The most convincing phishing email your finance team gets this year won't have a single typo. It will quote a real thread, match the sender's sign-off, and reference a project only your company knows about. That's the whole trick now, and it's getting cheaper by the month.

The pipeline is simple. Public writing (blogs, LinkedIn, conference talks) is the floor. Mail leaked in old breaches is the ceiling. Best case for the attacker: a live compromised mailbox, which hands over full threads, real signatures, current projects, and the back-and-forth rhythm between two people who actually know each other. Feed that to a GPT-class model and you get a clone that imitates coworkers, vendors, execs, your help desk. Drop the lure into an existing reply chain and it inherits the trust of every legit message above it.

Here's the kind of payload that produces, from one walkthrough of this technique:

"Hey, I need you to review this document before the meeting. Let me know once you've opened it."

Read that as a detection problem. No urgency theatrics. No grammar slip. Every signal your users were trained to key on is absent by design.