That urgent bank email might be fake. Check it in seconds. Scammers count on you acting fast, this makes you pause and check first, every time, in under a minute.
| BEC losses 2024 | $2.77 billion across 21,442 reported incidents in the US, FBI IC3 |
|---|---|
| BEC losses 2013-2023 | $55.5 billion in global exposed losses across 305,033 incidents, FBI IC3 |
| Core red flags | Urgency or threats, mismatched sender or link domain, generic greeting, unusual payment or credential requests |
| Verification method | Contact the company via a phone number or website you already know is real, not the info in the message, per FTC guidance |
1. Write one red-flag prompt
Open any AI chat and save this line somewhere you’ll actually use it: “Check this message for phishing red flags: urgency or threats, mismatched sender or link domain, generic greeting, unusual payment or credential requests. Explain why, not just yes or no.” This becomes your standard first check on anything that feels off.
2. Paste before you click
Any time a message pushes you to act fast, click a link, confirm details, pay urgently, copy the full text into the chat with your prompt. Don’t retype it, paste it exactly as received so the AI sees what you saw, links included.
3. Read the reasoning, not just the verdict
A flat ‘yes it’s phishing’ teaches you nothing. Ask the AI to name the one or two strongest red flags in plain words, so you start recognizing the pattern yourself next time, without needing to check.
4. Pin it where it’s one tap away
Save the prompt in your notes app, a text expander, or a pinned chat, not buried in old messages. If finding the prompt takes longer than reading the suspicious email, you won’t use it when it matters.
5. Verify separately before acting
Never click the link in the suspicious message to check it, even out of curiosity. Go to your bank or company’s app or website directly, or call a number you already know is real.
A worked example
A colleague forwards you an email that looks like it’s from your bank, asking you to verify your account right now.
Before
Subject: Urgent: Verify Your Account Now
Dear Customer,
We have detected unusual activity on your account. Failure to verify within 24 hours will result in suspension. Click here to confirm your identity: http://secure-bank-verify.com/login
Thank you,
Customer Security Team
After
Likely phishing. Red flags: 1) Urgency and a 24 hour suspension threat, designed to make you act before you think. 2) ‘Dear Customer’ instead of your name, your real bank knows who you are. 3) The link domain ‘secure-bank-verify.com’ does not match your bank’s real domain, always check this before clicking. 4) ‘Customer Security Team’ has no name or employee ID attached. Do not click. Open your bank’s app or official site directly instead.
Three ways to bend it
For WhatsApp and SMS scams
Job offers, prize wins, and fake delivery fee messages common on WhatsApp follow the same pattern. Paste the text into the same prompt, it flags fake urgency and upfront payment requests just as well as it does with email.
For finance and vendor payments
Before approving any request to change a vendor’s bank details, run the email through the same check first. Business email compromise, where scammers impersonate a supplier, relies on the request looking routine, the AI will flag the sudden account change as the real red flag.
For job seekers screening offers
If a ‘recruiter’ message asks for money, ID scans, or bank details before an interview even happens, that’s a common job scam pattern. Run the message through the same check before you respond to anything.
When it goes wrong
AI flags almost everything as suspicious and I stop trusting it
Ask it for the single strongest red flag and a confidence level, not a full list every time. A vague or empty answer usually means the message is actually fine.
The scam still got past the check
AI reads the words in front of it, not technical email headers or where a link actually leads. Treat it as your first filter, not the final word, and still verify through an official app or number.
I never remember to use it in the moment
Attach the habit to a trigger, not memory: any message that mentions money, urgency, or a password gets pasted in, no exceptions, until it becomes automatic.
When not to use this
Don’t use this as your only defense, and never click a suspicious link or open an attachment just to test it, even carefully, if you’re unsure. It also won’t catch a well built attack with no obvious red flags in the text, since it can’t see sender headers or where a link actually leads. If your company has an official channel to report phishing, use that first for anything real, this technique is for your own first read before you decide whether to act, not a replacement for IT or security.
What you can now do
You get a fast, honest gut check on anything that feels off, before you click, instead of guessing and hoping.
Part of Making Life Easier With AI, a weekly walk-through of one small thing AI can take off your plate.
Take this further
Act as a blunt hiring manager who has read ten thousand resumes, not a career coach. I will paste my full resume and the job description I want. Rewrite the whole resume for that role, section by section, in this order: summary, experience, skills, education. Rules: every experience line leads with impact, not duty. Use bracketed placeholders like [8 percent] for any number I did not give you, and list at the end every placeholder I need to replace with a real figure. Keep it to one page of text. Plain formatting only, no tables or columns, so screening software can parse it. After the rewrite, tell me the three weakest claims that need evidence before I send this anywhere. My resume: [paste resume]. The role: [paste job description].
Takeaways
- Write and save one reusable red-flag prompt in your notes app or a pinned chat so it is one tap away when a message feels off
- Paste the full suspicious message into the AI exactly as received, including links, rather than retyping or summarizing it
- Ask the AI to name the one or two strongest red flags in plain words instead of accepting a plain yes or no verdict
- Before approving any vendor payment or bank detail change, run the request through the same phishing check first
- Never click the link in a suspicious message to test it, go to the official app, site, or a known phone number instead
Questions people actually ask
How do I know if an email is actually phishing?
Look for urgency or threats, a sender or link domain that does not match the real company, a generic greeting like ‘Dear Customer,’ and unusual requests for payment or credentials. You can also paste the full message into an AI chat and ask it to explain which red flags it sees and why, not just give a yes or no answer.
Is it safe to paste a suspicious email into ChatGPT or Claude?
Pasting the text is generally fine for spotting red flags, but never click the link first to test it, and avoid pasting sensitive account numbers or passwords into the chat. Treat the AI’s read as a first filter, then verify through your bank or company’s official app or website before taking any action.
Can AI actually catch phishing emails reliably?
AI can read the wording in front of it and flag patterns like urgency, mismatched domains, and generic greetings, but it cannot see real email headers or where a link technically leads. Well built attacks with no obvious red flags in the text can slip past it, so it should be your first check, not your only one.
What should I do instead of clicking a link in a suspicious message?
Go directly to your bank or company’s app or official website by typing the address yourself, or call a phone number you already know is real, rather than using anything in the message. This avoids fake login pages designed to steal your credentials, which is the same advice the FTC gives for phishing scams.
How do I remember to actually check messages before acting on them?
Attach the habit to a trigger instead of relying on memory: any message mentioning money, urgency, or a password gets pasted into your saved AI prompt first, no exceptions. Keeping the prompt pinned in your notes app or a text expander makes it fast enough to use in the moment.
Sources
- Recognize and Report PhishingCISA
- How To Recognize and Avoid Phishing ScamsFederal Trade Commission
- Business Email Compromise: The $55 Billion ScamFBI Internet Crime Complaint Center (IC3)
What happens next
Expect scammers to keep using AI themselves to write cleaner, more convincing messages with fewer obvious red flags, which narrows the gap this kind of check relies on. Business email compromise losses have kept climbing according to the FBI IC3, so scrutiny on vendor and payment change requests specifically is likely to increase. Watch for AI chat tools adding built in phishing or scam checks directly into email and messaging apps rather than requiring a separate copy-paste step.

