Ask most business owners how to spot a phishing email and you’ll get a familiar answer: clumsy spelling, an odd sender address, a logo that’s slightly off. For years that advice has held up reasonably well. It’s becoming less reliable by the month.
Across Eastbourne, Hastings, Crawley, Worthing and the rest of Sussex, plenty of small and medium-sized businesses have built their cyber security habits around exactly this kind of advice, look for the obvious signs, click carefully, and you’ll usually be fine. The next generation of phishing attacks is being designed specifically to get past that approach.
The old approach to phishing
Traditional phishing relies on volume rather than precision. A criminal builds one fake website, often a convincing copy of a bank or supplier login page, and sends the same email to as many inboxes as possible, hoping a small percentage of people click through. Because the fake site is fixed, security tools and alert staff can eventually spot it, report it and have it taken offline.
That model isn’t disappearing overnight, but researchers have already shown how artificial intelligence could replace it with something considerably harder to catch.
A phishing page built especially for you
Instead of one static fake website, this newer method uses AI to generate the page itself, in real time, inside the visitor’s own browser. Someone clicks a link, and the page that loads quietly asks a legitimate AI tool to produce the content there and then, the wording, the layout, even the underlying code, built specifically for that one visit.
Because nothing fixed exists until someone actually opens the link, there’s no single fake page for filters or security teams to flag and remove. Every visit can look slightly different, which makes a lot of today’s detection methods far less useful.
This approach is still largely experimental. But the building blocks behind it, AI used to write malicious code, malware that assembles itself as it runs, and AI-assisted scams more generally, are already in active use. It’s a reasonable bet that fully dynamic, AI-built phishing pages are a matter of when rather than if.
Why smaller, local businesses can’t assume they’re not a target
It’s tempting to assume this kind of attack is reserved for large, well-known organisations rather than an accountancy practice in Crawley or a retailer on Worthing high street. In practice, criminals don’t filter by postcode or company size, and the National Cyber Security Centre (NCSC) has been clear that organisations of every size face phishing attempts, with smaller businesses often more attractive precisely because their defences and security teams tend to be lighter.
If your business in Eastbourne, Hastings or anywhere else across Sussex doesn’t have a dedicated IT security team watching for this kind of threat, that’s exactly when a more convincing, AI-built scam becomes most dangerous, because the old advice of “look for the mistakes” simply stops applying.
What actually helps now
The most reliable defence against this shift isn’t training everyone to spot every fake. It’s making sure that one successful click doesn’t turn into a serious incident. In practice, that means:
- Multi-factor authentication on every account that supports it
- Secure browsers and endpoint protection that’s kept up to date
- Email filtering that flags suspicious links before anyone gets the chance to click
- A clear, blame-free process for staff to report anything that looks suspicious
None of these measures depend on someone noticing a typo or an odd logo. They keep working even when the scam in front of someone looks entirely convincing.
If a suspicious email lands in your inbox, you can report it directly using the NCSC’s phishing reporting service. If your business has actually lost money or been compromised, that should be reported to Report Fraud (the service previously known as Action Fraud), the UK’s national reporting centre for fraud and cyber crime.
The assumption worth changing
Phishing isn’t going away, it’s adapting. The safest approach for any business, whether you’re based in Hastings, Worthing, Crawley, Eastbourne or anywhere else in the UK, is to assume the next scam reaching your inbox will look entirely legitimate, and to build your defences around limiting the damage rather than relying on spotting it first.