TL;DR:

  • AI-generated phishing emails now achieve 5–10x higher click rates than traditional bulk phishing by referencing real, specific details about your business and contacts
  • These attacks scrape your website, LinkedIn, Companies House filings, and public social media to build a profile before crafting the email
  • The defences that work aren’t expensive — they’re mostly about process, not software

The phishing email used to be obvious. Generic salutation, broken English, urgent request from someone you’ve never heard of. Your staff learned to spot them. Your spam filter caught most of the rest.

That’s no longer the environment. In 2026, criminals are using generative AI to write phishing emails that are specific, credible, and in many cases indistinguishable from legitimate correspondence — because they’re built on real information about your business.

What “AI-Personalised” Actually Means

Traditional phishing was mass-market: send a million emails, accept that 0.1% will click. The economics of bulk phishing still work, but the marginal cost of personalisation has fallen to near zero, and the click-rate improvement is dramatic. Recent security research puts AI-personalised phishing emails at 5–10 times the click rate of generic equivalents.

Here’s how a targeted attack against a UK small business typically works in 2026:

Stage 1: Reconnaissance. An automated tool scrapes your website (staff names, email format, services offered, clients mentioned in case studies), your LinkedIn company page (employee names and roles), Companies House (directors, registered address, filing history), and any press coverage or social media. In under five minutes, it has a detailed profile of your business.

Stage 2: Email construction. The AI uses this profile to write an email that references specific real details. Not “Dear Customer” — “Dear [actual director name]”. Not a generic invoice — “Following our conversation about the Q2 digital marketing work for [real client name you’ve mentioned publicly]”. Not a random bank — “As discussed with [real staff member name], we need to update the payment details for [actual supplier name from your website]”.

Stage 3: Delivery. The email arrives from a domain that closely resembles a real supplier or customer (often one character different, or using a different TLD), with a real staff name in the sender field.

The result is an email that a busy employee, reading quickly between tasks, will often act on without questioning.

The Most Common Attack Patterns in 2026

Invoice fraud targeting accounts teams. An email appearing to be from a real supplier, referencing a real type of work you do, asks accounts to update bank details before processing the next payment. The email uses the real supplier’s company name and is addressed to the real accounts person by name.

CEO fraud with AI voice backup. The phishing email appears to come from the director or owner, requesting an urgent payment or information transfer. If the employee hesitates and phones to verify, a second layer of the attack uses an AI voice clone of the director (built from public video or audio) to confirm the instruction.

Fake client follow-up. An email appearing to be from a real prospect or new client requests that you click a link to access “project documents” or sign a proposal. The link leads to a credential harvesting page styled to look like Google Docs, DocuSign, or your email provider’s login.

HMRC/regulatory impersonation with real details. Emails referencing your actual company registration number, VAT number (if you’ve published any VAT invoices that have ended up in data breaches), or Companies House filing dates to appear authentic.

What Actually Works as a Defence

The good news: the defences here are not expensive or technically complex. They’re mostly about establishing simple processes.

Verify any payment change request by phone — always. This single rule would prevent most invoice fraud. The verification must be to a number you already have for that supplier (from previous correspondence or their website) — not to a number included in the suspicious email. This should be a written policy, not just informal guidance.

Establish a verbal codeword for urgent requests from leadership. For CEO fraud specifically, having a simple codeword that any employee can ask for when receiving an unusual instruction from “the boss” stops the attack dead. The codeword isn’t in any email or document — it’s shared verbally between staff.

Check email domains carefully, not just display names. Teach staff to look at the actual email address in full, not just the display name. An email showing “Accounts - Rapid Print Solutions” as the sender name but coming from accounts@rapid-print-solutions.co (not .co.uk) is a red flag. In Outlook and Gmail, hovering over the sender shows the full address.

Use DMARC on your own domain. DMARC prevents criminals from sending emails that appear to come from your domain. This protects your clients and partners from receiving fake emails purportedly from you. It doesn’t protect you from fake emails coming to you, but it’s an important baseline that’s free to implement.

Brief staff regularly, using real examples. Abstract security training has limited effect. Showing your team an actual AI-generated phishing email targeting a similar UK business, and talking through the specific details that made it convincing, is far more effective. The National Cyber Security Centre publishes regular threat updates with real examples.

What the NCSC Says

The National Cyber Security Centre’s 2026 threat assessment specifically calls out AI-enhanced spear phishing as a growing threat to UK SMEs, noting that the barrier to entry for sophisticated targeted attacks has fallen significantly. Their guidance echoes the above: process controls (payment verification calls, domain checking) are more reliable defences than technical tools alone, because the AI-generated content can bypass content-based filters.

The NCSC’s Exercise in a Box (free, online) includes phishing simulation exercises you can run with your team. It’s worth doing before an actual attack tests your staff response.

The Deepfake Voice Layer

The AI voice cloning element deserves specific mention because it’s the part that catches people most off-guard. Public audio of directors and business owners — from video testimonials, podcast appearances, YouTube content, or even voicemail greetings — can be used to create convincing voice clones in minutes.

The defence is the same: any unusual financial instruction must be confirmed through an established verification process, regardless of how convincing the voice sounds. If your director phones to ask for an urgent payment, the response is “I’ll call you back on your mobile” — not compliance based on voice recognition alone.