The Typos Are Gone: How AI Changed Phishing Emails
You’ve probably heard the advice: if an email has bad spelling and strange grammar, it’s probably a scam. That advice made sense for a long time. Scam emails used to be easy to spot — they read like they’d been translated twice and proofread never.
That’s no longer true.
AI writing tools have made it trivially easy for anyone to produce polished, professional, grammatically perfect text in seconds. Scammers use the same tools. The result is that the spelling-and-grammar filter that protected a lot of people no longer works the way it used to. The emails that arrive in your inbox today can look and read exactly like the real thing.
What AI-Generated Phishing Emails Look Like Now
A phishing email is one designed to get you to take an action — click a link, enter your credentials, open an attachment, or call a number — under false pretenses. The goal is usually to access your accounts, steal personal information like your SIN, or install software on your device.
Modern AI-generated versions of these emails are polished and specific. They may reference your name, your bank, your province, or your account type. They match the visual style and tone of the real organization they’re impersonating. They read like normal business communication — because they were written by software trained on vast amounts of normal business communication.
Here’s an example of how one might read: “Dear [Your Name], we’ve detected unusual sign-in activity on your account from a new device in Ontario. To protect your account, please verify your identity within 24 hours using the link below. If you do not act, your account access will be suspended.” Clean. Specific. Professional. Fake.
What to Look For Instead
Since polish and grammar are no longer reliable signals, here are the ones that still hold up:
Urgency. Legitimate organizations rarely demand that you act within 24 or 48 hours or face account suspension. That timeline is designed to short-circuit your instinct to pause and check. Real institutions give you time.
Unexpected requests. If you weren’t expecting to hear from your bank, or the CRA, or Service Canada — and the email asks you to do anything involving your account, your login, or your personal information — that unexpectedness is worth pausing on.
Links that don’t match the sender. Hover your cursor over any link in the email (without clicking) and look at the actual web address that appears. If the email claims to be from TD Bank but the link goes to “tdbank-secure-verify.com” or any address that isn’t exactly td.com, do not click it. Scammers register addresses that look close but aren’t the real domain.
Requests for personal information by email. Your bank, the CRA, and Service Canada will not ask you to reply to an email with your SIN, password, banking details, or security questions. That’s not how legitimate organizations handle sensitive information.
An attachment you didn’t ask for. Attachments from organizations you didn’t specifically request documents from are worth treating with care. They can install software on your device when opened.
The Signal That’s Harder to Fake
One thing that AI cannot fake is the actual sender domain — the part of the email address after the @ symbol. “service@cra-arc.gc.ca” is the real CRA. “service@cra-verification-canada.com” is not. A professional-looking email from a slightly-off address is one of the most common signals that something is wrong.
Take two seconds to look at the actual email address — not the display name, which can say anything — before you act on any request.
Why Calling Still Works
All of this can feel overwhelming, but it resolves to a single reliable action: if an email asks you to do anything with your account, call the organization directly before doing it.
Not the number in the email. The number on their official website, on your bank card, or on your most recent statement. A thirty-second call will tell you whether the request is real.
One thing to do: The next time you receive an email asking you to take action on any account — bank, CRA, Service Canada, or anything else — before clicking anything, call the organization directly using a number you find independently. This one habit makes the spelling of the email completely irrelevant.
Report phishing emails and fraud attempts to the Canadian Anti-Fraud Centre at 1-888-495-8501 or antifraudcentre.ca.