Phishing emails used to be fairly easy to spot. A misspelled subject line, a sender address that was slightly off, stilted grammar. The classic tells that every business owner learned to recognise. Those tells are largely gone now.
Generative AI has given attackers the ability to produce thousands of personalised, grammatically perfect phishing emails in minutes. They can replicate a supplier’s writing style, reference a real recent invoice, and match the exact tone of a genuine correspondence thread. UK SMEs are now facing a 43% year-on-year rise in ransomware attacks, with email-based phishing the entry point in 82% of successful breaches. The average cost of a ransomware incident to a UK SME — including downtime, recovery costs, reputational damage and regulatory fines — exceeds £200,000.
The email filter your IT provider set up three years ago was built for a different threat. Here is what has changed, and what actually works now.
How AI has transformed the attack
Traditional phishing operated at volume and low effort. Send a million generic emails, get a fraction of a percent clicking through, and that is still a meaningful number of compromised accounts. The weakness was quality: the emails were obvious, untargeted, and frequently suspicious to anyone paying attention.
AI reverses this. Attackers can scrape publicly available information about your business — your website, LinkedIn profiles, Companies House filings, press mentions — and generate emails that are highly specific to your company. The “invoice” references your actual supplier and the right amount. The “IT support” email arrives the morning after a genuine system issue. The “HMRC” message knows your business structure and trading name.
Voice phishing has evolved at the same pace. AI voice cloning can credibly mimic a known contact from a short audio sample. Calls claiming to be from your bank, accountant, or a senior colleague are no longer a remote theoretical risk — they are a documented, current attack vector affecting UK businesses.
The practical consequence is that the primary defence most SMEs rely on — staff recognising something that looks suspicious — is materially weaker than it was two years ago.
What actually stops AI phishing
Awareness training remains worth doing, but it cannot be your only defence layer. You need technical controls that reduce the attack surface regardless of whether an individual employee makes a mistake.
Configure DMARC, DKIM and SPF. These are email authentication standards that tell receiving mail servers whether an email claiming to come from your domain actually does. Without them, anyone can send emails impersonating your business to your customers and suppliers. Setting them up is a one-time technical task — your IT provider should be able to complete it in under an hour, and it protects your reputation as well as your inbox.
Enforce multi-factor authentication on every account. If login credentials are stolen through phishing, MFA means the attacker still cannot use them without a second verification step. Enable it on email, cloud storage, accounting software, and any remote access tools. This single control blocks the majority of credential-based breaches.
Introduce a verbal callback rule for unusual requests. Any request to change bank account details, transfer funds, or grant access permissions — regardless of who it appears to come from — must be verified with a spoken conversation using a known, trusted phone number. Not a reply to the same email thread. Not a call to a number included in the message itself.
Monitor what is being done in your name
One of the most overlooked phishing risks is your own domain being spoofed to target your customers or suppliers. KeepSafe includes domain monitoring that alerts you when your brand or domain appears in suspected phishing campaigns — so you know when you are being impersonated, not just when you are being targeted directly.
The one action to take this week
Call your IT provider and ask two questions: Are DMARC, DKIM and SPF configured for our domain? Are all Microsoft 365 or Google Workspace accounts protected by multi-factor authentication? If the answer to either is no, or uncertain, book the fix this week rather than adding it to a future review list.
Phishing is now a professional, AI-assisted industry operating at scale. The technical hygiene steps that neutralise most of it remain relatively straightforward. The gap between businesses that have done them and those that have not is growing wider every month.