Phishing in the AI Era

Week 1: Phishing in the AI Era
See Something. Say Something. Report It.
Phishing is when criminals send a message designed to trick you into clicking a link, opening a file, sharing information, or sending money. It is still one of the most common ways scammers get in. In the National Cybersecurity Alliance’s 2025 survey, phishing accounted for 40% of the cybercrime incidents people reported.
What’s new is how convincing phishing has become. Artificial intelligence (AI) lets scammers write flawless messages, copy a familiar writing style, and even clone voices, all in seconds. The old advice to “look for typos” no longer works. This week, learn what to watch for instead, and what to do when something feels off.
How AI Is Changing Phishing
The FBI warns that criminals now use generative AI to make fraud faster and more believable:
- Text: Polished, personal-sounding emails, texts, and social media messages, often built from details you or your organization have posted publicly.
- Images: Fake profile photos, IDs, and documents that make a fake person or business look real.
- Voice: Cloned voices of family members, coworkers, or supervisors asking for urgent help or money.
- Video: Deepfake video of executives or other authority figures, sometimes on live calls.
| Type | What it looks like |
|---|---|
| Smishing (text) | A text about a delivery, a bank alert, a toll bill, or your financial aid, with a link to “fix” the problem. |
| Vishing (voice) | A call from “the Help Desk,” “your bank,” or a loved one, possibly with an AI-cloned voice, asking for codes, payment, or remote access. |
| Quishing (QR code) | A QR code in an email, flyer, or parking notice that leads to a fake sign-in or payment page. |
| Business email compromise | A message that appears to come from a supervisor or vendor, asking for gift cards, a wire transfer, or a change to banking or payroll details. |
| Social media and messaging apps | A friendly stranger, recruiter, or “investment advisor” who builds trust over time before asking for money or information. |
Spot the Scam: Five Fictional Examples
These examples are fictional and were written for training. They show common patterns, not actual messages sent to CCRI.
1. The financial aid “hold” (students)
The message: A text reads: “CCRI Financial Aid: Your refund is ON HOLD. Verify your account within 24 hours to avoid cancellation,” followed by a short link.
The tell: A deadline designed to rush you, a shortened link, and a text asking you to sign in.
The safe move: Don’t tap the link. Check your status by signing in to MyCCRI directly, or contact Financial Aid (One Stop Student Services).
2. The too-good remote job (students)
The message: An email offers a flexible remote assistant job for $500 a week. After a quick chat interview, they mail you a check to deposit and ask you to send part of it back for “equipment.”
The tell: No real interview, pay that seems too high, and a request to send money back. According to the FTC, this is a common fake-check scam aimed at job seekers.
The safe move: Never deposit a check and return money. Look up the company with words like “scam” or “complaint.” Ask CCRI Career Services before you respond.
3. The urgent request from a “dean” (faculty and staff)
The message: An email that looks like it’s from a senior administrator says: “I’m in meetings all day and need a favor. Please pick up six $100 gift cards for a staff recognition event and send me the codes. Keep this between us for now.”
The tell: Gift cards, secrecy, urgency, and a request to skip normal purchasing. The sender’s address may be a personal account or carry the yellow [External] tag.
The safe move: Don’t reply to the email. Call or message the person using contact information you already have, then report the email.
4. The vendor with new bank details (faculty and staff)
The message: A familiar vendor writes: “We’ve changed banks. Please update our payment details before Friday’s invoice is paid,” and attaches a form with new account numbers.
The tell: A banking change requested by email, plus time pressure. Scammers often take over or imitate real vendor email accounts.
The safe move: Confirm any payment or banking change by phone, using a number already on file, before anything changes. Then report the email.
5. The panicked phone call (everyone)
The message: You get a call that sounds exactly like a family member: “I’ve been in an accident and I need money right now. Please don’t tell anyone.”
The tell: Emotion, urgency, secrecy, and a request for money. AI can clone a voice from a short audio clip.
The safe move: Hang up and call the person back at a number you know. Consider agreeing on a family “safe word” ahead of time, as the FBI and National Cybersecurity Alliance recommend.
Red Flags, Even When the Message Looks Perfect
- Pressure to act fast, keep a secret, or skip the usual process.
- Requests for your password, MFA codes, gift cards, payments, or changes to banking or payroll details.
- Links, attachments, or QR codes you weren’t expecting, even from someone you know.
- A sender address, phone number, or web address that’s slightly off.
- A message claiming to be from CCRI that carries the yellow [External] tag.
- An offer that seems too good to be true, like easy money, a guaranteed investment, or a prize you didn’t enter for.
Stop. Verify. Report.
- Stop: Don’t click, reply, scan, or call back numbers from the message.
- Verify: Contact the person or organization using a phone number, website, or app you already know.
- Report: In Outlook, select the message, select Report, then choose Report Phishing (or Report Junk for spam). Forward scam texts to 7726 (SPAM). Report suspicious calls or texts involving your CCRI account to the IT Help Desk.
Already Clicked? Act Fast. You’re Not in Trouble.
Reporting a suspected phishing attempt is never a mistake, even if you already clicked. The sooner we know, the faster we can protect you and the college.
- Contact the IT Help Desk right away: [email protected] | 401-825-1112 | Help Desk portal.
- If you entered your CCRI password on a suspicious page, change it immediately using Reset Password.
- If you shared banking or payment information, contact your bank as well.
This Week’s Challenge: Phishing in the AI Era Crossword
How sharp are your scam-spotting skills? Download the crossword, and check your answers when the key is posted on October 12.
- Download the Week 1 Crossword (PDF, 1 page)
- Week 1 Crossword Answer Key (PDF, 1 page)
Free Resources
- AI Fools: Stay Sharp! (National Cybersecurity Alliance)
- Why Your Family and Coworkers Need a Safe Word in the Age of AI (National Cybersecurity Alliance)
- How to Protect Yourself Against Deepfakes (National Cybersecurity Alliance)
- AI and the Future of Phishing: Interactive Tool (National Cybersecurity Alliance)
- Criminals Use Generative AI to Facilitate Financial Fraud (FBI)
- How to Recognize and Avoid Phishing Scams (FTC)
- How to Recognize and Report Spam Text Messages (FTC)
- College Students: Avoid Scammers While You Job Hunt (FTC)
- Recognize and Report Phishing (CISA)
- Recognize and Report Phishing (CCRI)
- Spam and Phishing Support (CCRI IT Help Desk)
Up next, October 12: Protecting Your Devices at Work and Home.
Every faculty member, staff member, and student is part of CCRI’s cybersecurity team. See something? Say something. Report it.
Sources
National Cybersecurity Alliance, “Cybercrime Victimization Climbs to Record High 44% Over Five-Year Period” (press release). FBI Internet Crime Complaint Center, PSA241203, December 3, 2024 (link). Federal Trade Commission consumer guidance (linked above).