Sicon

Super Intelligence Consultants
Seattle, Las Vegas, Silicon Valley

Build your plan

Insights / Threat defense

The next phishing email will be flawless

Bad grammar used to give attackers away. AI took that tell off the table, so your defenses have to move from spotting to verifying.

Lookalike email quarantined before anyone clicks

For twenty years, security training taught people to look for mistakes: odd grammar, a generic greeting, a logo that looked a little off. That advice is now out of date. Language models write clean, specific, well-timed email in any language, and they can read your company’s website, press releases and LinkedIn pages first.

The same goes for voice and video. A few minutes of recorded speech, easy to find for most executives, is enough to clone a voice convincingly. In early 2024 a finance employee at the engineering firm Arup joined a video call with what looked like the company’s CFO and several colleagues. All of them were deepfakes. The employee made fifteen transfers totalling about US$25 million before anyone realised.

FromDana Ruiz, CFO <dana.ruiz@yourcornpany.com>rn, not m

SubjectConfidential: acquisition wire, today please

I need this transfer processed before 3pm. I’m in back-to-back meetings, so please don’t call. Keep it between us until the announcement.

Fluent, specific, urgent, and one letter off. Checking the address won’t catch it every time. Calling a number you already have will.

Stop trying to spot fakes

People are bad at detecting a good fake, and the fakes are improving faster than people are. The durable fix is to make the decision not depend on whether the message looks real.

  • Verify on a second channel. Any request to move money, change bank details or reset access gets confirmed by calling a number you already had, never one in the message.
  • Use code phrases for the few people who can authorize payments. Agree them in person and rotate them.
  • Require two people for anything irreversible. Attackers can fool one person under time pressure; fooling two is much harder.
  • Make it safe to slow down. Leaders should say out loud that nobody gets in trouble for verifying a request from them.

The durable fix is to make the decision not depend on whether the message looks real.

Rehearse it

A policy nobody has practised fails under pressure. Run consented drills: a cloned-voice call to the finance team, a spoofed vendor asking to change bank details. Then debrief without blame. The goal isn’t to catch people out. It’s to make the pause a habit.

If you want help setting this up, our AI threat defense work covers the exposure review, the protocols and the drills.

Related service

Tell us what worries you about AI. We’ll send back a plan.

Build your plan