How to Train Staff to Spot AI-Written Phishing Emails

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Train Staff to Spot AI-Written Phishing Emails.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Train Staff to Spot AI-Written Phishing Emails.

Stop teaching staff to hunt for spelling mistakes, because AI writes clean, personal emails. Teach them to judge the request instead: anything asking for money, a login, a code or client data, with pressure or a changed route, gets checked through a number or address you already hold. Then drill it monthly and make reporting one click.

The reason the old advice fails is simple. A scammer can now feed a tool your website, your team page and a few public reviews, and get back an email in your supplier's tone that mentions your real opening hours and your practice manager by first name. It will read perfectly. What it still can't do is get paid, or get a password, without someone taking an action. Training works when it targets that action, and a 20-minute first session plus two minutes a month is enough for most small teams.

Follow me on Instagram@sagnikteaches

What AI changed about phishing, and what it didn't

AI made phishing emails cheaper to write well. The typos, odd phrasing and generic "Dear customer" greetings that people were taught to spot are now optional, and a scammer can produce fifty tailored versions in the time it once took to write one. Replies inside an existing email thread, perfect translation into any language, and a tone copied from a real supplier are all easy.

Connect on LinkedInSagnik Bhattacharya

What hasn't changed is the goal. Nearly every phishing email wants one of five things: a payment, a change of bank details, a login, a one-time code, or a file of client or staff data. That is the fixed point your training should hang on. A clean email asking for nothing risky is just an email; a clean email asking for one of those five things deserves a check, however convincing it sounds. The wider picture of how AI raises the risk for small firms is in AI security risks for small businesses.

Subscribe on YouTube@codingliquids

Four questions that still catch a polished fake

Give staff four questions, in this order, and practise them until they are automatic. They work on AI-written emails because none of them depends on bad writing.

  1. What is it asking me to do? Pay, change bank details, log in, share a code, send data, open an unexpected attachment. If the answer is "nothing risky", stop worrying. If it is one of these, go to question two.
  2. Has the route changed? A new bank account, a new email address, a new portal link, "reply to my personal address while I'm travelling", a request moving from email to WhatsApp. Changes of route are where fraud lives.
  3. Is there pressure? A deadline today, a threat of suspension, an unusually senior person asking, a request to keep it quiet. Pressure exists to stop you doing the check.
  4. Can I confirm it another way? Using a phone number or address you already hold, never one from the email. If you can't confirm it, don't act on it.

Two "yes" answers to questions 2 and 3 on a risky request is the signal to stop and verify. Staff don't need to decide whether the email is fake; they only need to decide whether to check.

Three AI-polished examples to train with

Use examples that look like your own post. These three are illustrative, written the way AI-assisted phishing tends to read now, and set in a six-person osteopathy clinic.

Example 1: the supplier bank change

From: Accounts Team <accounts@[yoursupplier]-billing.com>
Subject: Re: Invoice 4471 - updated remittance details

Hi [practice manager's first name],

Thanks again for the order of treatment couch covers and the
massage lotion restock last month. Quick one: we've moved our
business banking as part of our year-end changes, so could you
make sure invoice 4471 ($1,236.40) goes to the new account below?
The old account will close on Friday and payments to it may bounce.

[new account details]

Many thanks, and have a good weekend at the clinic.
Accounts Team

Run the four questions. It asks for a payment to new details (risky). The route has changed: a new account and a sender domain with "-billing" added. There's pressure: the old account "closes Friday". It can be confirmed by calling the supplier on the number from a previous invoice or their website. The friendly tone, the correct product names and the real invoice number are exactly what AI makes easy; they prove nothing.

Example 2: the shared document

Subject: [Osteopath's name] shared "Clinic rota Oct-Dec.xlsx" with you

You have a new shared file. Sign in with your Microsoft 365
account to view and edit.

[Open document]

This link expires in 24 hours.

It asks for a login (risky). The route is a link in an email rather than the file appearing in OneDrive or Teams as it normally would. There's pressure: "expires in 24 hours". The confirmation is easy: open OneDrive or Teams directly and look for the file, or message the colleague. If the file isn't there, it isn't real. A password manager helps here too, because it won't autofill on a lookalike sign-in page.

Example 3: the new patient with an attachment

Subject: Referral notes before my first appointment

Hello, I've booked in for Thursday at 10:30 for lower back pain.
My physio asked me to send you my previous treatment notes and
scan report so you have them in advance. They're in the attached
file (password 2291 as it's medical).

Thanks so much, looking forward to meeting you.

This one targets clinics and service firms because it sounds like normal patient admin. It asks you to open an attachment (risky), and a password-protected archive is a common way to slip past email scanning. The check: is there a Thursday 10:30 booking under this sender's email address? If not, don't open it. If there is, reply asking them to bring the notes, or to use your normal upload route.

Run the first session in 20 minutes

A short, practical session beats an hour of slides. Here is an agenda that fits into a team meeting.

MinutesWhat happensWhy
0-3Show one real phishing email your business received, with the "old" red flags missingMakes the point that clean writing proves nothing
3-8Teach the four questions, written on one cardOne tool to remember, not a list of twenty signs
8-15Pairs work through the three examples above, adapted to your businessPractice beats listening
15-18Show exactly how to report: the button, the channel, what happens nextPeople report when it is easy and thanked
18-20State the payment-change rule (below) and who to callThe single rule that stops the most expensive losses

Tailor the examples to each role in the team

AI lets scammers write for a specific job, so your examples should do the same. In a small team, each role tends to see a different kind of lure:

  • Reception and front desk: fake customer or patient emails with attachments, "your booking system login has expired" messages, and fake reviews platforms asking you to "verify your listing".
  • Whoever pays the bills: changed bank details, invoices that look like real ones with a new payment link, and "overdue, account on hold" threats from utilities or software suppliers.
  • Practitioners and field staff: messages on their phones, including texts with delivery or parking-fine links and QR codes on printed letters, which skip every email filter you have.
  • The owner: impersonation in both directions. Emails pretending to be the bank or the accountant, and emails pretending to be the owner, sent to everyone else.

Give each person one example from their own column in the first session. It takes five extra minutes to prepare and makes the training feel like it is about their job, not a generic video.

Keep it alive with two-minute monthly drills

People forget within weeks unless the habit is refreshed. The simplest drill is to take one real suspicious email reported that month, remove anything personal, and post it in the team chat with the four questions answered underneath. If nobody reported anything, use a "real or fake?" pair: one genuine supplier email and one lookalike.

You can use your approved AI tool to adapt examples to your own business, as long as you frame it as awareness training and keep the output inside the team. A prompt like this works:

I run staff awareness training for a small [osteopathy clinic].
Write two short training emails for a "real or fake?" exercise:
1) a genuine-looking reminder from a supplier we use for
   [treatment couch covers and lotions], asking for nothing risky;
2) a fraudulent version that asks for a payment to new bank details,
   uses a slightly different sender address, and adds time pressure.
Mark each with [TRAINING EXAMPLE] at the top. After them, list the
warning signs in the second email using these four checks:
the request, a changed route, pressure, and how to confirm it.

An illustrative answer to the second part might read: "Warning signs: asks for payment to new bank details (request); sender uses accounts-billing rather than the usual domain (route); says the old account closes in two days (pressure); confirm by calling the number on last month's invoice (confirmation)." That's usable as it stands. What you'd fix: AI often invents a supplier name or a phone number, so swap those for placeholders, and check the "genuine" email really asks for nothing, because models sometimes slip a link in.

Simulated phishing tests, and how to run them fairly

Sending fake phishing emails to your own staff shows who clicks, but it needs care in a small team where everyone knows each other.

  • Microsoft 365. Microsoft's Attack simulation training runs realistic tests and assigns short training to people who click. It needs Microsoft Defender for Office 365 Plan 2 for each user you include; Business Premium alone doesn't provide it, though Plan 2 can be added on top. Microsoft offers a trial through the Defender portal if you want to try one round.
  • Google Workspace and others. Third-party awareness services offer simulations for small teams. Compare them on whether they let you write scenarios about your own suppliers, and how they report results.
  • Doing it yourself. Possible, but tell staff in advance that tests will happen from time to time, and never simulate pay, bonuses, redundancies or health scares. Those erode trust faster than they teach.

Whatever route you take, report results as team numbers, not names. The aim is more reports, not a list of people who failed.

Make reporting easier than deleting

A suspicious email that one person deletes is a missed warning for everyone else. Make reporting a single click and make the response visible.

  • Outlook (Microsoft 365) has a built-in Report button with a "Report phishing" option, which sends the message to Microsoft and, if your admin sets it up, to a mailbox you choose.
  • Gmail has "Report phishing" in the three-dot menu on an open message.
  • A team channel called something like "suspicious" in Teams, Slack or a WhatsApp group, where staff can forward or screenshot anything odd. For a five-person firm, this is often all you need.

Whoever handles reports should reply within the hour with "thanks, it's fake, deleted for everyone" or "thanks, it's genuine". That small reply is what keeps people reporting.

Here is what a good and a bad reaction look like, from a pharmacy that received a reply inside a genuine email thread with its wholesaler, asking to "resend the account-holder form with your login details, our portal reset them":

Bad: "No problem, form attached with our current login." It was a real thread, so it felt safe. The thread had been hijacked from the wholesaler's side.

Good: "I'm not sending logins by email. I'll call your accounts line on the number from our contract to sort it." Then a forward to the suspicious channel. The call confirmed the wholesaler had never sent it.

The first 15 minutes after someone clicks

Training should include what to do when it goes wrong, so people report instead of hiding it. Write these steps on the same card as the four questions:

  1. Tell the named person straight away, by phone or in person, not by email from the account that may be compromised.
  2. If a password was typed in, change it from a different device, and sign out of all other sessions. Microsoft 365 and Google both let an admin do this for a user.
  3. Check the mailbox for new rules. A rule that forwards or deletes emails containing "invoice" or "payment" is a classic sign that someone has been inside the account and wants to stay hidden.
  4. If a payment went out, call the bank immediately using the number on your card or statement. Speed matters more than anything else here.
  5. If an attachment was opened, disconnect the device from the network and ask whoever looks after your IT to check it before it is used again.

Then log what happened and thank the person for reporting it. A clinic that makes this routine calmly will hear about the next incident in minutes rather than weeks.

The payment-change rule that stops the costly ones

Most of the money lost to phishing in small firms goes through changed bank details or urgent transfers. One written rule closes most of that gap. Put it in writing, tell suppliers about it, and make it apply to the owner too.

PAYMENT CHANGE RULE

1. We never change a supplier's, staff member's or customer's bank
   details because of an email, text or message alone.
2. Any request to change bank details, pay a new payee, or make an
   urgent payment is confirmed by phone, using a number we already
   hold (contract, previous invoice, their website), not one in
   the message.
3. The person who confirms writes the date, time and name of who
   they spoke to on the payment record.
4. A second person approves any first payment to new details.
5. This applies to requests that appear to come from the owner.
   The owner will never mind being called to check.

For extra protection, some accounting tools now flag unusual bank-detail changes automatically, and catching duplicate invoices and payment fraud with AI covers how to add that check. The phone call still comes first.

Stolen passwords matter less with a second factor

Training reduces clicks, but someone will eventually type a password into a fake page. A second factor on every account means a stolen password alone doesn't open the account. Passkeys go further, because they won't work on a lookalike site at all. Switching them on for email, accounting and AI tools is the cheapest safety net you can add; turning on two-factor authentication for every AI account walks through each tool.

Measuring whether the training worked

Three numbers tell you enough, tracked monthly in a simple sheet:

  • Reports per month. This should go up after training, which is good news, not bad.
  • Time from arrival to first report. The faster one person reports, the sooner you can warn the others.
  • Risky actions taken. Clicks on simulated tests, or real incidents such as a login entered or a payment made. This should fall towards zero.

Say the six-person osteopathy clinic runs the 20-minute session in October. This is an illustration. In September it had two reports and one near-miss, when reception nearly opened an "appointment notes" attachment. By December, after three monthly drills, it logs nine reports over the quarter, the median time to first report falls from "the next day" to about 40 minutes, and there are no risky actions. Nine reports in a quarter doesn't mean more phishing arrived; it means the team is now seeing it.

When the message is a voice note or video call

The same four questions apply to phone calls, voice notes and video calls, which AI can now fake convincingly in some cases. A call that sounds exactly like the owner asking for an urgent transfer is still a risky request, through a changed route, with pressure. Hang up and call back on the number you hold. The details of voice and video scams are covered in spotting deepfake voice and video scams aimed at your business.

A plumbing firm's office manager might get a voice note on WhatsApp that sounds like the owner: "I'm on a job, phone's dying, can you pay the merchant's invoice to this new account before 3?" The request is money, the route is new, the pressure is the deadline. A two-minute call to the owner's normal number ends it. That's the whole of good phishing training in one example: nobody had to spot a fake, they only had to follow the rule.

Further reads

Sources: Microsoft Learn, Attack simulation training licensing and FAQ (Microsoft Defender for Office 365 Plan 2); Microsoft Support, reporting phishing in Outlook; Google Gmail Help, report phishing.

Want a phishing drill built around your own suppliers?

On a 1:1 call we'll look at which emails in your business carry money or logins, write the verification rules for them, and set up a reporting route your team will use.

Book a 1:1 call with me