The old advice was look for bad grammar, check the from address, be suspicious of urgency. That advice matched a world where phishing was a million identical emails written in broken English.

That world is gone. The emails are clean. They use your company name. Sometimes they use a colleague’s name. Sometimes they skip email and call, sounding like someone you know.

If your IT company’s idea of protection is an annual video and a spam filter, they are defending last decade’s problem.

The email is no longer the tell

AI writes fluent mail in whatever tone the attacker wants. It can pull a job title, a coworker, and a live project off public pages and write something that looks internal.

You should not be expected to catch that by squinting at commas. People will click a good fake. The provider’s job is to make that click expensive for the attacker: filtering, safe links, and a way to report it that someone actually reads.

The voice on the phone can be fake too

A few minutes of public audio is enough to clone a voice. The pattern is an email that looks like the owner, then a call that sounds like the owner, asking for a wire.

That is not something the office manager should have to “just know.” There should already be a rule, enforced by your IT and finance process, that money does not move on email or a surprise call. Your provider should have helped you put that in place, not emailed you a tip sheet.

QR codes walk around the filter

A lot of email tools are decent at links. Attackers put a QR code in the message instead. The filter sees an image. The phone opens the site off the company network.

This is why “we have email security” has to mean more than a spam score. Someone has to be tuning for the current tricks, not the ones in the product brochure.

MFA is necessary. It is not the finish line

MFA still stops a lot of stolen passwords. Attackers now sit between the user and the real login and steal the session after the code is approved.

So MFA has to be the right kind, on the right accounts, with someone watching for the rest. An IT company that says “you have MFA, you are fine” stopped too early.

What we do We run current phishing defenses, not a once-a-year slideshow. That means the Microsoft 365 protections, reporting that we actually see, and financial-request rules so one good fake email cannot empty an account.

What to ask them

Ask how they handle QR lures, voice impersonation, and MFA bypass. Ask when they last ran a simulated phish that looked like this year, not 2018.

If the answer is training video plus spam filter, reach out. We will tell you what is actually in front of your inboxes.