For years, standard security awareness training has boiled down to a short, simple checklist: watch for bad grammar, look for a sender address that doesn’t match the company name, and hover over links before you click. It was simple, memorable, and for a long time, it worked.
Not anymore.
The advancement of AI has democratized everything, lowering the barrier to entry for complex tasks while sharpening the abilities of existing experts, and that unfortunately includes internet scammers. What has changed isn’t just that AI writes cleaner emails; it’s that AI makes it incredibly fast and cheap to find information about a target, and then tailor a scam to something the victim is primed to expect. A delivery notification arrives the same afternoon you’re actually expecting a package. You receive a call about a fraudulent charge after you used your credit card somewhere unfamiliar. A recruiter reaches out about a job opening that perfectly aligns with a recent LinkedIn update. None of these are inherently suspicious on their own, but very well could be; hence one of the reasons for security awareness training. What’s changed is the speed: AI can now identify who is a plausible target for a given pretext (i.e., “hook”) and generate a convincing, tailored approach fast enough to reach someone while the real event is still fresh, sometimes within hours, not weeks.
This is exactly what happened to me. I recently updated my LinkedIn profile to reflect my independent cybersecurity advisory work and soft-launch of RedZoan Consulting. This past weekend, I received an email from “partners@valentissearch[.]com,” describing itself as an executive-search practice representing a vetted network of former senior U.S. government leaders. Given my background, it was a highly plausible pitch that deserved a real look rather than an instant delete. Despite being in cybersecurity for 17+ years across the NSA, Mandiant, and Google, the standard “is this legitimate or not” security checklist most of us are used to following gave this email a clean pass.
What Landed in My Inbox

Looking at this screenshot now, you can probably spot a few things that feel off. But remember: this blog post is about phishing, which means your brain is already primed to look for deception. In the middle of a busy workday, without that psychological primer, those subtle clues are much harder to catch. Scammers, much like marketers, understand this human behavior implicitly, and they are using AI to exploit it at scale.
I ran it through the standard security checklist:
-
Sender address spoofed? No, the domain matched and the sender displayed correctly.

-
Malicious hyperlinks? No links at all, just a sending email address in the signature block.
-
Grammar or formatting red flags? None. The writing was very professional, though the use of an em dash (—) slightly hinted at an AI drafting assistant.
The email passed the usual security checks. However, it did raise a few softer red flags:
-
The Subject Line: “Confidential advisory opportunity”. In my experience, unsolicited emails leading with a need for “privacy” are a common scam tactic.
-
The Salutation: “Dear Candidate” instead of my name. While generic openings aren’t unusual for recruiting, it sat oddly next to how specific the rest of the email claimed to be about my unique background.
-
The Signature: Just “ValentisSearch,” with no named individual to lookup.
Prompted by those soft signals, I dug deeper and found a cluster of additional inconsistencies, enough that I can’t rule out this being a scam, or at minimum, a company that isn’t what it presents itself to be:
-
The domain, valentissearch[.]com, was registered on July 16, 2026[1]. This was a little over 6 weeks from when I received the email. A firm claiming a vetted, senior-level network has a web footprint younger than a houseplant.
-
There is no independent trace of the company anywhere. No press, no reviews, and no LinkedIn presence. The website features a quote from a “Founding Partner” who leaves no independent digital footprint either.
-
The site was built using a commercial AI website generator[2]. That’s not inherently suspicious, plenty of legitimate businesses use these tools. But the use of AI combined with the generic wording and thin content found elsewhere on the site implies it took almost no time or resources to create, which raises real questions about the site’s legitimacy and purpose.
The Soft Signals Are the Hard Part
Nothing about this website or email would have tripped a spam filter or a security scanner[3]. That’s the real story here: the line between what’s legitimate and fabricated is becoming difficult to parse using the tools and procedures most organizations rely on.
Moreover, targeted attacks like spearphishing are effective because it is easy to rationalize away the soft signals. Four weeks into building my own consulting practice, an unsolicited advisory opportunity aligning with my background was the kind of message anyone in that position would want to be true. That’s not a gap in judgment. It’s the exact human response modern-day scams are built to exploit: a message engineered to line up with whatever is already on the target’s mind. Between LinkedIn activity, public job history, and everyday digital footprints, attackers rarely have to guess what that is anymore.
The Broken Defense
AI has made this style of highly targeted outreach cheap enough to attempt at scale, rendering old advice unreliable — and it’s no longer confined to a well-crafted email. A peer-reviewed Harvard study found AI-generated spear-phishing more than quadrupled the click-through rate of traditional, human-written phishing, and the threat is leaving the inbox entirely:
Here is the uncomfortable conclusion: If a seasoned cybersecurity professional is doing a double take over an email’s legitimacy, it is not a reasonable expectation for non-security personnel like an HR coordinator, finance analyst, or executive assistant. It’s an even less reasonable expectation for the senior executives and other high-authority stakeholders who are frequently the most targeted, precisely because of what they’re positioned to authorize: a wire transfer, a vendor change, a system access grant. No matter how good your training program is on paper, seniority is not a substitute for structural verification.
Testing It Before It Tests You
Security awareness training remains a staple of every business, but training alone was never a complete answer. It teaches people what to look for, but it does not tell you what happens organizationally when an attack inevitably slips through.
Are there other controls in place? What is your real confidence that they will work as designed? What is the plan beyond hoping it never happens to you?
These are questions a Tabletop Exercise (TTX) is built to answer. At its core, a TTX is a guided, discussion-based simulation where your team walks through a realistic cyber incident step-by-step. It gets your IT, finance, HR, legal, public relations, executive leadership, etc. in the same room to find out where your incident response plan holds up and where it breaks down, while the stakes are still zero.
Instead of testing your employees’ ability to spot a typo, a modern TTX tests your organization’s resilience against the attacks that bypass initial detection. Consider how your team would handle scenarios like these:
- The AI Voice Clone (Vishing): A finance manager receives a frantic, highly convincing phone call, seemingly from the CEO but generated via an AI deepfake, authorizing an immediate, out-of-band wire transfer to a “new vendor.” What is your mandatory out-of-band verification process, and who enforces it?
- The Contextual Spear-Phish: An HR coordinator receives an email containing a malicious payload. The email perfectly references a recent internal company offsite and mimics the exact tone of your benefits provider. It bypasses the spam filter and the employee clicks it. How long does it take for your endpoint detection to alert the security team, and what is the protocol for isolating that machine?
- The Hijacked Vendor Thread: A legitimate, trusted partner’s email account is compromised, and an attacker uses an existing email thread to send an updated, fraudulent invoice. The sender is real and the domain is real, but the bank routing details are fake. Does your accounts payable team have a technical or manual safety net to catch this?
In the context of the MITRE ATT&CK framework, a cyberattack isn’t a single event. It is a lifecycle. The scenarios above only represent “Initial Access.” Once an attacker establishes that foothold, a timer starts. The longer it takes your organization to detect, respond, and contain the threat, the further the attacker progresses toward lateral movement, privilege escalation, and ultimately, data exfiltration or financial theft. A tabletop exercise doesn’t just test whether your defenses work; it tests how rapidly you can compress that timeline before a manageable incident turns into a catastrophic breach.
A checklist gave this email a clean pass. My gut didn’t. Training teaches your people what to look for, but it doesn’t tell you what happens when something is missed. That’s the gap a tabletop exercise closes.
If your answer to any of the scenarios above is “hope it doesn’t happen,” or you’re not confident your plan would hold up, let’s talk.
Visit www.redzoan.com or reach out directly at james@redzoan.com to start the conversation.
Sources
https://www.hostinger.com/blog/hostinger-horizons-launch/ ↩︎
Of the 92 scanners available on VirusTotal, 1 does flag the website for “phishing”. https://www.virustotal.com/gui/url/db56b511ed0b68e48af9e818ee089694749e8580da6ad9ad53dcb0b7de5de282/detection ↩︎