The Educator Magazine U.K. Sept-Dec 2026 issue - Magazine - Page 14
The new face
of phishing:
Ai and the risks
for schools
by Gareth Jelley, Cyber Security Lead at edtech charity
LGfL – The National Grid for Learning
Cyber threats facing schools are becoming
more sophisticated, with artificial
intelligence transforming the way
cybercriminals target staff and pupils.
Today's phishing attacks bear little
resemblance to the poorly written scam
emails of the past. AI enables criminals to
create convincing, personalised
messages that closely mimic the tone,
style and identity of trusted colleagues,
suppliers or organisations, making them
far harder to recognise.
By drawing on publicly available
information, attackers can tailor scams to
individual schools, while AI also enables
compromised accounts to be exploited
more quickly than ever before. As a result,
even experienced members of staff can
be deceived. In this changing threat
landscape, recognising suspicious emails
is no longer enough. A culture of
verification offers stronger protection,
where unexpected requests are routinely
checked and staff feel confident raising
anything that doesn’t look right.
The rise of AI-powered phishing
AI is being used by cybercriminals in
several key ways:
Increasingly sophisticated phishing emails
AI tools can generate professional,
realistic emails that contain no obvious
spelling or grammar errors. These
messages often imitate the tone and
style of senior staff or external
organisations, making them difficult
to question. Increasingly, attackers are
also using compromised email accounts
belonging to colleagues, suppliers or even
other schools. Known as ‘business email
compromise’, these attacks exploit trust
by sending malicious emails from genuine
accounts.
AI-generated voices and
impersonation
Using short audio samples found online
or recorded from previous calls,
attackers can create deepfake voice
messages. These may sound like a
headteacher, senior leader or trusted
colleague requesting urgent action. AI
can also be used to create convincing
video calls, making voice and appearance
alone unreliable ways of verifying
omeone's identity.
Personalised scams using public
data
AI can quickly scan websites, social media
and online records to build detailed
profiles of staff. This allows attackers to
reference real names, roles, school events
or internal structures to make scams
appear legitimate.
Attacks beyond email
Email is not the only route for attacks.
Criminals are increasingly using platforms
such as Microsoft Teams, Google Chat,
messaging (smishing), voice services
(vishing) and QR codes (quishing) to
deliver malicious links or persuade staff
to take action.
Why awareness training alone is
no longer a reliable defence
Many schools have previously relied on
training that teaches staff to identify
phishing emails through:
• Spelling mistakes
• Suspicious email addresses
• Poor formatting or unusual language
However, AI-generated scams often avoid
these warning signs entirely. They look
polished, professional and believable.
In many cases, genuine emails written
by busy colleagues may contain more
mistakes than AI-generated phishing
messages.
This means that visual clues alone are
no longer a reliable guide and it is safer
to adopt a verification-based approach,
checking unusual requests independently
before acting.
Advice for teachers: Staying safe
from AI-driven scams
1. Always verify unusual requests
If you receive an unexpected request
involving money, sensitive information
or changes to payment details, the safest
first step is to pause.
Then:
• Confirm the request using a different
communication method, such as a known
phone number or face-to-face
conversation.
• Speak to the person directly where
possible.
• Use official school communication
channels.
• Be cautious of contact details provided
within the email or message itself.
If a supplier asks you to change bank
details, it is advisable to verify the request
using an existing telephone number
already held by the school rather than one
included in the email.