The threat of AI-powered phishing and scams in schools
Feature
Man at a laptop

Cybersecurity threats in schools are evolving quickly, and one of the most significant developments is the rise of AI-powered phishing and scams. Gareth Jelley from edtech charity LGfL – The National Grid for Learning, explains what teachers need to know

Unlike traditional phishing attempts, which often contained spelling mistakes or obvious red flags, modern attacks are increasingly sophisticated, personalised and difficult to detect.

Cybercriminals are now using artificial intelligence to generate highly convincing messages, impersonate trusted individuals and exploit publicly available information. As a result, schools are facing a new kind of digital risk where even experienced staff can be misled. AI is also reducing the time it takes for attackers to exploit compromised accounts, making rapid reporting and response more important than ever.

How AI is changing phishing attacks

AI is being used by cybercriminals in several key ways. Firstly, by generating highly convincing phishing emails. AI tools can generate professional, realistic emails that contain no obvious spelling or grammar errors. These messages often imitate the tone and style of senior staff or external organisations, making them difficult to question. Increasingly, attackers are also using compromised email accounts belonging to colleagues, suppliers or even other schools. Known as ‘business email compromise’, these attacks exploit trust by sending malicious emails from genuine accounts.

Cybercriminlas can also utilise voice cloning and impersonation. Using short audio samples found online or recorded from previous calls, attackers can create deepfake voice messages. These may sound like a headteacher, senior leader or trusted colleague requesting urgent action. AI can also be used to create convincing video calls, making voice and appearance alone unreliable ways of verifying someone’s identity.

Cybercriminals can also create personalised scams using public data. AI can quickly scan websites, social media and online records to build detailed profiles of staff. This allows attackers to reference real names, roles, school events or internal structures to make scams appear legitimate.

Email is not the only route for attacks. Criminals are increasingly using platforms such as Microsoft Teams, Google Chat, messaging (smishing), voice services (vishing) and QR codes (quishing) to deliver malicious links or persuade staff to take action.

Why awareness training alone is no longer a reliable defence

Many schools have previously relied on training that teaches staff to identify phishing emails through spelling mistakes, suspicious email addresses, and poor formatting or unusual language.

However, AI-generated scams often avoid these warning signs entirely. They look polished, professional and believable. In many cases, genuine emails written by busy colleagues may contain more mistakes than AI-generated phishing messages.

This means that visual clues alone are no longer a reliable guide and it is safer to adopt a verification-based approach, checking unusual requests independently before acting.

So what is the advice for teachers to stay safe from AI-driven scams?

Always verify unusual requests

If you receive an unexpected request involving money, sensitive information or changes to payment details, the safest first step is to pause. Then confirm the request using a different communication method, such as a known phone number or face-to-face conversation.

Speak to the person directly where possible or use official school communication channels. Be cautious of contact details provided within the email or message itself.

If a supplier asks you to change bank details, it is advisable to verify the request using an existing telephone number already held by the school rather than one included in the email.

Be cautious of urgency and authority

AI phishing often relies on pressure tactics such as urgency and deadlines, fear and threats, and impersonating authority. These messages often arrive at already pressured times, just before holidays or at the end of the school day when staff are busy and more likely to act quickly.

Pause and ask yourself: does this really need doing now? Am I being pressured into acting? Can I verify this before responding?

Treat voice requests with caution

Voice cloning and AI-generated video calls make impersonation more convincing than ever. If you receive a call requesting urgent action, keep in mind that the voice may not be genuine, end the call politely, and call back using a trusted number from school records.

For high-risk actions, such as authorising payments, schools may also wish to introduce a pre-agreed verification passphrase known only to authorised staff. This provides an additional safeguard against sophisticated impersonation attempts.

Be aware of your digital footprint

Attackers often gather information from school websites, social media profiles, and public events and announcements.

One area worth reviewing is how much information schools publish about staff, particularly names, photographs, job titles and organisational structures. While celebrating achievements is important, limiting unnecessary personal information makes it harder for attackers to build convincing scams.

Report anything suspicious immediately

If something feels unusual, report it to your school’s IT support or network manager immediately and follow your school’s agreed cyber incident reporting process. Mistakes happen and if you accidentally click a link, enter login details or download a suspicious attachment, quick reporting can make all the difference. 
Rapid reporting allows IT teams to reset passwords, revoke compromised devices, investigate unusual logins and prevent attackers from gaining further access.  This works best when there is a clearly publicised reporting route so staff know exactly who to contact.

Use strong security habits every day

Good habits that make a real difference, such as using strong, unique passwords and enabling multi-factor authentication (MFA) wherever available. Good habits also include logging out of systems when not in use and questioning unexpected requests, even when they appear to come from someone you know. 

With cybersecurity, as with safeguarding or health and safety, everyone has a role to play in protecting the school community.

Conclusion

AI-powered phishing represents a major shift in the cyber threats facing schools. Because these scams are more realistic, more personalised and increasingly use trusted communication channels, the traditional “spot the scam” approach no longer offers the protection it once did.

Instead, the strongest defence is a culture of verification, where unusual requests are routinely checked through another communication channel, suspicious activity is reported immediately and staff feel confident questioning even apparently genuine messages.

In today’s threat landscape, technology is only part of the picture. The greatest protection comes from well-informed colleagues who stay alert, take time to verify before acting, and see cybersecurity as something everyone contributes to. 

For more information and resources, visit lgfl.net