Technology newsroom
Is This Email Human or AI? How to Spot New-Era Phishing Emails Before You Click
AI enables scammers to craft more sophisticated phishing emails. This article provides effective verification methods, emphasizing checking an email's 'intent' and 'credibility' rather than trying to discern if it was human- or AI-written. This approach helps you stay safe from clicking dangerous links and data theft.
Nowadays, the emails you receive might look so good that it makes you wonder if a human actually wrote them, or if AI was used? This article won't teach you how to be an AI detector. Instead, it will provide a more crucial tool: how to analyze and decide if an email is credible and safe, regardless of who or what wrote it.
### Understand Before Solving
In the past, we might have spotted phishing emails by their grammatical errors or awkward phrasing. However, modern Generative AI like ChatGPT now allows scammers to create emails that are perfect in both language and format in just a few seconds. This renders our first line of defense—'noticing linguistic abnormalities'—ineffective.
The problem has shifted from 'Was this email written by AI?' to 'Is this email's intent good or malicious?' An email drafted by your colleague with AI assistance, if its content is correct, poses no danger. Conversely, an email deliberately written by a scammer, even without AI, remains dangerous.
Therefore, instead of trying to identify which sentences AI wrote, we should shift our focus to examining the 'intent' and 'credibility' of the entire email. This is an extremely crucial skill in the digital age.
### Before You Start
Preparation for this isn't technical; it's about attitude and readiness.
1. **Be Ready to Be Suspicious:** Before clicking any links or opening attachments, always pause and question the email you've received, especially those that convey urgency or offers that seem too good to be true.
2. **Know Official Communication Channels:** Understand how your organization or bank communicates. For example, IT departments will never ask for your password via email, nor will banks send you links to fill in personal information to unlock your account.
### How to Act Safely
Here are 6 verification steps to assess an email's credibility, instead of trying to determine if AI wrote it:
1. **Check the 'Sender' Beyond the Display Name**
* **WHAT:** Check the sender's full email address, not just the display name.
* **HOW:** On a computer, hover your mouse over the sender's name. On a mobile device, tap the sender's name once to view the actual email address details.
* **WHY:** Scammers can set the sender's name to anything, such as 'HR Department' or your boss's name. However, spoofing the actual email address (e.g., `[email protected]`) is much harder. They often use similar-looking but fake email addresses, such as `[email protected]` or `[email protected]`.
* **EXPECTED RESULT:** You should see the sender's actual email address, which should be the official domain name of the organization. If it's a free email service like Gmail or Hotmail, or has unusual spelling, be suspicious immediately.
2. **Analyze Unusual 'Urgency and Emotional Pressure'**
* **WHAT:** Observe language that creates a strong sense of urgency, fear, greed, or curiosity.
* **HOW:** Look for words or phrases like 'URGENT', 'Your account will be suspended in 24 hours', or 'Confirm your personal information to claim a reward'.
* **WHY:** This is a social engineering technique used by scammers to make you panic and click without thinking. AI can naturally craft such emotionally manipulative messages.
* **EXPECTED RESULT:** Most legitimate organizational emails use neutral and professional language. They will not pressure you to urgently perform actions related to personal information.
3. **Always Check the Destination 'Link' Before Clicking**
* **WHAT:** Check the actual URL or website address that the link will take you to.
* **HOW:** On a computer, hover your mouse over the link (do not click) and observe the actual URL that appears in the bottom-left corner of your browser or email client. On a mobile device, tap and hold the link, and a small window will display the full URL.
* **WHY:** The text of a link might say `sync-tech.com`, but the hidden URL underneath could be `login.secure-synctech.xyz`, which is a fake website. AI can write persuasive content to make you click, but the link's destination is the most dangerous point.
* **EXPECTED RESULT:** The displayed URL should match the official website of the organization that sent the email and should be relevant to the email's content. If it's an unfamiliar or unusually long URL, do not click under any circumstances.
4. **Consider the 'Context' of the Content: Is It Logical?**
* **WHAT:** Evaluate if the request or content in the email aligns with your current situation.
* **HOW:** Ask yourself: 'Am I expecting this email?' 'Does my boss usually ask me to buy gift cards via email?' 'Why would the bank send an invoice via a .zip file?'
* **WHY:** AI can generate realistic-looking content, but it cannot know your work context or personal relationship with the sender. Therefore, requests that deviate from the norm are critical warning signs.
* **EXPECTED RESULT:** The email content should align with what you expect or be part of a normal workflow.
5. **Look for Overly 'Generic' and Non-Specific Content**
* **WHAT:** Observe greetings or content that do not specify your name or unique personal information.
* **HOW:** Does the email start with 'Dear Esteemed Member' or 'Dear User' instead of your name? Does the content vaguely refer to 'your account' without specifying an account number or other familiar reference information?
* **WHY:** While AI can tailor content to individuals, phishing emails are often sent in large volumes using a common template. A lack of specific information can therefore be a noticeable indicator.
* **EXPECTED RESULT:** Legitimate emails from services you use typically include your name or some information that confirms it is truly sent to you.
6. **Verify Requests Through 'Other' Trusted Channels**
* **WHAT:** If unsure about a critical request, such as a money transfer or providing personal information, verify it through an alternative communication channel.
* **HOW:** If you receive an email from a colleague or your boss, call them, send a message via the company's chat app, or ask them directly. Do not use a reply to that email for verification.
* **WHY:** This is the safest and most definitive way to confirm the authenticity of a request, as it bypasses the potentially compromised email channel entirely.
* **EXPECTED RESULT:** You will receive clear confirmation directly from the person whether the request is genuine or fake.
### Check the Results
You'll know this approach is effective when:
* You can confidently identify and delete suspicious emails without worrying about missing important information.
* You don't fall victim to scams, whether by clicking dangerous links or providing personal information.
* You successfully develop the habit of 'stop-think-click', which is the most crucial security skill.
### If Still Unsure
If you've followed all steps but are still not 100% sure if an email is safe:
* **For work emails:** Forward the suspicious email to your organization's IT department. Do not click anything in that email. The IT department has the tools and expertise to investigate.
* **For personal emails:** If it's not an important email you were expecting, the safest option is to delete it. If you think it might be important from a bank or other service, log in directly through their official website (type the URL yourself in the browser) or call their Call Center using the number provided on their official website to inquire.
In summary, tackling emails in the age of AI isn't about trying to figure out who wrote them. It's about developing critical thinking skills and examining the hidden intent within the message. Constantly questioning and verifying information is the best defense for you and your organization against cyber threats.