Spotting phishing: five typical tricks
AI-generated emails are flawless and personal — the old tell-tale signs no longer apply. These five patterns every team should know.
“Watch out for spelling mistakes” — that advice is obsolete. Modern phishing emails are flawless, personally addressed and imitate real senders convincingly. Instead of hunting for typos, it pays to know the tricks behind them.
1. Artificial time pressure
“Your account will be locked in 24 hours.” Pressure switches off critical thinking. Reputable senders rarely set such tight, threatening deadlines.
2. The boss who discreetly asks for something
CEO fraud plays on hierarchy and secrecy. A supposed request from management for a “confidential, short-term” transfer should always be verified via a second channel.
The most effective defence isn't a filter but a team that reports suspicious emails instead of clicking them.
3. The almost-right address
The real domain is often not at the end of the sender address. “microsoft.com.security-alert.io” is not Microsoft. A glance at the actual domain part exposes many fakes.
4. The attachment that pushes
Unexpected invoices, parcel notifications or “voice messages” as attachments are among the typical entry points. When in doubt: don't open — report.
5. The QR code
Quishing shifts the attack to the smartphone, where the URL is harder to check. A QR code in an email deserves the same scepticism as a link.
The goal of awareness isn't to stop everyone from ever clicking — that's unrealistic. The goal is a culture where reporting is natural and a wrong click becomes a learning unit, not a penalty.
Related from our offering
Keep reading
Emergency or crisis? Why the distinction decides your response
Server-room fire at 3 a.m.: emergency or crisis? Separating the two terms cleanly means alerting the right people, escalating in time — and preventing a manageable incident from becoming an existential threat.
5 common mistakes in emergency planning — and how to avoid them
Perfect on paper, useless when it counts: why emergency plans fail on vague instructions, missing upkeep, IT tunnel vision, untrained roles and slow alerting — with practical examples and concrete remedies.