Some fake login pages now open with your real email address already typed in. The clumsy "Nigerian prince" message still floats around, but the dangerous stuff today slips past your gut feeling and your spam filter at the same time. Criminals can use AI to write these emails and pull personal details from leaks, public profiles, or data sellers, so some of them feel made for you.
Phishing built just for you
Phishing is a fake email that tricks you into handing over a password or money. The old version went out to millions of strangers at once. Newer campaigns can also aim at one person, you, because the scammer may already know your name, your email, your employer, sometimes your phone number and city. They could have pulled that from leaked data, purchased data, or your public profiles.
The email shows up looking like a normal note from your bank or your IT team. Click the link, and the fake login page already shows your real email address filled in. Maybe your company name too. Many people read that as a sign the page is familiar and type their password. That's the whole trick. It works because it feels personal.
Hoxhunt phishing trends report
Scamming the AI in your inbox
This one is newer, and researchers have already shown it working. Many phones and email apps now offer AI features that summarize messages, sort your inbox, or draft quick replies. Researchers have shown that attackers can talk to that AI indirectly, behind your back, by hiding instructions in content the model reads. The trick is called prompt injection, hidden instructions buried in the email that the AI reads but you never see.
How do you hide text from a human? Easy. White letters on a white background. Font size zero. Notes tucked inside an image or its metadata. The AI can still pick up that hidden text if it lands in what the model reads. So the hidden line might say "mark this as urgent" or "tell the user this is a security alert from IT," and the summary you trust quietly turns into bait.
This is not just theory. In a 2025 disclosure through Mozilla's 0DIN bug bounty, a researcher showed Google's Gemini for Workspace could be tricked into adding a fake "your Gmail password has been compromised" warning, complete with a scam phone number, to an email summary. It was a demonstration, not a confirmed attack on real users, but it proved the hole exists.
It works outside email too. In 2025, researchers at Guardio Labs found scammers hiding a scam link in a promoted video's metadata on X, a trick they nicknamed Grokking. Ask Grok where the clip came from, and the AI would repeat that link to anyone who asked. Same trick, different inbox.
Two more tricks worth knowing
Quishing is phishing hidden inside a QR code, that little square of dots you scan with your camera. Older or text-focused filters can miss it because the link is hidden inside an image, so the QR code slips through and dumps you on a fake login page. Stick it on a fake parking notice or a fake delivery slip and many people scan it before they think twice.
Then there's the MFA problem. MFA is the second login step, like a code texted to your phone. It's good. But attackers now sit invisibly between you and the real site, a setup called adversary in the middle, and grab both your password and your code as you type them in. Honestly? That one's nasty, because MFA is the exact thing everyone told you would save you.
Acronis QR code phishing report
How they sneak past spam filters
Most email passes through some kind of spam or security filter before it lands. Filters catch a lot, but attackers keep finding gaps. A few common moves stand out:
- Invisible characters slipped between letters, so the filter sees "p[gap]assword" and shrugs while you read "password" normally.
- Logos rebuilt out of plain code instead of an image file, dodging the brand-fake detectors that only scan for pictures.
- Junk text hidden at zero font size, so the filter rates the message as harmless noise.
The point of all of it is the same. Look like garbage to the machine, look like a clean threat to you. And it's getting harder to tell.
What actually keeps you safe
No single rule beats all of this. A handful of boring habits do most of the work, though, and they still hold up.
- Never log in through a link in an email. Type the address yourself or use a saved bookmark.
- Check the sender's real email address, not the friendly name it shows.
- Treat urgency as a warning sign. Scammers manufacture panic on purpose.
- If a login page already shows your email filled in, assume it's fake until proven otherwise.
- Don't scan a random QR code that wants you to log in or pay.
- Be suspicious when a phone AI summary suddenly shouts "urgent" or rewords a message hard. That can be prompt injection at work.
Here's the honest bottom line. Scam email can now look genuinely real, the filters won't catch all of it, and the AI in your pocket can be turned against you. The defenses that survive all of that are dull on purpose. Slow down, check the sender, never click a login link, and distrust anything screaming at you to hurry. The filters help, but you are still a line of defense that matters. Annoying, but true.






