I was almost scammed by AI, and it was terrifyingly convincing.

A few weeks ago, I received an email from someone claiming to work for ShareGate. If you’re not familiar with them, ShareGate is a well-known software company that builds tools for migrating, managing, and securing Microsoft 365 environments, SharePoint, Teams, OneDrive, and more. Their software is widely used by IT admins for tenant-to-tenant migrations and governance.

The email opened with a detailed summary of one of my blog posts, which covers migrating Exchange MRM policies to Purview DLM. It accurately captured the practical approach I’d laid out and even noted that the article highlighted pitfalls in the migration process that are often overlooked. On that point, the message was spot on.

Then came the ask: would I be interested in a paid placement where “we” (ShareGate) could demonstrate how ShareGate Migrate handles the policy assessment and transition piece of the workflow? Again, the details were precise and technically accurate.

Why I didn’t suspect anything at first

My first thought was whether this counted as sponsorship. Since I’m relatively new to this space, it hadn’t really occurred to me that I might be offered payment to cover expenses. At that point, nothing felt off, for a few reasons:

  • ShareGate is a well-established vendor that regularly collaborates with the community.
  • ShareGate Migrate is a real, actively used product.
  • The email read as entirely legitimate.
  • There was no urgency or pressure. The message even closed with, “Happy to discuss if you’re open to it.”

The cracks start to show

Before considering the offer, I wanted more information, so I asked for a call. The reply gave me pause:

“I should mention that I’m not able to jump on calls directly, but if needed, I’d be happy to coordinate with someone from my team who can connect with you. I’d be more than happy to continue the conversation here over email.”

That’s when my instincts kicked in, and a few things started to stand out:

  • The sender, “Alex Richards,” didn’t appear to exist anywhere online.
  • The domain was sharegate-partnerships[.]com. A quick DNS lookup showed it redirected to instantly[.]ai.

Instantly[.]ai is a platform built for legitimate cold sales outreach, but its features make it just as attractive for phishing and scam operations:

  • Deliverability tricks: warmup sequences and IP rotation that help emails land in inboxes instead of spam folders, useful for scammers and salespeople alike.
  • AI-generated messaging: makes it cheap and easy to produce large volumes of varied, personalized-sounding messages, ideal for convincing phishing attempts.
  • Custom SMTP and unlimited accounts: makes it trivial to spin up many different sending identities.

Confirming the scam

I reached out to a contact in the community who actually collaborates with the real ShareGate. Once they verified the domain, it was immediately clear: this was a scam.

What were they after? I can only speculate, but my best guess is they wanted to plant malicious code on my blog, or possibly extract sensitive personal information from me.

What this taught me

Scam and phishing emails sent through AI platforms like Instantly[.]ai usually still carry some familiar red flags:

  • A sense of urgency (mine had none)
  • Unusual requests (mine seemed perfectly legitimate)
  • A mismatched sender domain (which I should have caught sooner)

What was missing, though, was the one thing that usually gives these scams away: sloppy or unnatural writing. In my case, the text was entirely credible. It used information I had published myself, and combined it with a real product to make the pitch believable. This wasn’t a poorly spelled plea from a distant “prince”, it was precisely engineered around my own content and aligned with a product that could plausibly offer real value. And it was almost certainly fully automated. I couldn’t tell it apart from a legitimate message.

I don’t consider myself naive about the tactics scammers typically use. And yet, nothing about this raised a flag at first. Both the message and the follow-up request felt completely legitimate.

The bigger lesson

Malicious actors are now using generative AI to deceive us, and it doesn’t take advanced technical skill to pull off. All it takes is a well-crafted prompt fed into a system that uses AI to identify exploitable opportunities.

This means we can no longer rely on poor grammar or strange requests to spot a scam. Producing coherent, compelling, and personalized text is trivial for AI. So we need to shift our attention to other signals: fraudulent domains, unnecessary urgency, and senders or companies that don’t actually exist.

If you’re responsible for security awareness in your organization, don’t rely on technology alone. Pair your technical anti-spam defenses with real user awareness training. And when someone in your organization falls for a scam (real or simulated), resist the urge to shame them. In my view, those “gotcha” moments are outdated. It’s far more valuable to treat these incidents as learning opportunities for the whole organization.

The actual messages, for reference:

Leave a comment