The phishing tell that just disappeared.
AI writes flawless French now.
For years, the reliable giveaway of a phishing email in Switzerland was the language: stilted French, odd Schweizerdeutsch, a translation that didn't quite land. In 2026 that early-warning sign quietly vanished — and your staff need to know it.
2026-09 · 8 MIN READ
Ask anyone in a Swiss office how they spot a phishing email and you'll often hear the same thing: "the French was bad," "it wasn't really Swiss German," "you could tell it was translated." For a Romandie SME or an International Geneva organisation, imperfect language was a genuine, if accidental, layer of defence. Generative AI has erased it. Phishing emails now arrive in flawless Romandie French and Schweizerdeutsch — complete with region-appropriate cultural references — indistinguishable from a message written by a native colleague.
Why this is more dangerous than it sounds
The language tell wasn't a minor convenience — for many organisations it was the primary filter their people actually used. Remove it and two things happen. First, click rates on convincing lures rise. Second, and more costly, business email compromise (BEC) becomes far harder to catch. BEC is the attack where someone is persuaded to make a payment, change bank details, or release data because an email appears to come from a trusted executive, supplier or partner. It carries no malicious link or attachment for a filter to catch — it relies entirely on plausibility, and perfect language makes it plausible.
The numbers are stark. Swiss organisations lost an estimated CHF 67 million to BEC in 2026, up 40% on the year before, with the average individual loss around CHF 238,000. Microsoft's own data captures why it's so dangerous: BEC represented only 2% of observed threats but 21% of attack outcomes — low volume, high hit rate.
The variant that defeats even a careful eye
The hardest version is vendor email compromise: attackers don't imitate your supplier from a lookalike domain — they compromise the supplier's real mailbox, watch the genuine invoice correspondence for weeks, then send a payment-redirection request from the authentic account, with real signatures, passing every authentication check. There is no spelling mistake to catch, no wrong domain to notice. The email is genuine; only the instruction is fraudulent.
When the language is perfect, the domain is real, and the signature checks out, the only defence left is process: verifying a high-stakes request through a second, trusted channel before acting on it.
What actually defends you now
If "it read oddly" no longer protects you, these do:
- Out-of-band verification for anything that moves money or data. A payment, a bank-detail change, a sensitive data request — verified by a phone call to a known number, never a number in the email. This single process rule defeats most BEC, regardless of how perfect the message is.
- Phishing-resistant MFA to stop the account takeovers that make the worst BEC possible — when the attacker controls the real mailbox, there is no impersonation to spot.
- Behavioural email defence and a SOC that flags the anomalies people can't see: a new inbox rule quietly forwarding invoices, a login from unusual infrastructure, a first-time payment instruction from a long-quiet contact.
- Training that reflects 2026, not 2019. Staff drilled to look for bad grammar are trained for a threat that no longer exists. The lesson now: verify the request, not the wording.
The takeaway for Geneva
For a region full of NGOs, missions, fiduciaries and SMEs that move money and sensitive data daily, the disappearance of the language tell is not a minor shift — it removes the defence most staff were unconsciously relying on. The organisations that stay safe in 2026 are the ones that replaced "does this read wrong?" with "have we verified this through a second channel?" — and that have someone watching the mailbox behaviours no human eye can catch.
Talk to our engineersIs your team still trained for 2019's phishing?
Our free audit reviews your email defences, MFA and payment-verification process — and shows where AI-perfect phishing could still get through.