[Webinar] Defending against AI-powered social engineering with SF 49ers & NY Giants
Research

Bad Grammar is Dead. Tone Matching is the New Payload

Generative AI has eliminated typos in phishing. Discover how attackers weaponize LLMs for perfect tone matching, and how Doppel stops them at machine speed.

Bad Grammar is Dead. Tone Matching is the New Payload

“Look for the typos.” In 2026, that doesn’t cut it.

Bad grammar, awkward phrasing, and unusual capitalization were the red flags that every security awareness training (SAT) (opens in new tab) program called out for decades. But AI eliminated the language barrier for attackers, so today’s cybercriminals write better than most of your actual employees.

Check any social engineering (opens in new tab) definition: There’s a description of the psychological manipulation of people into performing actions or divulging confidential information. Now, that psychological manipulation is being outsourced entirely to AI.

Threat actors are using LLMs to perfectly mimic the specific cadence, vocabulary, and communication style of your executives. They want to sound exactly like your CFO at 4:00 PM on a Friday.

Tone is the new payload, and it is bypassing secure email gateways (SEG) (opens in new tab) and human skepticism at an alarming rate.

The typo took a vacation

Attackers realize they have a goldmine every time a new conversational AI model hits the mainstream.

No need to hire a native speaker to run business email compromise (BEC) (opens in new tab) campaigns. Just hand the drafting process over to AI.

The resulting efficiency gains are overwhelming. Attackers are pumping out AI-generated lures at a volume and quality that human scammers could never achieve.

Here’s how AI has supercharged the modern phishing lifecycle:

Grammar isn’t a reliable filter anymore. If your defense strategy relies on an employee pausing because a sentence feels slightly ‘off,’ you’re operating on a dangerously outdated playbook.

Tone matching: Hijacking the corporate persona

A perfectly written email from a total stranger might get ignored by a busy employee. But a perfectly written email from your CEO, referencing an ongoing internal project and using their exact signature sign-off, gets answered immediately.

This is where tone matching enters the equation. LLMs are adept at stylistic mimicry, so if you feed an AI a few paragraphs of someone’s writing, it can easily reverse-engineer their personality.

Cybercriminals actively scrape the open web to build a comprehensive data dossier on your executives before they ever send a lure. LLMs are specifically tasked with scraping company PR releases, public podcasts, and executive social profiles, and the goal is to perfectly mimic specific internal jargon and the broader organizational tone, effectively bypassing basic employee intuition.

They pull specific context from a variety of sources:

  • Attackers use LinkedIn profiles and posts to capture industry jargon, map reporting structures, and mirror professional cadence.
  • Public press releases and earningscalls help threat actors understand exactly how leadership speaks about corporate strategy, recent acquisitions, and financial goals.
  • When a third-party vendor is breached, cybercriminals dig through historical email threads to study how your internal team communicates with outsiders.

The attacker then feeds this rich dossier into an LLM with a simple, natural-language prompt to instruct AI to write an urgent message to the VP of Finance, asking for vendor payment approval, using the exact tone from the provided samples and referencing a real, upcoming software deployment.

A psychological trap is the result. It feels authentic, easily bypassing the employee's natural skepticism because it reads exactly like the dozens of other emails they receive from that specific executive every week.

Threat construction matrix: How tone matching works

Look at the specific variables an attacker asks the AI to replicate. Here is a breakdown of how publicly available data is weaponized into a tailored psychological payload:

How an attacker assembles a persona

Beyond text: A multi-channel illusion

Tone matching isn't confined to the written word. The exact same AI principles are being applied to voice communications and mobile channels, and the results are causing massive financial damage.

If a financial controller is skeptical of an email, their legacy security training tells them to pick up the phone and verify the request. But what happens when the voice on the other end of the line also belongs to the attacker?

Deepfake audio (opens in new tab) has reached a concerning level of fidelity. Cybercriminals only need a few seconds of clean audio (pulled from a keynote speech, a YouTube interview, or a corporate webinar) to create a near-perfect voice clone. They then use these clones to execute real-time voice phishing, or vishing (opens in new tab), campaigns.

The growth of this specific tactic is exploding. According to CrowdStrike’s 2025 Global Threat Report (opens in new tab), vishing attacks skyrocketed by 442% between the first and second halves of 2024.

Attackers are also aggressively shifting toward SMS (smishing) (opens in new tab) to bypass email gateways. Smishing now accounts for a massive 35% of all mobile phishing (opens in new tab) attempts, and it yields a 40% higher median click rate than traditional email lures.

When an attacker can perfectly replicate both the written style and the vocal pitch of a trusted leader across any device, the human perimeter collapses. This is why deepfake brand protection (opens in new tab) has shifted from a luxury to a critical operational requirement.

How to catch a perfect clone

The human brain is hardwired to trust familiar patterns, and generative AI is specifically designed to exploit that hardware. If an email sounds exactly like your boss, uses their favorite phrases, and references a real project, your brain assumes it’s your boss.

Stop relying on the human eye and start dismantling the attacker’s operational infrastructure before the message is ever sent — with Doppel (opens in new tab).

Here’s how Doppel’s agentic AI-native platform (opens in new tab) neutralizes tone-matched social engineering:

  1. Continuous ecosystem monitoring: Doppel's AI agents constantly scan domain registrars, DNS records, social platforms, and the dark web. We look for the staging environments attackers use to launch these campaigns, such as newly registered lookalike domains or spoofed executive profiles.
  2. Machine-speed takedowns: When we identify a threat actor staging a campaign against your brand or your VIPs, we don't wait for the perfectly written email to arrive. We execute automated API takedowns, interfacing directly with hosting providers to destroy the infrastructure before the attack is armed.
  3. Dynamic internal simulation: We take the live threat intelligence gathered by our agents and convert it into internal training simulations. If attackers are currently using LLMs to clone your CEO's tone regarding a specific vendor, we launch safe, proactive simulations using that exact same lure. This builds actual muscle memory, training your staff to rely on strict out-of-band verification protocols rather than trusting their gut.

Retire the red pen. Pick up social engineering defense

Laughing at poorly translated, grammatically absurd phishing emails? Gone.

Every security team is in a highly sophisticated landscape where malicious actors have the exact same access to world-class language models as the company’s engineers.

Grammar is perfect, and tone is easily cloned. The payload is now the complete psychological manipulation of your workforce.

To survive this shift, accept that the human perimeter cannot be secured with a basic spelling test.

Get started with Doppel (opens in new tab) to deploy an agentic defense that continuously monitors your external attack surface and executes automated takedowns, so you can neutralize the threat before AI even finishes writing the prompt.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.