Phishing

Scam emails no longer have grammar mistakes: AI writes them better than many people.

Request a consultation

What it is

Phishing is a message (usually an email) that imitates a trusted sender to steal credentials or data, or to get malware installed. With AI the text is flawless in any language, personalised with public information about the victim and produced at scale.

How it works

  1. 1The attacker gathers public information about you or your company.
  2. 2They write a believable email with a reason for urgency and a link to a fake login page.
  3. 3The credentials you enter reach the attacker, who uses them at once, sometimes bypassing codes with pages that relay them in real time.
  4. 4With the stolen account they try to hit your contacts and colleagues.

How to spot it

  • Urgency or threats (“account suspended”, “payment pending”)
  • Sender or domain slightly different from the real one
  • A link whose real address does not match the one shown
  • Unusual requests for passwords, codes or payments, or unexpected attachments
  • Note: the absence of mistakes is no longer a sign of safety

How to defend

  • Do not click: open the site by typing the address or from the official app
  • Use passkeys or security keys, more phishing-resistant than SMS codes
  • Use a password manager: it fills only on the correct domain
  • Verify unusual requests on another channel
  • In companies: email filters, DMARC, simulations and regular training

If you think you have been hit

  • Change the password from a trusted device and sign out other sessions
  • Enable (or restore) multi-factor authentication
  • Tell IT or your bank if you entered payment details
  • Report the message and warn contacts who may receive messages in your name

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.