Every phishing email uses one of nine tricks. Learn them once and you'll see them coming for the rest of your life.
Phishing is the starting point of most breaches, and it succeeds for a simple reason: it doesn't attack your computer, it attacks your attention. Every technique below is a different way of getting you to act before you think. Learn the tricks once, and you'll see them coming for the rest of your life.
Ready to test yourself? After reading this guide, take our interactive phishing test: ten realistic scenarios, your score emailed to you with a results link you can share with your manager.
The display name says "Microsoft Support" but the address is helpdesk@micros0ft-verify.com. Or the domain is one character off: rnicrosoft.com, paypa1.com, company-portal.net instead of portal.company.com. On phones, mail apps often show only the display name, so tap it to reveal the real address.
The link leads to a pixel-perfect copy of a real login page: Microsoft 365, Google, your bank. You type your password; the attacker receives it and often forwards you to the real site so nothing seems wrong. Tell: the address bar. The page can copy everything except the real domain.
"Your account will be closed in 24 hours." "Unusual sign-in detected, verify now." "Final notice." Deadlines and threats exist to make you skip the checking you'd normally do. Real companies rarely give ultimatums by email, and nothing legitimate is ruined by a five-minute pause.
Fake invoices, "voicemail" files, shipping labels, résumés. Danger formats: .html attachments (open a fake login page on your own machine), Office files that ask you to Enable Content (that button runs code), and .zip/.iso archives that smuggle programs past filters. If you weren't expecting it, don't open it. Verify with the sender another way.
No links, no attachments, no malware, just a short message that appears to come from your CEO or a vendor: "Are you at your desk? I need a favor, keep this between us." It escalates to gift cards, wire transfers, or "updated banking details." Because there's nothing technical to detect, filters miss it. Your verification habit is the only defense: confirm any money-moving request through a channel you already trust.
Personalized phishing built from your LinkedIn, your company's website, or a previous breach: it names your boss, your projects, your travel. Accuracy is not proof of legitimacy. Our social engineering guide covers this in depth.
The same cons by text message ("USPS: your package is on hold, pay a $0.30 redelivery fee") or QR code on a poster, parking meter, or emailed "invoice." QR codes are links you can't read before opening, so treat unexpected ones like unexpected links, because that's what they are.
An attacker with your password bombards you with approval pop-ups until you tap Approve, or phones you "from IT" asking for the six-digit code you were just texted. Never approve a login you didn't start; never read a code to anyone. No legitimate organization asks for one.
The scariest one: attackers compromise a real mailbox and reply inside an existing email thread, complete with real history, real signature, and real context, delivering a poisoned link or "updated invoice." The thread being genuine doesn't make the newest message genuine. Unusual requests get verified out-of-band, no matter how real the thread looks.
Before acting on any message that wants something from you, run this checklist:
When in doubt, report it. Forward suspicious messages to your IT team (or to us) rather than deleting them quietly; one report can protect fifty coworkers who got the same email. And if you clicked before thinking, see Think you've been hacked?. Fast reporting beats perfect prevention every time.
We run live training sessions and can set up ongoing simulated phishing campaigns for your business.