Skip to Main Content
Phishing

Phishing email examples, annotated

Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.

Subash Poudel4 min read

The short answer

  1. The pretexts that dominate are mundane - deliveries, invoices, password resets, tolls - because dramatic stories get scrutinised.
  2. In almost every example the giveaway is structural, not visual - a lookalike domain, a mismatched link, or a request no real organisation makes.
  3. Bank fraud alerts are the costliest pattern, because they end with moving money to a "safe account" that belongs to the attacker.
  4. CEO and supplier fraud carries no link at all, which defeats every link-checking habit.
  5. The same test resolves all six - stop, and reach the organisation through a route you chose.

The most useful thing about studying phishing examples is discovering how boring the effective ones are. There is no dramatic story, no obvious tell, no broken English. Just a routine notice about something you might plausibly have forgotten.

Six patterns, annotated.

1. The bank fraud alert

From: Barclays Fraud Team <alerts@barclays-secure.net> Subject: Unusual activity on your account — action required

We detected a payment of £1,204.00 to a new payee at 03:41. If you did not authorise this, cancel it immediately.

[Cancel this payment]

This link expires in 30 minutes for your security.

What it is doing. Leading with fear and a specific number, then offering the reassuring action rather than the suspicious one. You are not being asked to send money — you are being asked to stop a payment, which feels protective.

The tells. barclays-secure.net is a secure.net domain. The 30-minute expiry has no security purpose; it exists to prevent you thinking. The precision of "£1,204.00 at 03:41" is manufactured credibility.

2. The delivery notice

From: Royal Mail <info@rm-redelivery.info> Subject: Your parcel is on hold

We attempted delivery but the address is incomplete. Confirm your details and pay the outstanding £1.99 shipping fee to reschedule.

What it is doing. Everyone is expecting something. The amount is trivially small, which lowers resistance — you are not evaluating a £1.99 charge, you are clearing an annoyance.

The tells. Delivery companies do not charge redelivery fees by text link. The domain is unrelated to the brand. The real object is not £1.99; it is the card details entered to pay it.

3. The unpaid toll

From: +1 (445) 202-XXXX Subject: (SMS)

E-ZPass: You have an unpaid toll of $6.35. Late fees of $75 will apply and your vehicle registration may be suspended. Pay now: ezpass-toll-pay.us

What it is doing. A plausible small debt, a disproportionate consequence, and a real programme name. If you drive anywhere with tolls, you cannot be certain you did not miss one.

The tells. Registration suspension over $6.35 is not how toll authorities operate. The domain is not the agency's. The FTC identified exactly this pattern as a major driver of the 40% rise in government-impersonation reports in 2025.

4. The password reset you did not request

From: Microsoft account team <no-reply@ms-accountsecure.com> Subject: Did you request a password reset?

If this was not you, secure your account immediately.

[This wasn't me — secure my account]

What it is doing. Inverting the usual instinct. You have been trained not to click links in unexpected emails, but this one appears to be warning you about someone else's activity. The safe-seeming button is the malicious one.

The tells. The domain again. And the structural point: a genuine "was this you?" notice does not need you to follow its link — you can always check account security by going to the service directly.

5. The invoice

From: Accounts <accounts@sup-plierinvoices.com> Subject: RE: Invoice 4471 — overdue

Hi, following up on the attached. Our bank details have changed since the last payment — updated remittance information is in the PDF.

invoice_4471.pdf

What it is doing. The RE: implies an existing thread. The tone is administrative and slightly impatient, which discourages questions. The payload is a changed bank account.

The tells. A supplier changing bank details by email is the single most reliable fraud indicator in business payments. It should always be verified by phone, using a number from your own records — never one in the email.

6. CEO or colleague fraud

From: Sarah Whitmore <s.whitmore.ceo@gmail.com> Subject: Quick favour

Are you at your desk? I'm in back-to-back meetings and need something handled discreetly. Don't call — just reply here.

What it is doing. Authority plus isolation. "Don't call" is presented as convenience and functions as a defence against verification. The initial message asks for nothing, which is why filters miss it and why you reply.

The tells. A personal email address for work. Discretion combined with urgency. Most of all: an explicit reason not to verify.

What every example has in common

PatternPresent in
Unexpected contactAll six
A plausible, mundane pretextAll six
Manufactured time pressure1, 2, 3, 6
A domain that is nearly right1, 2, 3, 4, 5
A reason not to verify independently1, 6

None of these depends on the message looking wrong. All six can be resolved by the same move: stop, and reach the organisation through a route you chose yourself. Full method in how to identify a phishing email.

Sort real messages under time pressure

Our inbox drill gives you a full mailbox of genuine and fraudulent messages and asks you to clear it — which is a very different skill from reading examples.

Try it free

Frequently asked questions

What does a phishing email look like?
Usually mundane. The most effective ones imitate routine notices — a delivery that needs an address confirmed, an invoice, a password reset, an unpaid toll — because an ordinary message invites less scrutiny than a dramatic one. Visual quality is high; the giveaways are structural.
What is the most common phishing email right now?
Delivery and toll notices by text, and bank fraud alerts by phone or message. The FTC reported that government impersonation reports rose 40% in 2025, driven substantially by fake unpaid-toll messages spoofing real programmes such as E-ZPass and SunPass.
Can a phishing email be dangerous if I only open it?
Opening a message is very rarely the harmful step on a modern, updated device. The risk comes from what follows — clicking a link and entering credentials, approving a login prompt, or opening an attachment. Remote images loading can confirm your address is active, which is a reason to disable automatic image loading but not a reason to panic.
How do I report a phishing email?
In the UK, forward it to report@phishing.gov.uk. In the US, report to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov. Also report it inside your mail client, which improves filtering for everyone, and tell the impersonated organisation — most banks have a dedicated address.

Sources

  1. New trends in reports of imposter scams Federal Trade Commission, 2026
  2. Phishing Activity Trends Report, 1st Quarter 2025 Anti-Phishing Working Group, 2025

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.