ChannelLife New Zealand - Industry insider news for technology resellers
New Zealand
AI scams make phishing harder to spot, Vertech warns

AI scams make phishing harder to spot, Vertech warns

Fri, 28th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Vertech has warned that artificial intelligence is making online scams harder for businesses to detect, as traditional signs of phishing become less reliable.

Daniel Watson, managing director at Vertech, said scammers can now use AI to produce emails that look far more authentic than the clumsy messages that once raised immediate suspicion.

"Bad English used to give people an immediate reason to be suspicious. AI means a scammer can now produce an email that is grammatically correct, professionally written and much closer to the sort of communication a business would normally expect to receive.

"The issue is more than spelling and grammar because the language itself can be made more plausible. If somebody is targeting a professional services firm, a logistics company or another business, they can produce communications that sound much more like the way people in that industry actually speak to each other," Watson said.

He said the shift goes beyond email. Text messages, audio, images and video can now be generated or altered at scale, widening the range of tools available to criminals.

Scammers are also likely to combine these methods with AI agents that can hold conversations and guide people through fraudulent transactions without immediately appearing suspicious, Watson said.

He cited a recent example involving an experienced salesperson.

"I know of an experienced salesperson who spent about 45 minutes discussing a vehicle purchase with what he believed was another salesperson. When he rang back the following day, he discovered the person he had spoken to didn't exist. He had been talking to an AI agent.

"That should concern business owners because people are becoming accustomed to dealing with bots and AI agents as part of legitimate business processes. A criminal can potentially use exactly the same technology to build trust, answer questions and move somebody towards making a payment," Watson said.

Verification checks

Vertech argues that businesses should place more weight on independent verification, especially when staff receive requests involving payments, changes to bank account details or sensitive commercial information.

Watson said staff should avoid relying on contact details supplied in a suspicious message and instead use information already known to be genuine.

"If somebody sends you an email saying they are from a bank, don't use the phone number supplied in the email. Find the bank's number independently, call it and ask to be put through to that person.

"The same principle applies when a supplier tells you their bank account details have changed. Confirm the change using contact details you already know to be legitimate before anybody transfers the money," Watson said.

That advice reflects a broader shift in cybersecurity practice, as organisations move away from judging whether a message looks genuine and towards proving who is behind it.

Watson said established processes matter most when significant sums are at stake.

"If you were buying a car or a house, you would want to know who you were dealing with and see what you were buying. Yet people will sometimes send significant amounts of money to somebody they have never met because the email, website or conversation appears convincing.

"AI is making those appearances more convincing, so businesses need procedures that do not depend on whether somebody thinks an email looks genuine. Verification needs to happen independently," Watson said.

Social engineering

The warning highlights a familiar cybercrime tactic taking a new form. Social engineering has long relied on trust, urgency and impersonation, but AI allows those methods to be used more fluently and at greater scale.

For smaller companies in particular, that creates a practical challenge. Many have trained staff to spot obvious red flags such as spelling mistakes, poor grammar or awkward phrasing, yet those indicators are becoming less dependable as generative AI tools improve.

Watson said employee awareness remains important, but it is no longer enough on its own.

"The old advice about looking for spelling mistakes isn't enough anymore. Staff still need cybersecurity awareness, but businesses also need processes that assume a convincing email, phone call or online conversation may not be what it appears to be.

"The safest question is no longer simply, 'Does this look genuine?' It is, 'Have we independently verified who we are dealing with?'" Watson said.