Security1 distinct publisher2 min readPublished
The claim arrives as a Barracuda-authored commentary with one number behind it. The bill lands on awareness programs whose template libraries and click-rate baselines were built on deliberate typos.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Start with the measurement, because that is where the money is. A simulation program reports click rate and report rate against a template library. When those templates carry deliberate spelling and grammar errors, the trend line records how staff respond to one specific cue. Replace the library with fluent, personalized mail and the number moves for reasons that have nothing to do with employee behaviour or with any control you changed. That break in the line is itself the finding. Somebody has to say so to whoever has been reading the year-over-year slide.
The verification advice is cheap to say and not cheap to run. The column's worked example is an employee who gets a payment request that appears to come from their manager, and the escape is a phone call to the manager rather than a reply to the message [10]. That call only exists if the employee already holds a number that did not arrive in the email [9]. Same problem with "requests that break established business workflows" [7]: a workflow has to be written down before anyone can notice it being broken, so a vendor changing bank details is only a red flag where a documented bank-change procedure exists. The deliverable is a known-good contact directory and an approval path. The training deck is the inexpensive part of this.
The claim is also checkable in-house, which matters more than the percentage. Pull the mail your own users reported last quarter and compare it against the templates your simulation vendor ships. If the reported corpus still carries the clumsy phrasing your library imitates, the library is not stale yet for your mail flow. If it does not, your baseline is already measuring a cue your users no longer see. That comparison takes an afternoon and answers the question for your organisation specifically, which no external figure does.
Rate the document for what it is: an SC Media Perspectives column, written by a member of that publication's contributor community [12]. There is no CVE here, and no named actor or dated campaign attached. Nothing in this piece has to be closed by Friday. What is under review is a twenty-year training habit that the author says taught people to spot phishing through bad grammar, awkward phrasing and clumsy translation [6]. The habit is durable because it was easy to teach and easy to test. Both of those properties are what make it expensive to retire.
Ranked by verification strength, evidence, and original report placement.
An SC Media Perspectives commentary states that "look for spelling mistakes and bad grammar" was for years one of the defining pieces of advice for spotting phishing attempts.
The column argues that anyone can now use generative AI to create polished, personalized phishing emails in seconds, rendering the typo-and-grammar advice increasingly irrelevant.
The column says that for 20 years people were taught to spot phishing by looking for bad grammar, awkward phrasing and clumsy translation, and calls that playbook obsolete.
The column's recommended replacement signals are urgency designed to bypass normal processes, requests that break established business workflows, and pressure to stay within the attacker's communication channel.
The column recommends that employees independently verify unusual or high-risk requests through a different known contact method rather than replying to the message.
The column's example: an employee receives an email appearing to be from their manager asking for a payment to a vendor; following the instructions sends money to the attacker, while a phone call to the manager exposes the scam.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
California's AI security push is really a hiring order: one AI cyber officer per agency1 distinct publisher
security
A volunteer SOC for 45,000 water systems: what the Water Watch Center asks of operators1 distinct publisher
security
66% of mobile banking trojans now take the whole device, and 45% ask for a ransom1 distinct publisher
security
Seventeen thousand tries: the Hugging Face agent found ordinary bugs at a rate humans cannot fund1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One self-cited number
Everything traceable here comes from a single commentary, and its only statistic is introduced as "recent Barracuda research" and then reclaimed as "our research" three paragraphs later — no study name, sample, window or link. The descriptive parts hold up because they describe the column itself; the empirical parts, including the claim that attackers have moved on from broken grammar, rest on assertion.
Nobody has said they changed anything
Not one organization in this reporting is shown retiring a typo-based template, rewriting a simulation, or adopting a call-back verification rule — and the 90% figure measures criminal tooling, not defender behaviour. Prescription is not uptake, so we leave this unscored rather than read adoption into a recommendation.
Headline outruns the statistic
"AI killed the typo" is a claim about who writes phishing mail. The 90% figure is a claim about whether campaigns rent their infrastructure — a different thing, and one that would be true even if every lure were hand-typed by a human. That mismatch, plus an unquantified assertion that generic blasts are being replaced by tailored mail, is where the overstatement sits. The underlying advice is sober; the framing around it is not.
Vendor argues for the refresh cycle
The number and the conclusion share an author. A commercial party in the phishing-defense business supplies the statistic, then recommends that organizations rebuild their awareness and simulation programs — a conclusion that happens to generate work in its own market. SC Media's contributor label makes the arrangement visible, which is more than many vendor bylines offer, but the column never says what the author's employer sells.
Sure what was said, unsure it is so
We can state with near-certainty what this column argues and who is behind its one number. Whether the underlying picture is accurate — how much phishing is now AI-written, what share of simulation libraries still trade on misspellings — is unknowable from what is in front of us, and a single unverified source keeps the ceiling low.