In March 2024, a finance employee at a Hong Kong multinational wired $25 million to threat actors after a single phishing email led to a deepfake video call with what appeared to be the company's CFO. That's not a Hollywood plot — it's a police-confirmed incident reported by CNN. And it started with one email that someone didn't question.
Knowing how to spot phishing emails isn't a nice-to-have skill anymore. It's the single most important defensive behavior any employee can develop. According to the Verizon 2024 Data Breach Investigations Report, phishing and pretexting accounted for over 70% of social engineering incidents. Your inbox is the front line, and this post gives you the exact techniques to hold it.
Why Phishing Still Works in 2026
Phishing emails aren't the poorly spelled Nigerian prince scams of 2005. Modern threat actors use AI-generated text, cloned brand templates, and harvested personal data to craft messages that look legitimate. I've reviewed phishing kits sold on dark web forums that include pixel-perfect replicas of Microsoft 365 login pages, complete with CAPTCHA prompts.
The reason phishing still works isn't technology — it's psychology. These emails exploit urgency, authority, and fear. A message claiming your account will be locked in 24 hours bypasses your rational brain and triggers a click before you think.
And the stakes keep climbing. The FBI's 2023 IC3 Annual Report documented over $2.9 billion in losses from business email compromise alone. That number doesn't include the ransomware infections, credential theft, and data breaches that start with a single phishing email.
How to Spot Phishing Emails: 8 Red Flags That Matter
I've trained thousands of employees across industries, and these are the indicators I teach first. Not every phishing email will have all of them — sophisticated ones might only show one or two. But if you see any of these, slow down.
1. The Sender Address Doesn't Match the Brand
The display name says "Microsoft Support" but the actual email address is [email protected]. Always hover over or tap the sender's address to see the real domain. One swapped character is all it takes.
2. Urgency or Threats Drive the Message
"Your account will be permanently deleted in 12 hours." "Immediate action required to avoid legal consequences." Legitimate organizations rarely threaten you via email with tight deadlines. Threat actors use urgency because it works — it short-circuits your judgment.
3. The Link URL Doesn't Go Where It Claims
Hover over any link before clicking. If the button says "Sign in to your bank account" but the URL points to login.bankofamerica.com.phish-site.ru, that's a credential theft attempt. On mobile, press and hold the link to preview the destination.
4. Unexpected Attachments
An invoice you didn't request. A shipping notification you weren't expecting. A "voicemail" in .html format. Malicious attachments remain one of the most common ransomware delivery methods. If you didn't expect it, verify it through a separate communication channel before opening.
5. Generic Greetings from Services That Know Your Name
Your bank knows your name. Your employer knows your name. "Dear Valued Customer" or "Dear User" from a service you use daily is a signal the sender is blasting a list, not writing to you.
6. Requests for Credentials or Sensitive Data
No legitimate IT department, bank, or government agency will ask you to email your password, Social Security number, or multi-factor authentication codes. Ever. If an email asks for these, it's social engineering.
7. Slightly Off Branding or Formatting
Blurry logos, inconsistent fonts, unusual spacing, or a footer that references the wrong year. Phishing templates are good, but they're rarely perfect. Compare the suspicious email side-by-side with a legitimate one from the same sender.
8. The "Too Good to Be True" Offer
A $500 gift card for completing a survey. A tax refund you didn't file for. An inheritance from a relative you've never heard of. These lures prey on greed and curiosity. Close the email and move on.
What Does a Phishing Email Actually Look Like?
Here's a scenario I use in phishing awareness training for organizations: an employee receives an email that appears to come from their company's HR department. The subject line reads "Updated PTO Policy — Action Required by Friday." The email body uses the company logo, references the correct fiscal year, and includes a link to "review and acknowledge the new policy."
The link leads to a cloned SharePoint login page. The employee enters their credentials, and now the attacker has access to the corporate network. No malware was needed. No vulnerability was exploited. Just one convincing email and one moment of inattention.
This is why phishing simulation exercises are so critical. They give employees the experience of being targeted in a safe environment, which builds the pattern recognition that stops real attacks.
The $4.88M Lesson Most Organizations Learn Too Late
IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million. Phishing was the top initial attack vector. Let that sink in — the most expensive security problem most organizations face starts with an email that someone shouldn't have clicked.
Here's what actually happens in the organizations I work with that get this right: they don't rely on a single annual training session. They build a culture of skepticism. Monthly phishing simulations. Immediate feedback when someone clicks a test link. Recognition when someone reports a real phishing attempt to IT.
That continuous approach is exactly what we've built into our cybersecurity awareness training program. It covers not just phishing, but the broader threat landscape employees need to understand — from ransomware to zero trust principles.
What to Do When You Spot a Phishing Email
Spotting the email is only half the job. What you do next determines whether your organization stays safe or gets compromised through someone else's inbox.
- Don't click any links or open attachments. Not even to "check."
- Don't reply. Responding confirms your address is active and monitored.
- Report it immediately. Use your organization's phishing report button (most email clients have one), or forward it to your IT/security team.
- If you already clicked, say so. Speed matters in incident response. Change your password immediately and enable multi-factor authentication if it's not already active. Alert your security team so they can contain the damage.
- Warn your colleagues. If a phishing email hit your inbox, it probably hit others too. A quick heads-up on Slack or Teams can prevent the next click.
Why "Just Be Careful" Isn't a Strategy
I hear this constantly from leadership: "We just tell our people to be careful with email." That's not security awareness — that's wishful thinking. Being careful without knowing what to look for is like telling someone to drive safely without teaching them what a stop sign looks like.
Effective defense against phishing requires structured, ongoing training. Employees need to see real examples. They need to practice identifying threats in controlled phishing simulations. They need to understand the psychology behind social engineering so they can recognize the emotional triggers that threat actors exploit.
The organizations that invest in this consistently see measurable results. CISA recommends regular phishing exercises as a core component of any cybersecurity program, and the data backs that up — organizations that run monthly simulations see click rates drop by over 60% within the first year.
Quick Reference: How to Spot Phishing Emails
If you remember nothing else from this post, remember this checklist:
- Check the sender's actual email address, not just the display name.
- Hover over links before clicking — verify the real destination URL.
- Be suspicious of urgency, threats, or too-good-to-be-true offers.
- Never provide passwords, MFA codes, or sensitive data via email.
- Verify unexpected attachments or requests through a separate channel.
- Report suspicious emails to your IT or security team immediately.
Phishing isn't going away. The tools and techniques will keep evolving, and AI is making these attacks harder to detect by the month. But the fundamentals of how to spot phishing emails remain consistent: slow down, look for the red flags, and verify before you act.
Your inbox will always be a target. Make it a well-defended one.