Back to all articles

E-mail fraud: when everything looks legitimate

E-mail remains a common entry path. An attacker may not need to “crack passwords” — one person clicking a link that mimics SharePoint, a bank, or a supplier is enough. Clear rules beat vague “be careful” advice.

Red flags: artificial urgency, payment account changes, macro attachments, senders that look almost like a real domain. Genuine providers rarely push you to enter a password on a random page immediately.

Same story on SMS, WhatsApp, and social

Scam copy often mirrors e-mail, just on a phone with less room to think. On WhatsApp or Facebook a hijacked friend account sends “urgent” links; another trick is asking you to forward an SMS code (they are resetting your account elsewhere). Same defense: second-channel verification, no pressured clicks. See smishing and family impersonation.

What looks credible but is still a trick

Clients show a display name first; that is trivially spoofed. The real domain (and sometimes Return-Path) matters. Homoglyph domains swap letters for visually similar Unicode characters and pass a quick glance.

HTML links can show one label and point elsewhere — hover or view source to see the target. QR codes in attachments hide the URL entirely and are increasingly used for payment scams.

Example: invoice with a new bank account

An attacker mimics a real supplier thread and sends an invoice that matches past PDFs except for the IBAN or reference. A rushed AP clerk may pay fraud. Fix: verify any payment-detail change via a known historical phone number (contract, past invoice), never the number embedded in the same e-mail.

What to do

  • Verify payments or detail changes via a second channel (call a known number, not one from the mail).
  • Train with examples from your industry, not only generic slides.
  • Add mail hygiene (SPF/DKIM/DMARC, secure gateways) — see our DMARC article.

Filters help, but the click decision is human. Provide a simple escalation path: who to report to, and that caution is welcome.