By Gareth Jelley, Cyber Security Lead at edtech charity LGfL – The National Grid for Learning
Cybersecurity threats facing schools are becoming more sophisticated, with AI-powered phishing and scams emerging as one of the most significant challenges. Unlike traditional phishing attempts, which were often easy to identify because of spelling mistakes or suspicious wording, today’s attacks are far more convincing, targeted and difficult to spot.
Artificial intelligence enables cybercriminals to create realistic emails and messages, impersonate trusted colleagues or organisations, and use publicly available information to make scams appear genuine. This growing level of sophistication means that even experienced members of staff can be deceived. AI also allows attackers to act more quickly after gaining access to an account, making prompt reporting and a rapid response essential to limiting potential damage.
How AI is transforming phishing attacks
AI is being used by cybercriminals in several key ways:
Realistic phishing emails
AI enables cybercriminals to create highly convincing phishing emails that are professionally written and free from the spelling or grammar mistakes often associated with traditional scams. These messages can closely mimic the tone, writing style and branding of senior leaders, colleagues or trusted organisations, making them appear authentic and more difficult to recognise as fraudulent. Increasingly, attackers are also using compromised email accounts belonging to colleagues, suppliers or even other schools. Known as ‘business email compromise’, these attacks exploit trust by sending malicious emails from genuine accounts.
Voice cloning and identity impersonation
Using short audio samples found online or recorded from previous calls, attackers can create deepfake voice messages. These may sound like a headteacher, senior leader or trusted colleague requesting urgent action. AI can also be used to create convincing video calls, making voice and appearance alone unreliable ways of verifying someone’s identity.
Personalised scams using public data
AI can quickly scan websites, social media and online records to build detailed profiles of staff. This allows attackers to reference real names, roles, school events or internal structures to make scams appear legitimate.
Attacks beyond email
Email is not the only route for attacks. Criminals are increasingly using platforms such as Microsoft Teams, Google Chat, messaging (smishing), voice services (vishing) and QR codes (quishing) to deliver malicious links or persuade staff to take action.
Building on phishing awareness training
Many schools have previously relied on training that teaches staff to identify phishing emails through:
- Spelling mistakes
- Suspicious email addresses
- Poor formatting or unusual language
However, AI-generated scams often avoid these warning signs entirely. They look polished, professional and believable. In many cases, genuine emails written by busy colleagues may contain more mistakes than AI-generated phishing messages.
This means that visual clues alone are no longer a reliable guide and it is safer to adopt a verification-based approach, checking unusual requests independently before acting.
Practical steps to protect yourself from AI-driven scams
1. Verify unexpected requests
If you receive an unexpected request involving money, sensitive information or changes to payment details, it is best to treat the email or message alone as insufficient. Confirm the request through a trusted method, such as speaking to the person directly, calling a known phone number or using an established internal communication channel, before acting.
Then:
- Confirm the request using a different communication method, such as a known phone number or face-to-face conversation.
- Speak to the person directly where possible.
- Use official school communication channels.
- Be cautious of contact details provided within the email or message itself.
If a supplier asks you to change bank details, it is advisable to verify the request using an existing telephone number already held by the school rather than one included in the email.
2. Be cautious of urgency and authority
AI phishing often relies on pressure tactics such as:
- Urgency and deadlines
- Fear and threats
- Impersonating authority
These messages often arrive at already pressured times, just before holidays or at the end of the school day when staff are busy and more likely to act quickly.
Pause and ask yourself:
- Does this really need doing now?
- Am I being pressured into acting?
- Can I verify this before responding?
3. Treat voice requests with caution
Voice cloning and AI-generated video calls make impersonation more convincing than ever.
If you receive a call requesting urgent action:
- Keep in mind that the voice may not be genuine.
- End the call politely.
- Call back using a trusted number from school records.
For high-risk actions, such as authorising payments, schools may also wish to introduce a pre-agreed verification passphrase known only to authorised staff. This provides an additional safeguard against sophisticated impersonation attempts.
4. Consider what you share online
Cybercriminals often gather information from publicly available sources, including:
- School websites
- Social media profiles
- Public events and announcements
One area worth reviewing is how much information schools publish about staff, particularly names, photographs, job titles and organisational structures. While celebrating achievements is important, limiting unnecessary personal information makes it harder for attackers to build convincing scams.
5. Report anything suspicious immediately
If something feels unusual:
- Report it to your school’s IT support or network manager immediately.
- Follow your school’s agreed cyber incident reporting process.
- Mistakes happen and if you accidentally click a link, enter login details or download a suspicious attachment, quick reporting can make all the difference.
Rapid reporting allows IT teams to reset passwords, revoke compromised devices, investigate unusual logins and prevent attackers from gaining further access. This works best when there is a clearly publicised reporting route so staff know exactly who to contact.
6. Use strong security habits every day
Good habits that make a real difference:
- Using strong, unique passwords.
- Enable multi-factor authentication (MFA) wherever available.
- Log out of systems when not in use.
- Questioning unexpected requests, even when they appear to come from someone you know.
With Cybersecurity, as with safeguarding or health and safety, everyone has a role to play in protecting the school community.
Looking ahead:
AI-powered phishing is changing the cyber threat landscape for schools. These attacks are more convincing, highly personalised and increasingly exploit trusted communication channels, making them much harder to identify than traditional phishing attempts. As a result, combining awareness with a habit of verifying unusual requests offers the strongest protection.
This is best achieved through a culture of verification, where unusual requests are routinely checked through another communication channel, suspicious activity is reported immediately and staff feel confident questioning even apparently genuine messages.
In today’s threat landscape, technology only offers part of the solution. The greatest protection comes from well-informed colleagues who stay alert, take time to verify before acting, and who see cybersecurity as something everyone contributes to.
For more information please visit – https://lgfl.net/security.
Image credit: https://unsplash.com/photos/scam-spelled-with-scrabbles-on-a-wooden-table-FjyseC7iV3k




