A couple of years ago, most phishing emails were laughably bad. Misspelled words, dodgy formatting, a “Nigerian prince” who needed your bank details. You could spot them in seconds. In 2026, that’s changed.
Researchers now estimate that around 82.6% of phishing emails involve some form of AI-generated content, and Hoxhunt’s 2026 threat data shows AI-generated campaigns surged roughly 14 times at the end of 2025 alone.
Attackers are writing emails that look and sound like they came from your actual colleagues, and they’re catching people who really should know better. Let’s explore what’s changed, why small teams are getting caught out, and the steps that will actually keep your inbox safer this year.
These Emails Don’t Look Like Scams Anymore

The biggest change this year is how personalised AI-generated phishing has become. Attackers feed large language models publicly available data from LinkedIn profiles, company websites, press releases and social media posts.
The NCSC calls this your “digital footprint”, and it’s exactly what makes modern spear-phishing so hard to spot. The result is an email that references your real job title, your manager’s name, a project your company actually announced last quarter, and a tone that matches how your colleagues write.
One common example doing the rounds in 2026: a fake email from “your CEO” asking you to approve an urgent invoice for a supplier your company genuinely uses. The email mentions a real project by name, uses the CEO’s actual sign-off style, and links to a convincing login page.
There’s no broken English, no weird formatting. It looks completely legitimate. Business email compromise scams like this are projected to drive over $25 billion in losses globally in 2026, and UK Finance reported UK phishing-related fraud losses exceeded £1.2 billion in 2025.
Another version targets finance teams. The attacker scrapes a company’s recent job postings to learn which software they use, then sends an email pretending to be from that software provider.
It’ll say something like, “Your subscription payment failed, click here to update your billing details.” The email includes the correct product name, your company’s name and sometimes even the finance manager’s first name.
Why Are Small Teams Especially Vulnerable?
Startups and small businesses often assume they’re too small to be targeted. That’s not how it works anymore. AI-based phishing tools now cost attackers as little as $75 to run, which means thousands of personalised emails can be blasted out with almost no effort. A five-person startup will get hit with the same convincing fakes as a FTSE 100 company.
Small teams also tend to have less formal processes. If your CEO messages you on Slack asking you to quickly pay an invoice, you probably won’t question it. There’s no procurement department to flag it, no approval chain to slow things down.
That informality is exactly what attackers exploit. Up to 46% of SMEs report having only minimal, or even no, cybersecurity measures in place at all, according to a 2026 OECD report, which leaves most small businesses running on old assumptions.
Lock Down Your Email Authentication First

Before you think about training, make sure your email setup isn’t making things worse. Three protocols will help here: SPF, DKIM and DMARC. Together, they’ll verify that emails claiming to come from your domain actually came from your domain.
SPF (Sender Policy Framework) tells receiving mail servers which IP addresses are allowed to send email on your behalf. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing emails so the recipient can confirm they haven’t been tampered with. DMARC ties them both together and tells receiving servers what to do when an email fails those checks.
If you haven’t set these up yet, you’re leaving the door open for attackers to spoof your domain. Most domain registrars and email providers have guides to help you configure the DNS records, and whoever handles your IT can get the basics in place quickly.
Getting DMARC to a proper enforcement policy will take longer, and the NCSC recommends starting with a policy of “none”, monitoring reports for six to eight weeks, then moving to “quarantine” or “reject” once you’re confident every legitimate sending source is covered. The NCSC’s free Mail Check service will help you verify everything is configured correctly.
Test Your Team Before an Attacker Does
Awareness training is a good starting point, but a one-off seminar won’t cut it. Research tracking over 12,000 employees found that generic training programmes showed no meaningful effect on click rates or reporting. Organisations running continuous behaviour-based simulations, on the other hand, get failure rates down to around 1.5%.
Phishing simulation tools will let you send fake phishing emails to your own staff and see who clicks. You’ll quickly find out whether your team would hand over credentials to a well-crafted fake. Run these tests regularly, not just once a year, and pair them with short coaching moments rather than public shaming.
For deeper testing, some companies bring in external specialists who use the same AI-assisted techniques that real attackers use to probe defences. A UK red teaming service will simulate social engineering attacks across email, phone calls, messaging apps and even physical access, so you’ll see exactly where things break down before someone with bad intentions does.
Build Habits, Not Just Policies

The best protection against AI-powered phishing is a culture where people happily slow down and double-check. Encourage your team to verify unusual requests through a different channel.
If you get an email from your CEO asking you to transfer money, pick up the phone and call them. If a supplier sends a new bank account number, confirm it by ringing the number you already have on file.
Set up a simple process for reporting suspicious emails. It doesn’t need to be complicated. A shared Slack channel or a dedicated email address will work. What matters is that people actually use it, and that nobody gets criticised for flagging something that turns out to be legitimate.
Your Inbox Won’t Get Safer on Its Own
AI-generated phishing is only going to get more convincing. The tools attackers use will improve, the personalisation will get sharper, and the volume will keep climbing. Small teams can’t treat this as someone else’s problem.
Set up your email authentication, test your staff with realistic simulations, and build a culture where verifying before clicking is just how things are done. The companies that take this seriously now will be the ones that don’t end up in a breach headline later.

Blogger | Business Writer | Sharing startup advice on UK business blogs
