue of an economic tradeoff. Mass campaigns were written fast, priced for volume, and often composed by people working in a second language. Persuasion cost human hours: researching a target, learning a vendor relationship, matching someone's writing style. Because those hours were expensive, hand-built spear phishing was rationed to targets worth the labor — a treasury desk, an executive assistant with signature authority, a finance chief at a company large enough to justify the effort.
Everyone else got the cheap version. The cheap version became the shape of our training.
Generative models collapsed the cost of the expensive version. This is analysis rather than a measured finding, but the mechanism is not speculative: drafting fluent, context-matched business prose is precisely the sort of work language models do well, and they do it at scale. So the change is not simply better phishing. It is targeted-grade quality at commodity volume — the kind of attention once reserved for a large corporate treasury operation, now economically viable against a sixty-person distributor in the San Fernando Valley.
A 200-seat Los Angeles business used to be protected in part by its own unimportance. That shield has thinned.
The prose was never the tell — the context gap was
Here is where many awareness programs went backwards. Employees who reliably caught fraud were rarely reacting to grammar. They were reacting to context that did not fit: a vendor who never emails about invoices, an approval that skipped a step, a request arriving from outside the conversation it claimed to continue. Language was a proxy for that mismatch, and a crude one.
Business email compromise, in my assessment, has always been an access problem more than a writing problem. When an attacker controls a real mailbox — through a stolen password, a hijacked session, or a supplier breached three links up the chain — the context arrives free. The thread is genuine, the relationship history is real, and tone can be copied from the archive sitting in the same inbox. There is no forged sender to detect, because the sender is authentic.
Fluent generation closed the language gap. Mailbox access and public information — filings, job postings, licensing records, professional profiles — close the context gap. With both closed, the reader has very little left to perceive. Asking them to perceive it anyway is a design failure rather than a discipline problem.
Why polish itself has become the discrepancy
An observation offered as opinion rather than data: real internal email is bad writing. Fragments. "ok approved." "call me." Sent from a phone with no greeting and one stray autocorrect. Executives in particular write like people with eleven minutes between meetings, because they are.
So a message that is courteous, well structured, free of typos and thoughtfully paragraphed — from a colleague whose normal register is four words and a period — carries a discrepancy in its polish. Not proof of anything. A discrepancy.
The temptation is to convert that into a new checklist item: be suspicious of good writing. Resist it. Every surface signal is now cheap to imitate, including whichever one you invent next. Voice deserves the same skepticism, and with synthetic speech now widely available, "call the number in the email to confirm" is a control that verifies very little. Any verification path the attacker supplies inside their own message is not verification. It is theater with an extra step.
Verification belongs in the process, not in the reader
The executive decision this should inform is resource allocation: buy less detection capability for humans and more architecture that tolerates human failure. Concretely, that means a short list.
- Bind verification to the action, not the message. Any change to payment details, payroll direction, banking instructions or vendor remittance triggers a callback to a number from your own vendor master file — never from the email, never from the signature block. The trigger is the action type, and it applies no matter how legitimate the request looks. That is the entire point.
- Make stolen credentials non-convertible. Phishing-resistant sign-in, meaning passkeys or hardware keys, plus deliberate Conditional Access policy in Microsoft 365, means a convincing email that harvests a password yields very little. Session and token theft deserve equal attention; a stolen session skips the login prompt entirely.
- Instrument the mailbox, then read the instruments. New inbox rules, external forwarding, sign-ins from improbable locations and unusual mailbox permission grants are the fingerprints of thread hijacking in preparation. Telemetry nobody reviews is not a control. Monitored detection and response is the working core of modern cybersecurity, and it is what turns a signal into an intervention.
- Change the economics of reporting. Track reporting rate, not click rate. Tell staff plainly that judging is not their job and forwarding is. Then make reporting frictionless and free of embarrassment, because a report that requires a form and a hold queue will not happen at 4:50 on a Friday.
- Remove solitary authority over irreversible actions. Wires, banking changes and privileged permission grants should not be executable by one convinced person. Dual control is old, unglamorous, and probably the highest-yield item on this list.
None of this requires a new platform. Most of it is process design, which is usually cheaper than the tooling conversation it tends to get buried under.
The list worth writing before your next leadership meeting
The wrong question is how to train people to spot better fakes. That race is unwinnable, and it was the wrong race well before these tools arrived. The better question: which irreversible actions in this company can be triggered by a single convincing message?
Write the list. It tends to be shorter than people expect and more alarming. Put structural verification in front of each item, then accept that your employees will eventually be fooled by something excellent — because being fooled and being compromised should not be the same event. One related item belongs in the same meeting: cyber policies often treat funds-transfer fraud differently from ransomware, and that distinction is easier to understand before the week you depend on it.
Pro Link Systems has served Los Angeles businesses from Woodland Hills since 1999. Our help desk is in-house, US-based and staffed 24/7, phones answered live with no phone tree, and our average ticket first-response time is 15 minutes — which is the practical reason an employee who is unsure about an email asks someone instead of guessing. If you want a candid review of where one convincing message could still move money or grant access, our managed IT services team is at prolinksystems.com/managed-it-services.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.