The Email That Cost One Company $37 Million

In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked legitimate. It used correct names, proper formatting, and convincing language. The only thing standing between a normal workday and catastrophe was one employee's ability to recognize email phishing red flags — and that day, the red flags were missed.

I've spent over a decade helping organizations build security awareness programs, and the pattern is always the same. People assume phishing emails are obvious — broken English, Nigerian prince schemes, laughably fake logos. That era is over. Modern phishing is polished, targeted, and devastatingly effective.

This post walks you through the nine email phishing red flags that I see fooling real employees in real organizations every single week. Bookmark it. Share it with your team. Print it and tape it to a monitor if you have to.

Why Phishing Still Works in 2026

According to the Verizon Data Breach Investigations Report, phishing and pretexting accounted for the vast majority of social engineering incidents in their most recent analysis. Despite billions spent on email security tools, the human element remains the weakest link.

The reason is simple: threat actors don't need to beat your firewall. They need to beat one distracted employee at 4:47 PM on a Friday. And they're getting better at it every quarter. Generative AI has supercharged phishing campaigns, eliminating the grammar mistakes and formatting errors that used to give attackers away.

That means your team needs sharper instincts. Here are the red flags that actually matter.

9 Email Phishing Red Flags Your Team Needs to Know

1. Urgency That Feels Manufactured

"Your account will be locked in 2 hours." "Respond immediately or payroll will be delayed." Threat actors weaponize panic. They want you clicking before thinking. Legitimate organizations rarely impose a two-hour ultimatum via email.

In my experience, this is the single most effective tactic in phishing simulations. When we run phishing awareness training campaigns for organizations, urgency-based emails consistently get the highest click rates.

2. Sender Address Doesn't Match the Display Name

The email says it's from "Microsoft Security Team," but the actual address is [email protected]. Most email clients hide the full sender address behind a display name. Train your employees to click on that display name and inspect the actual domain every single time.

3. Generic Greetings on Supposedly Personal Messages

"Dear Customer" or "Dear User" on an email that claims to be from your bank, your HR department, or your CEO. If the sender actually knew you, they'd use your name. This red flag is less reliable than it used to be — attackers now scrape LinkedIn for names — but combined with other signals, it still matters.

Hover before you click. Always. The hyperlink text says https://portal.microsoft.com, but the actual URL points to microsft-portal.credential-update.xyz. This mismatch is one of the most reliable email phishing red flags you'll ever encounter. On mobile devices, long-press the link to preview the destination.

5. Unexpected Attachments — Especially Office Files and PDFs

If you weren't expecting a document, don't open it. Malicious macros embedded in Word and Excel files remain a primary ransomware delivery mechanism. Even PDFs can contain embedded scripts and malicious links. When in doubt, verify with the sender through a separate communication channel — not by replying to the suspicious email.

6. Requests for Credentials or Sensitive Data

No legitimate IT department will ask for your password via email. No bank will ask you to "verify" your Social Security number by clicking a link. This is credential theft, plain and simple. If an email asks you to log in somewhere, navigate to the site directly through your browser — never through the link provided.

7. Domain Spoofing and Lookalike Domains

This is where attacks get sophisticated. Threat actors register domains like arnazon.com, paypa1.com, or g00gle.com. At a glance — especially on a phone screen — these look legitimate. I've seen attackers use internationalized domain names with Cyrillic characters that are visually identical to Latin letters. Your naked eye literally cannot tell the difference.

This is why technical controls like DMARC, SPF, and DKIM matter. But they're not foolproof, so awareness remains critical. CISA's Shields Up guidance recommends layering technical defenses with ongoing employee training.

8. Unusual Tone or Writing Style from Known Contacts

Your CFO sends you a casual Slack-style message asking for a wire transfer, but she normally writes formal emails with a specific signature block. That mismatch should trigger alarm bells. Business email compromise attacks often impersonate executives, and the tone is usually slightly off. Trust your gut when something reads differently than expected.

9. Emails That Bypass Normal Processes

"Don't tell anyone about this yet." "Handle this personally — don't loop in the team." Any email that asks you to circumvent established procedures is almost certainly an attack. Legitimate executives don't ask employees to secretly wire $50,000 to a new vendor without going through procurement.

What Are the Most Common Email Phishing Red Flags?

The most common email phishing red flags include manufactured urgency, mismatched sender addresses, generic greetings, suspicious links that don't match their display text, unexpected attachments, requests for login credentials, lookalike domains, unusual tone from known contacts, and instructions to bypass normal business processes. Recognizing even one of these signals should prompt you to stop, verify the sender through a separate channel, and report the email to your security team.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million in 2024. Phishing was consistently one of the top initial attack vectors. And yet, many organizations still treat security awareness training as a once-a-year checkbox exercise — a 30-minute video in January that nobody remembers by March.

That approach doesn't work. What works is continuous reinforcement. Regular phishing simulations. Bite-sized training modules delivered throughout the year. Building a culture where reporting a suspicious email is rewarded, not mocked.

If you're ready to build that kind of program, our cybersecurity awareness training platform gives you the structure and content to make it happen. Pair it with ongoing phishing simulation exercises and you're building actual resilience — not just compliance paperwork.

Beyond Red Flags: Building a Zero Trust Mindset

Spotting email phishing red flags is necessary but not sufficient. Your organization also needs layered defenses. Multi-factor authentication on every account. Zero trust architecture that verifies every access request. Email filtering with AI-powered threat detection. Endpoint detection and response tools that catch what humans miss.

The NIST Cybersecurity Framework lays out a comprehensive approach that balances people, processes, and technology. No single control stops phishing. But a well-trained workforce, combined with modern technical defenses, makes your organization dramatically harder to compromise.

What to Do When You Spot a Phishing Email

  • Don't click anything. No links, no attachments, no images.
  • Don't reply. Not even to tell the attacker you know it's fake.
  • Report it. Use your organization's phishing report button or forward it to your security team.
  • Verify separately. If the email appears to come from a colleague, call or message them directly using contact info you already have.
  • Delete it. Once reported, remove it from your inbox.

Your Employees Are Your Last Line of Defense

Every security tool you own can be bypassed. Every email filter has blind spots. At some point, a phishing email will land in someone's inbox — perfectly formatted, properly spelled, and dangerously convincing.

The only thing standing between that email and a data breach is whether your employee can recognize the red flags. That's not a technology problem. That's a training problem.

Invest in your people. Teach them what real phishing looks like — not the cartoonish examples from a decade ago, but the sophisticated social engineering campaigns that threat actors deploy today. Run simulations. Measure results. Repeat.

Because the next phishing email is already on its way.