How AI Is Making Phishing Attacks Harder for Schools to Detect
Most districts have a version of the same slide. Check for spelling errors, watch for odd grammar, be suspicious of generic greetings and urgent language. It has been sitting in staff onboarding decks for years.

That advice was never really about phishing. It was about the people sending it and what they could produce cheaply at volume. AI phishing, meaning phishing written or cleaned up with generative tools, has weakened that constraint, and the checklist has not caught up.
The Old Checklist Was Built for a Different Attacker
Bad grammar was never inherently part of fraud. It was often a byproduct of rushed, mass-produced messages or language barriers.
The tells schools trained on were the cheapest available, which made them the easiest to remove once removing them stopped costing anything. So the checklist did not become wrong. It became unreliable, which is worse, because staff still trust it.
Generative AI Makes the Cheap Tells Easy to Remove
The FBI has been explicit about this. Its public warning on generative AI and fraud notes that these tools assist with content creation and can correct for human errors that might otherwise serve as warning signs, and that criminals use them to limit grammatical and spelling mistakes when targeting US victims. The same alert names AI-generated text as support for spear phishing specifically.
Spelling and grammar are the errors the FBI describes the technology fixing. They are also among the familiar warning signs commonly taught in phishing-awareness training.
Which creates a measurement problem for anyone running simulations. If test emails still rely heavily on tells that attackers can now remove more easily, the exercise may place too much weight on cues that attackers can now remove easily. Keeping simulations current is partly a tooling question. Among the school-specific options, https://tartan.app/ uses AI to personalize simulations and training around roles, tools, difficulty, and user behavior.
Your District Publishes the Research Material
School districts often make more operational information public than many organizations realize, whether through public records requirements, board documents, staff directories, calendars, or procurement information. Most of it is published deliberately, and most of it should be.
None of that is a weakness on its own. It becomes one when writing a message that references the right assistant principal, the right vendor and the right week costs an attacker almost nothing.
A generic phish asks a stranger for money. A message mentioning the curriculum platform your board actually renewed in June, sent to the person who signs those approvals, is a different kind of request.
Detection Difficulty Is Measurable, and AI Pushes the Wrong Way
NIST’s Phish Scale considers both the cues in a message and how closely its premise aligns with the target audience’s context, helping trainers classify the difficulty of a simulated phish.
AI can reduce some of the obvious cues that make phishing easier to spot, while publicly available information can give attackers more context for building convincing premises. Together, those changes can produce harder-to-detect phishing scenarios.
That is the mechanism behind the headline. AI-assisted phishing can become harder to catch when it removes obvious cues while using context that closely fits the recipient, the same two dimensions the Phish Scale uses to assess detection difficulty.
The Attack Does Not Stay in the Inbox
The same FBI alert covers AI-generated audio and video, including cloned voices and real-time video calls impersonating company executives, law enforcement and other authority figures.
For a district, the exposure sits at the approval step. A request delivered in a convincing imitation of the superintendent’s voice may carry more authority than the same request arriving as an unfamiliar email.
Verification has to move to a channel the attacker does not control. A callback to a number from the internal directory rather than the number in the message. An agreed phrase for payment changes. Dull, and it works.
SHORT CHECKLIST: |
What to Change Before Next TermThe fixes here are mostly procedural, which matters for districts with small technology teams. ● Retire the spelling slide. Replace grammar hunting with source verification. Where did this actually come from, and does the request make sense for this person? ● Rate what you send. A campaign with no difficulty rating attached cannot be compared to last quarter’s campaign. ● Move verification off the channel. Payment changes, credential resets and urgent approvals get confirmed by callback, every time, no exceptions for people who sound senior. ● Train the reflex, not the checklist. The behavior worth building is reporting something that feels off, including when the reader cannot say why. |
That last one matters more as the tells disappear. A staff member who cannot articulate what is wrong but forwards the message anyway is doing exactly the right thing.
Wrap Up
The uncomfortable summary is that many security-awareness programs have trained people to look for a specific kind of sloppiness, while attackers have become better at eliminating it.
What replaces it is slower and less satisfying. Verify requests through a second channel, keep simulations current with what attackers can now produce, and make reporting the easy default rather than the thing that gets someone a lecture. None of that fits on a poster, which is probably why it works.