E-mail remains a common entry path. An attacker may not need to “crack passwords” — one person clicking a link that mimics SharePoint, a bank, or a supplier is enough. Clear rules beat vague “be careful” advice.
Red flags: artificial urgency, payment account changes, macro attachments, senders that look almost like a real domain. Genuine providers rarely push you to enter a password on a random page immediately.
Same story on SMS, WhatsApp, and social
Scam copy often mirrors e-mail, just on a phone with less room to think. On WhatsApp or Facebook a hijacked friend account sends “urgent” links; another trick is asking you to forward an SMS code (they are resetting your account elsewhere). Same defense: second-channel verification, no pressured clicks. See smishing and family impersonation.
What looks credible but is still a trick
Clients show a display name first; that is trivially spoofed. The real domain (and sometimes Return-Path) matters. Homoglyph domains swap letters for visually similar Unicode characters and pass a quick glance.
HTML links can show one label and point elsewhere — hover or view source to see the target. QR codes in attachments hide the URL entirely and are increasingly used for payment scams.
Example: invoice with a new bank account
An attacker mimics a real supplier thread and sends an invoice that matches past PDFs except for the IBAN or reference. A rushed AP clerk may pay fraud. Fix: verify any payment-detail change via a known historical phone number (contract, past invoice), never the number embedded in the same e-mail.
What to do
- Verify payments or detail changes via a second channel (call a known number, not one from the mail).
- Train with examples from your industry, not only generic slides.
- Add mail hygiene (SPF/DKIM/DMARC, secure gateways) — see our DMARC article.
Filters help, but the click decision is human. Provide a simple escalation path: who to report to, and that caution is welcome.