AI Can Write It. Can You Spot It?
AI is making phishing scams more realistic and harder to spot. From fake emails to convincing messages, scammers are using AI to trick students and employees into clicking, sharing information, or giving up passwords. Here’s how to spot the signs before you take the bait.
Think you can recognize a phishing email? Think again.
For years, cybersecurity awareness has taught us to look for obvious warning signs: misspelled words, strange email addresses, awkward wording, suspicious links, and urgent requests for money or passwords.
Those clues can still be useful. But artificial intelligence is changing the game.
Today, scammers can use AI to create convincing emails, text messages, and even voice recordings in seconds. Instead of receiving a message filled with obvious mistakes, you might get a polished email that appears to come from a professor, supervisor, university office, or even a friend.
For members of a campus community, that means cybersecurity awareness is more important than ever.
What makes AI-powered phishing different?
Traditional phishing messages often rely on volume. Attackers send thousands of generic messages and hope that a few people respond.
AI can make those messages much more convincing and personalized.
A scammer might use information publicly available online such as your name, major, job title, or even campus organization to create a message that sounds relevant to you.
For example, you may receive an email that appears to come from IT warning that your Montclair account will be deactivated unless you take immediate action. The message may include university branding, professional language, and a link to a fake login page designed to steal your credentials.
Another common scam involves fake file downloads. You might receive a message with a link to a document that appears to be related to work, class, or a shared file. Instead of opening a legitimate document, the link may take you to a fake download page or malicious website.
The technology behind the message may be sophisticated, but the goal is usually familiar: get you to click, share information, transfer money, or give an attacker access to an account.
Don't rely on grammar alone
One of the biggest changes AI brings to phishing is that poor grammar is no longer a reliable warning sign.
A well-written message can still be fraudulent.
Instead of asking, “Does this email look professional?” ask:
“Was I expecting this request, and does it make sense?”
Pay particular attention when a message asks you to:
- Enter your password or other login information
- Open an unexpected attachment
- Click a link to “verify” or “restore” an account
- Send money or purchase gift cards
- Share sensitive student, employee, or research information
- Bypass normal university procedures
- Act immediately because of a supposed emergency
Urgency is especially important. Scammers want you to react before you have time to think.
Slow down before you click
When a message creates a sense of urgency, take a moment to verify it independently.
If an email claims to be from Montclair's IT department, don't automatically click the link in the email. Instead, go directly to the official website or use a trusted bookmark to access the relevant service.
If someone appears to be asking for money or sensitive information, contact them through a known phone number or another established communication channel.
And remember: a familiar name in the “From” or signature field doesn't necessarily mean the message came from that person.
Your accounts are worth protecting
A compromised Montclair account can be more than an inconvenience. Depending on the account and your role, an attacker could potentially access email, files, research information, financial information, or other systems.
All Montclair accounts require Duo multifactor authentication (MFA). For stronger security, we recommend using Duo Mobile or a security key rather than less secure authentication methods when available.
Don’t stop there. Enable MFA on your personal accounts, including email, banking, social media, and other important services. MFA adds an extra layer of protection if your password is compromised.
Never approve a Duo request you didn’t initiate. If you receive an unexpected Duo prompt, deny it and report it.
What if you already clicked?
Don't panic.
Cybersecurity mistakes happen. The most important thing is to respond quickly.
If you clicked a suspicious link, entered your password into a questionable website or form, downloaded an unexpected attachment, or provided sensitive information:
- Stop interacting with the message.
- Change your password if you entered it into a suspicious site.
- Report the incident to phishfiles@montclair.edu.
- Tell us what happened, including what you clicked or what information you provided.
- Watch for additional suspicious messages or login notifications.
Reporting an incident isn't about assigning blame. Early reporting can help our team protect you and prevent the same attack from affecting other members of the campus community.
Cybersecurity is a community responsibility
Technology will continue to evolve, and so will the techniques used by cybercriminals. AI may make phishing messages more convincing, but the best defense remains the same: pause, verify, and think before you act.
No student, faculty member, or employee is expected to identify every sophisticated scam perfectly. What matters is developing habits that make it harder for attackers to succeed.
The next time you receive an unexpected request especially one involving passwords, money, sensitive information, or urgent action take a moment.
Don't let a convincing message make the decision for you.
When in doubt, verify the message through a trusted channel, contact the Phish Files, and report suspicious messages using the PAB.
- Published
- Type
- Topic