Back to the blog
Awareness

Spotting phishing: five typical tricks

AI-generated emails are flawless and personal — the old tell-tale signs no longer apply. These five patterns every team should know.

“Watch out for spelling mistakes” — that advice is obsolete. Modern phishing emails are flawless, personally addressed and imitate real senders convincingly. Instead of hunting for typos, it pays to know the tricks behind them.

1. Artificial time pressure

“Your account will be locked in 24 hours.” Pressure switches off critical thinking. Reputable senders rarely set such tight, threatening deadlines.

2. The boss who discreetly asks for something

CEO fraud plays on hierarchy and secrecy. A supposed request from management for a “confidential, short-term” transfer should always be verified via a second channel.

The most effective defence isn't a filter but a team that reports suspicious emails instead of clicking them.

3. The almost-right address

The real domain is often not at the end of the sender address. “microsoft.com.security-alert.io” is not Microsoft. A glance at the actual domain part exposes many fakes.

4. The attachment that pushes

Unexpected invoices, parcel notifications or “voice messages” as attachments are among the typical entry points. When in doubt: don't open — report.

5. The QR code

Quishing shifts the attack to the smartphone, where the URL is harder to check. A QR code in an email deserves the same scepticism as a link.

The goal of awareness isn't to stop everyone from ever clicking — that's unrealistic. The goal is a culture where reporting is natural and a wrong click becomes a learning unit, not a penalty.

NICA

Related from our offering

Discover awareness training

Turn knowledge into readiness.

Talk to us about NIS2, continuity provisioning or an awareness programme — consulting and software from one source.

Hosted in Germany • In line with the GDPR • a personal contact