Where I Think Phishing Emails Are Headed Next
People ask me constantly whether phishing is getting better or worse, and the honest answer is both at once. The volume of obviously bad attempts hasn't dropped, but the quality of the convincing ones has jumped in a way I genuinely didn't expect this quickly. Here's what I'm actually seeing change, and what I think is coming next.
None of this is guesswork pulled from a headline. It's patterns I notice in the messages people forward me to check, week after week, and where those patterns seem to be heading. I'd rather flag what's actually changing than repeat the same tired warnings about dodgy spelling and suspicious attachments, since the people reading this have usually heard those already.
The Sender Games Are Getting Better
AI tools mean phishing emails read more fluently now, sound more local, and reference real details scraped from LinkedIn or a company website. The bad spelling giveaway is fading fast, so I lean more on checking the actual sender address and less on typos as a red flag. I've written about the red flags I always check first, and that habit matters more now than ever, not less. What used to take a scammer real effort, writing convincingly, researching a target, matching a company's tone, now takes a few minutes with the right prompt, which means the volume of genuinely convincing attempts is only going to climb.
Voice and Video Are Joining the Email
It's not just email anymore. I'm seeing phishing attempts paired with voice notes or video clips generated to sound like someone you know, following up on an email to make it feel more convincing. If someone claiming to be a colleague or family member pushes you toward an urgent request by email and then by voicemail, that combination alone is worth treating as a red flag. A few seconds of someone's voice from a video call, a podcast appearance, or a social media clip is genuinely enough to clone a passable imitation now, and I expect this to become a standard part of the more targeted attempts within the next year or two, not a rare exception.
QR Codes Are Becoming the New Weak Spot
Quishing, phishing delivered through a QR code instead of a link, is one I'm getting asked about more often, and I think it's only going to grow. A QR code hides its destination until you've already scanned it, which sidesteps the hover-and-check habit that catches so many suspicious links. I'm seeing them turn up on fake parking fine notices, printed flyers stuck over genuine ones, and even emails asking you to "scan to verify" your account rather than click through directly, since a QR code image is also a neat way to slip past filters that would normally flag a suspicious link in plain text. My advice is simple: treat a QR code with exactly the same suspicion as a link you can't see the destination of, because that's precisely what it is. If your phone shows a preview of the destination before it opens the page, always read it, and if there's no preview at all, that's a reason to be more cautious, not less.
Fewer Mass Blasts, More Targeted Attempts
Spray and pray phishing hasn't gone away, but I'm seeing more attempts that clearly did some homework first, mentioning your actual employer, a recent order, or a real event you'd genuinely have reason to be following. That personalisation is designed to lower your guard, and it works, because it exploits the same instinct that makes us trust a message that seems to already know us. Slow down precisely when an email feels like it knows you, that familiarity is the manipulation, not a reason to relax.
What Actually Still Works Against It
None of this changes the basics much, which is honestly the most reassuring part of all this. Verify through a second channel, don't click links in unexpected emails, and turn on two factor authentication so a convincing email alone isn't enough to get into your accounts. A password manager like NordPass also means you're not reusing the same password across every account a scammer might target, and it won't autofill your details on a lookalike page even when everything else about the message looks completely genuine. If you do fall for a convincing one, report it through Action Fraud so it's on record, since that's part of what helps the next version of the scam get caught earlier.
The One Prediction I'm Fairly Confident About
I think the gap between "obviously fake" and "genuinely convincing" phishing is going to keep narrowing until it mostly disappears, which means the old advice of spotting scams by their mistakes has an expiry date. What replaces it is a shift in mindset rather than a new checklist: treating urgency and unexpected requests for money, login details, or personal information as the actual red flag, regardless of how polished, personal, or familiar the message sounds. The tell moves from how a message looks to what it's asking you to do.
Staying Ahead Without Becoming Paranoid
I don't think the answer is to distrust every email that lands in your inbox, that's exhausting and not sustainable, and it isn't how I live either. It's to build a habit of pausing on anything asking for money, login details, or urgent action, regardless of how convincing it looks, and to keep that habit running quietly in the background rather than treating every message as a fresh investigation. My Safety Toolkit has more on building that habit properly, and if you want a second opinion on something that's landed in your inbox, feel free to get in touch. I'd genuinely rather you ask than guess.
