In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook — using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from spoofed email addresses, and two of the most sophisticated tech companies on the planet paid up without blinking. If it can happen to them, it can absolutely happen to your organization.
A fake email — whether it's a phishing lure, a spoofed executive request, or a bogus invoice — remains the single most effective weapon in a threat actor's arsenal. The FBI's Internet Crime Complaint Center (IC3) reported that business email compromise (BEC) and phishing complaints resulted in over $2.9 billion in adjusted losses in 2023 alone. That number has only grown since.
This post breaks down exactly how fake emails work, how to identify them in seconds, and what your organization should do to stop them from ever reaching an inbox — or succeeding if they do.
What Makes a Fake Email So Dangerous?
Most people picture a fake email as an obvious Nigerian prince scam. That era is long gone. Modern fake emails are surgically targeted, visually identical to legitimate messages, and timed to exploit urgency or authority.
Here's what actually happens in a well-crafted attack. A threat actor researches your company on LinkedIn, identifies your CFO and CEO, then sends an email from a domain one character off — say, "@companly.com" instead of "@company.com." The email looks exactly like an internal request. It uses the CEO's real signature block. It asks for a wire transfer to close a deal before end of day.
Your CFO has seen a hundred emails like this. They comply. The money vanishes into a mule account overseas within minutes.
This is social engineering at its most effective — and it starts with a single fake email.
The Anatomy of a Fake Email: What to Look For
I've analyzed thousands of phishing messages over my career. The good ones are hard to catch. But even the best fake emails leave fingerprints if you know where to look.
1. Sender Address Doesn't Match the Display Name
The display name might say "Microsoft Security Team," but the actual address is something like [email protected]. Always expand the sender field. This is the single fastest way to catch a fake email.
2. Urgency and Emotional Pressure
"Your account will be suspended in 24 hours." "Immediate action required." "You have an outstanding invoice." Threat actors use urgency to bypass your critical thinking. Legitimate companies rarely threaten you in the first email.
3. Mismatched or Suspicious Links
Hover over every link before clicking. If the visible text says "https://portal.office.com" but the actual URL points to "hxxps://office-login.sketchy-domain.ru" — that's credential theft waiting to happen. On mobile, long-press to preview URLs.
4. Generic Greetings and Odd Formatting
"Dear Valued Customer" from a company that should know your name is a red flag. Watch for inconsistent fonts, misaligned logos, and awkward grammar. These details often slip through when attackers clone legitimate templates.
5. Unexpected Attachments
An unsolicited PDF, ZIP, or Excel file — especially one that asks you to enable macros — is a classic ransomware delivery mechanism. If you weren't expecting it, don't open it.
How Do You Tell If an Email Is Fake?
This is the question I get asked the most. Here's a quick checklist you can use every time something feels off:
- Check the sender's full email address — not just the display name.
- Hover over all links — verify the destination domain matches the sender's organization.
- Look for pressure tactics — real companies give you time to respond.
- Verify through a second channel — call the sender directly using a known phone number, not one from the email.
- Check email headers — tools like Google's "Show original" or Outlook's "Message headers" reveal the true origin server and SPF/DKIM/DMARC authentication results.
- Report it — forward suspicious messages to your IT or security team before taking any action.
When in doubt, pick up the phone. A 30-second call has saved companies millions.
The $4.88M Lesson Most Organizations Learn Too Late
According to IBM's 2024 Cost of a Data Breach report, the global average cost of a data breach reached $4.88 million. Phishing — which starts with a fake email — was consistently among the top initial attack vectors.
What makes this worse is that most organizations already have email security gateways in place. They have spam filters. They might even have DMARC configured. But threat actors continuously evolve. They use legitimate services like Google Forms, SharePoint, and Dropbox to host phishing pages. They compromise real email accounts to send messages that pass every technical check.
Technology alone won't save you. Your people are the last line of defense — and they need training that goes beyond a once-a-year compliance video.
Why Phishing Simulations Change the Game
In my experience, organizations that run regular phishing simulations see click rates on fake email campaigns drop by 50-75% within six months. The key word is regular. One-and-done training doesn't stick.
Effective phishing simulation programs send realistic fake emails to employees, track who clicks, and deliver immediate, contextual training at the moment of failure. This creates a feedback loop that builds real-world recognition skills — not just checkbox compliance.
If your organization doesn't have a phishing simulation program, that's a gap you need to close now. Our phishing awareness training for organizations provides exactly this kind of hands-on, scenario-based education that builds genuine resilience against fake email attacks.
Building a Culture That Catches Fake Emails
Technical controls matter. You should absolutely implement SPF, DKIM, and DMARC. You should enforce multi-factor authentication across every account. You should adopt a zero trust architecture that doesn't assume any request is legitimate just because it came from inside the network.
But the organizations I've seen handle email threats best are the ones that build a culture of healthy skepticism. Here's what that looks like:
Make Reporting Easy and Rewarded
If your employees feel like reporting a suspicious email is a hassle — or worse, that they'll get in trouble for false positives — they won't report anything. Deploy a one-click "Report Phish" button in your email client. Recognize employees who catch threats.
Train Continuously, Not Annually
Threat actors don't take 11 months off between campaigns. Your security awareness training shouldn't either. Short, frequent modules beat long annual sessions every time. Our cybersecurity awareness training program is designed around this principle — practical, current, and built for continuous reinforcement.
Brief Your Finance and Executive Teams Specifically
BEC attacks target the people who move money and make decisions. Your CEO, CFO, and accounts payable team need tailored training that addresses the specific fake email scenarios they'll face — wire transfer requests, vendor payment changes, and W-2 data requests.
What To Do When a Fake Email Gets Through
Even with the best defenses, a fake email will eventually reach an inbox. Here's your response playbook:
- Don't panic. Receiving a fake email isn't a breach. Clicking a link or entering credentials is.
- If credentials were entered: Reset the password immediately. Revoke active sessions. Check for forwarding rules or inbox modifications the attacker may have created.
- If money was transferred: Contact your bank immediately. File a complaint with the FBI's IC3. Time is critical — funds can sometimes be recovered if reported within 24-48 hours.
- Preserve evidence: Don't delete the email. Save full headers and any attachments for your incident response team or law enforcement.
- Notify your team: If one person received the fake email, others likely did too. Send an alert with specific indicators so people know what to look for.
The Threat Isn't Slowing Down
CISA's ongoing advisories consistently identify phishing and fake email campaigns as the primary initial access vector for ransomware attacks, data breaches, and espionage operations. The agency's StopRansomware initiative provides regularly updated guidance on current threat patterns — it's worth bookmarking.
The Verizon 2024 Data Breach Investigations Report found that 68% of breaches involved a human element — with phishing and pretexting leading the way. A fake email is still the easiest door for an attacker to walk through.
Your email gateway will catch the obvious stuff. Your DMARC policy will block some spoofs. But the well-crafted, targeted fake email that slips through every filter? Only a trained, skeptical human will stop that one.
Invest in your people. Run phishing simulations. Build the muscle memory that turns every employee into a sensor. That's how you win this fight.