The most dangerous phishing emails rarely look like obvious scams.
They may carry the logo of a bank, a delivery company, a payroll provider, a government agency, a familiar retailer or even a colleague. They may appear in a polished design, use a real executive’s name and arrive at the exact moment a recipient expects an invoice, shipment update or password-reset message.

That is the point.
Phishing is a form of social engineering: a deception designed to persuade someone to hand over passwords, financial information, Social Security numbers, multifactor-authentication codes or other sensitive data, or to click a malicious link or open an infected attachment. The Cybersecurity and Infrastructure Security Agency defines phishing as an online scam that uses deceptive or misleading tactics to entice users to share private information.
The best defense is not technical knowledge alone. It is a pause.
Before clicking, replying, downloading or paying, users should learn to recognize the signals that a message is attempting to create fear, urgency, confusion or misplaced trust. A few seconds of verification can prevent account takeover, identity theft, ransomware or a fraudulent payment that is difficult to recover.
The Federal Trade Commission warns that phishing messages often create a story: suspicious account activity, a failed payment, an unfamiliar invoice, a government refund, a free offer or a request to update personal information. The goal is to make the recipient act before thinking.
The first rule: Do not trust appearance alone
A polished email can still be fraudulent.
Scammers can copy logos, colors, signatures and layouts from banks, retailers, universities, government agencies and major technology companies. They can also use stolen email accounts, making a message appear to come from a real person or organization.
That means the sender’s display name, the name shown in an inbox, is not enough. A message labeled “Amazon Support,” “Your Bank” or “Jane Smith, CFO” may still come from an unrelated address.
The first inspection should focus on the full sender address and, when possible, the reply-to address.
A legitimate-looking display name might conceal an address such as:
- security-alerts@paypaI-support.com
- billing@yourcompany.co
- ceo.office@company-payments.net
- notifications@account-microsoft-security.com
These examples use tactics such as extra words, unfamiliar domains, altered spellings and characters that resemble letters. In the first example, a capital “I” can be used to mimic a lowercase “l.”
The FBI’s Internet Crime Complaint Center advises users to verify the actual email address, particularly on mobile devices where the full address may be hidden or truncated. It also warns users to look for misspellings in hyperlinks and domains that do not match the organization the message claims to represent.
A trusted brand name in the subject line is not proof of authenticity. A familiar logo is not proof. A sender address that merely looks close is not proof.
The pressure test
Phishing messages often rely on emotion rather than evidence.
They create urgency: “Your account will be closed today.” They create fear: “We detected unauthorized access.” They create scarcity: “Claim your refund before it expires.” They create authority: “This is a final legal notice.” Or they create secrecy: “Do not contact anyone else about this request.”
These tactics are designed to override normal caution.
The FTC identifies several common phishing narratives:
- A claim that suspicious activity or log-in attempts were detected.
- A statement that an account or payment method has a problem.
- A request to confirm personal or financial information.
- An invoice for something the recipient did not order.
- A payment link or attachment.
- A purported government refund or benefit.
- A coupon, prize or free offer.
The red flag is not simply urgency by itself. Real organizations sometimes send time-sensitive messages. The danger increases when urgency is combined with a request to click, download, disclose a password, approve a login, change bank details or send money.
A legitimate institution should be able to withstand verification.
If a message appears to come from a bank, open a new browser tab and type the bank’s known web address yourself, or use the official mobile app. If it appears to come from a colleague, call or message that person through a number or channel you already know. If it claims to come from a government agency, find the official contact information independently.
Do not use the phone number, reply button or website link supplied in the suspicious message.
The FTC’s advice is direct: if you know the company or sender, contact the organization using a phone number or website you know is real, not information contained in the email.
Inspect links before you click
A phishing email often succeeds or fails on a single click.
Links can lead to fake login pages designed to capture credentials, websites that install malicious software, pages that collect financial data or forms that ask for a one-time code. The visible text of a link may say www.yourbank.com, while the actual destination points somewhere entirely different.
On a desktop computer, hover over a link without clicking to view the destination address. On a phone, press and hold a link carefully to preview it, although interface behavior can vary by device and app.
Look for:
- Misspelled domains, such as micros0ft.com or arnazon.com.
- Extra words before or after a legitimate brand name.
- Strange domain endings or unrelated country-code domains.
- A long, confusing address that hides the true domain.
- A link that goes to a URL-shortening service when there is no clear reason.
- A website that asks for a password, payment information or multifactor-authentication code unexpectedly.
The FBI specifically recommends ensuring that a URL is associated with the business or person it claims to represent and warns that hyperlinks may contain misspellings of the legitimate domain name.
A secure-looking padlock icon or https alone is not proof that a site is legitimate. Encryption protects the connection between a browser and a website; it does not verify that the website operator is honest. Criminals can obtain certificates for fraudulent domains as well.
When in doubt, do not inspect further by clicking. Close the message and navigate independently to the official website.
Attachments: Treat the unexpected as risky
Attachments remain one of the most common delivery methods for malware and credential theft.
A message may claim to contain an invoice, a shipping notice, a résumé, a legal complaint, a tax document, a voice message or a shared file. The attachment may be a document that prompts the recipient to “Enable Content” or “Enable Macros,” a compressed ZIP file or an executable disguised with a misleading icon.
The most important question is simple: Were you expecting this file from this person?
If the answer is no, verify before opening it. This is especially important for unexpected attachments from known contacts because scammers may compromise real accounts and send malicious files to everyone in an address book.
The FTC notes that links and attachments in suspicious messages may install harmful malware. If you suspect you opened an attachment that downloaded malicious software, update security software, run a scan and remove anything identified as a problem.
Businesses should also configure devices to show full file extensions. A file named Invoice.pdf.exe may appear to be a PDF if extensions are hidden, when it is actually an executable program. The FBI recommends enabling full email and file extensions for employees to help identify suspicious content.
Business email compromise: When fraud sounds like your boss
For organizations, phishing often aims at a payment rather than a password.
Business email compromise, or BEC, is a sophisticated fraud scheme in which criminals impersonate executives, vendors, lawyers or employees to request wire transfers, redirect payroll, change banking information or obtain sensitive records.
The message may not contain an obvious link or attachment. It may simply say: “Are you available?” followed by a request to urgently send a payment or buy gift cards. In more advanced cases, criminals use a compromised real email account and study internal writing styles, invoices and payment processes before sending instructions.
The FBI says BEC has affected victims in all 50 U.S. states and 186 countries. From October 2013 through December 2023, it recorded 305,033 domestic and international incidents and more than $55.4 billion in exposed losses.
The most reliable defense is an independent verification process.
A request to change banking information, pay a new account, alter payroll details or send a large transfer should be confirmed through a second communication channel, for example, a call to a previously verified phone number. Do not reply to the suspicious email to ask whether it is real. If the account is compromised, the criminal may answer.
The FBI recommends using secondary channels and multifactor authentication to verify changes in account information.
Businesses should also use approval rules that require more than one person to authorize significant payments. The control may feel slow until the day it prevents a six-figure loss.
A practical phishing checklist
Before acting on an unexpected email, run through this checklist:
| Question | Why it matters | Safer action |
|---|---|---|
| Was I expecting this message? | Surprise is a common phishing advantage | Pause and verify independently |
| Does the sender’s full address match the claimed organization? | Display names can be forged | Expand the sender details |
| Is the message urgent, threatening or unusually secret? | Pressure reduces careful decision-making | Do not act under deadline pressure |
| Does it request a password, code, payment or personal data? | Legitimate organizations generally do not request sensitive data this way | Use the company’s official app or website |
| Does the link lead to the correct domain? | Fake domains mimic real organizations | Type the official address yourself |
| Is the attachment unexpected or unusual? | It may contain malware | Confirm through another channel |
| Is a payment or bank-change request involved? | BEC losses can be severe | Call a verified contact before acting |
| Does something simply feel off? | Small inconsistencies often matter | Report, delete and do not engage |
This checklist is useful because phishing messages are increasingly well written. Poor grammar remains a warning sign, but it is no longer a reliable test. Criminals can use AI writing tools, copy legitimate communications or target victims in their own language.
The stronger rule is behavioral: unexpected requests for action deserve verification.
Protect accounts before an attack
No defense is perfect. People can make mistakes, especially when messages arrive during a busy workday or appear to come from a trusted source. That is why account security should include layers.
The FTC recommends:
- Keeping computer and phone security software updated automatically.
- Using multifactor authentication on important accounts.
- Backing up data to an external drive or cloud service.
Multifactor authentication, or MFA, makes account takeover harder by requiring more than a password to log in. The additional factor may be an authenticator-app code, security key, push notification or biometric check.
MFA is not invincible. A phishing page can attempt to steal a one-time code, and attackers may use “MFA fatigue” tactics that flood a user with approval prompts. Never approve an unexpected login prompt. If you receive one, change your password through the official site, review account activity and investigate whether someone is trying to access the account.
Use unique, strong passwords for every important service. A password manager can generate and store long, unique credentials, reducing the damage if one company suffers a data breach.
For businesses, protections should include email filtering, domain protections, employee training, payment-verification procedures, restricted administrative access and tested incident-response plans. Training should not shame employees for reporting suspicious messages. A worker who reports uncertainty early may prevent a larger breach.
What to do if you clicked
The right response depends on what happened, but speed matters.
If you clicked a link but did not enter information, close the site. Update security software, run a malware scan and watch for unusual account activity. If you downloaded or opened a file, take the same steps and consider disconnecting the device from the network if you believe it may be infected, particularly in a workplace environment.
If you entered a password, change it immediately through the real service’s website — not through the phishing link. If that password was reused elsewhere, change it there too. Turn on MFA if it is not already enabled and review account-recovery settings, login history, forwarding rules and connected applications.
If you provided financial information, call the financial institution using the number on the back of the card or its official website. Monitor accounts for unauthorized activity. If you shared identifying information such as a Social Security number, the FTC directs consumers to IdentityTheft.gov for a tailored recovery plan.
If money was sent in response to a BEC request, contact the financial institution immediately and ask for a recall or reversal of the transfer. The FBI stresses that time is critical and says prompt reporting may help financial institutions and law enforcement freeze funds. File a complaint with the FBI’s Internet Crime Complaint Center at IC3.gov.
Report it, then delete it
Reporting phishing improves defenses for everyone.
The FTC asks consumers to forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, forward phishing text messages to SPAM (7726), and report the attempt at ReportFraud.ftc.gov.
At work, report suspicious messages through the company’s established security channel, such as the “Report Phishing” button in the email system or the information-technology help desk. Do not forward a suspicious message broadly unless the organization’s security team instructs you to do so; forwarding can spread a dangerous link or attachment.
For small businesses, reporting should be paired with a quick internal review: Did anyone else receive the message? Did anyone reply, click or make a payment? Are login records, mailbox rules or vendor details showing unusual changes?
Phishing succeeds when a recipient is rushed, isolated or embarrassed. The best response is the opposite: pause, verify and report.
FAQs
What is a phishing email?
A phishing email is a fraudulent message designed to trick someone into clicking a malicious link, opening an attachment, sending money or sharing sensitive information such as passwords, bank data or Social Security numbers. CISA describes phishing as an online scam that uses deceptive or misleading tactics to obtain private information.
What are the biggest phishing red flags?
Common signals include unexpected messages, urgent threats, generic greetings, requests to update payment details, mismatched sender addresses, misspelled web domains, unusual attachments and requests for passwords, MFA codes or money. The FTC says phishing scams commonly claim there is a problem with an account, suspicious activity or an invoice requiring action.
Can a phishing email come from a real email address?
Yes. A criminal may compromise a legitimate email account and use it to send fraudulent messages to the owner’s contacts. That is why an email from a known person that contains an unexpected link, attachment or payment request should still be verified independently.
Is it safe to click a link if it uses HTTPS?
Not necessarily. HTTPS encrypts your connection to a website, but it does not prove that the website is legitimate. A fraudulent site can use HTTPS. Check the actual domain name or avoid the link and visit the organization’s official site yourself.
What should I do if I gave a scammer my password?
Change the password immediately through the legitimate website, change it anywhere else it was reused, enable MFA, review recent account activity and check account-recovery settings. If personal or financial information was exposed, follow the FTC’s guidance through IdentityTheft.gov.
What should a business do after a fraudulent payment?
Call your financial institution immediately and request a recall or reversal. Then report to IC3.gov and retain all records including messages, payment information and account information. The FBI said quick action might freeze assets and cut losses.
