Phishing Email
Learn how phishing emails work, how to spot them, and how to protect yourself. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is a phishing email?
A phishing email is a fraudulent message designed to trick you into revealing sensitive information such as passwords, banking credentials, or personal identification by impersonating a trusted source. The term "phishing" is a deliberate play on "fishing": scammers cast a wide net and wait for unsuspecting people to take the bait.
These emails typically masquerade as communications from well-known organisations your bank, a delivery service, a government agency, or a popular platform like Google, PayPal, or Amazon. They look convincing because scammers invest effort in copying logos, formatting, and language from the real organisation's communications.
Anyone with an email address is a potential target. Phishing does not discriminate by age, profession, or technical ability. It is the most common form of cybercrime in the world precisely because it does not require sophisticated hacking — it relies on deceiving people, not breaking through software.
Who is targeted: General internet users, employees, bank customers, students, and anyone with an email account.
Why it works: Phishing exploits trust in familiar brand names, creates a sense of urgency that overrides careful thinking, and uses visual design to appear legitimate at a glance.
Scale & Statistics
How common is this scam?
Phishing email is not a minor nuisance — it is the dominant form of cybercrime globally, and its scale is growing every year.
- 3.4 billion phishing emails are sent every single day worldwide
- $17.4 billion in global financial losses from phishing attacks in 2024 — a 45% increase from the previous year
- 193,407 phishing complaints were filed with the FBI's Internet Crime Complaint Center (IC3) in 2024 alone
- $4.88 million is the average cost of a phishing-related data breach to an organisation
- 96% of all phishing attacks are delivered via email, making it the dominant attack channel
- 45% of professionals surveyed globally in 2024 reported having fallen victim to a cyberattack or online scam, many originating from phishing emails
- It takes an average of 254 days to identify and contain a breach that began with a phishing email
Most affected sectors: financial services (23.5% of all attacks), healthcare, and SaaS platforms.
Sources: FBI IC3 2024 Internet Crime Report; IBM Cost of a Data Breach Report 2024; Anti-Phishing Working Group (APWG) Q4 2024; NordVPN Phishing Statistics 2025
How It Works
How does it work?
Modern phishing emails are far more sophisticated than the poorly worded messages of the early 2000s. Today's attacks are often indistinguishable from genuine communications, increasingly powered by AI tools that personalise messages at scale.
-
The scammer chooses a target and a lure — They decide whether to target individuals broadly (mass phishing) or a specific group such as customers of a particular bank. They select a trusted brand to impersonate.
-
A fake landing page is created — The scammer builds a website that closely mirrors the real organisation's login page or form, hosted on a domain that looks similar (e.g.
paypa1-secure.cominstead ofpaypal.com). -
The email is sent — A bulk email is distributed with an urgent subject line such as "Your account has been compromised" or "Action required: verify your identity." The message includes a link to the fake page.
-
The victim clicks and enters their credentials — Believing the email to be genuine, the victim logs in or submits personal data on the fake page.
-
The data is harvested — Credentials are instantly captured and used to access real accounts, make fraudulent transactions, or sold on dark web marketplaces.
Platforms and tools commonly used: Email (Gmail, Outlook, corporate systems), SMS follow-ups, and AI writing tools to craft convincing copy.
Recent variations in 2024–2025:
- AI-generated phishing emails now achieve a 54% click-through rate, compared to 12% for human-written messages
- Over 73% of phishing emails in 2024 showed signs of AI assistance
- QR codes embedded in emails are used to bypass link-scanning filters
- Trusted platforms like SharePoint, Google Drive, and Zoom are exploited as hosting ground for malicious links — used in 96% of business-targeted attacks in 2024
Psychological Tactics
What psychological tactics are used?
Phishing emails succeed not because of technical sophistication, but because they are engineered to bypass rational thinking. Scammers study human psychology carefully.
| Tactic | How it is used |
|---|---|
| Urgency | "Your account will be suspended in 24 hours." Urgency compresses the time available for careful thought. |
| Authority | Impersonating a bank, government body, employer, or well-known platform creates an automatic compliance instinct. |
| Fear | Threats of account loss, legal action, unpaid fines, or missed deliveries trigger an emotional response that overrides scepticism. |
| Familiarity | Using your name, employer, or recent activity (gathered from data breaches or social media) makes the message feel personal and credible. |
| Social proof | Phrases like "millions of users have already updated their security" make inaction feel abnormal. |
| Reward | Promises of a refund, prize, or unclaimed package appeal to positive anticipation. |
Even cautious, technically literate people fall for phishing. When we are anxious, distracted, or tired, our brains shortcut to instinct. A well-timed phishing email — arriving just after a real delivery, or mimicking a bank you actually use — can fool anyone. The deception is designed for the average person in a busy moment, not someone reading slowly and carefully.
Real-Life Example
A real-life case
Case: US government agency finance employee transfers $218,992 to fraudsters via phishing email (2023)
What happened: A finance employee at a US government agency received an email that appeared to come from a known supplier the agency regularly worked with. The message explained that the supplier's banking details had changed and requested that future payments be directed to a new account. The email used the supplier's real name, referenced ongoing contracts, and looked identical to previous legitimate correspondence.
How it unfolded: The employee, seeing nothing unusual about the request — supplier bank detail updates are routine — processed the change through the agency's payment system. No additional verification was sought because the sender's name was familiar, the request seemed procedurally normal, and there was no obvious urgency or alarm. The next scheduled payment of $218,992 was transferred to the fraudulent account.
The outcome: The fraud was only discovered when the real supplier followed up on a missing payment. By that point the funds had already been moved through multiple accounts and were unrecoverable. The attack is classified as Business Email Compromise (BEC) — a form of phishing targeting payment processes — and illustrates how phishing does not always involve a suspicious link or urgent panic. Sometimes the most dangerous attacks are the quietest ones.
Source: Splunk Cybersecurity Blog, "Phishing Attacks: Protecting Against Them," 2024 — splunk.com
Red Flags to Watch
Red flags to watch for
- The sender's email domain does not exactly match the real organisation — look for subtle swaps like
arnazon.com,paypa1.com, or extra words such assupport-paypal.com - The message creates urgency or threatens an immediate consequence if you do not act — "Your account will be closed within 12 hours"
- You are asked to click a link and log in, even if the link appears to show a legitimate URL (the visible text and the actual destination can differ)
- The greeting is generic — "Dear Customer," "Dear User," or just your email address, rather than your actual name
- The email asks for personal information your bank or service provider already holds, such as your password, full card number, or PIN
- Hovering over links reveals a destination URL that does not match the claimed organisation's real website
- There are spelling errors, unusual phrasing, or inconsistent formatting compared to genuine emails from the same sender
- The request to update payment or banking details arrives via email with no preceding phone call or formal documentation
How to Identify
How to identify a phishing email
Ask yourself before acting:
- Did I initiate this contact, or did this email arrive without warning?
- Would this organisation really contact me this way — especially to ask for sensitive information?
- Can I verify this independently by going directly to the website or calling the organisation?
Verification steps:
- Do not click any link in the email. Open your browser and type the organisation's official URL directly.
- Call the organisation using a phone number from their official website — not a number provided in the suspicious email.
- Check the sender's full email address carefully, not just the display name (which can be faked).
- Hover over any links before clicking — the actual destination appears at the bottom of your browser or email client.
- Paste suspicious links into a free checker such as VirusTotal or Google Transparency Report before visiting them.
- Forward suspicious emails to your organisation's IT team or the impersonated company's official fraud reporting address.
Legitimate vs fraudulent — how to tell:
| Legitimate email | Phishing email |
|---|---|
| Addresses you by your full registered name | Uses "Dear Customer," "Dear User," or your email address |
| Links go to the organisation's actual domain | Links go to a lookalike domain or URL shortener |
| Never asks for your password or full card number | Requests credentials, PINs, or payment details |
| Gives you time and multiple ways to respond | Creates urgency and a single action path |
| Matches the formatting and tone of past genuine emails | May have inconsistencies in logo, font, or wording |
How to Protect
How to protect yourself
Preventive habits:
- Enable multi-factor authentication (MFA) on all accounts — even if a scammer obtains your password, they cannot access your account without the second factor
- Use a password manager so every account has a unique, strong password — this limits damage if one credential is stolen
- Never reuse passwords across different sites
- Keep your email client, browser, and operating system updated — patches close known vulnerabilities exploited by phishing malware
- Enable spam and phishing filters in your email settings (Gmail, Outlook, and Apple Mail all offer this)
- Think before you click — pause any time an email prompts you to act immediately
If you have already been targeted:
- Do not click any further links or reply to the message
- Change your password immediately from a clean, unaffected device
- Enable MFA if it is not already active
- Contact your bank or card provider immediately if any financial information was entered
- Report the phishing email to your national cybercrime authority (see further reading below)
- Monitor your accounts and consider placing a fraud alert with a credit bureau
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| Have I Been Pwned | Checks if your email or password has appeared in known data breaches | Free |
| VirusTotal | Scans URLs and files for malware before you open them | Free |
| Google Safe Browsing | Checks if a website is flagged as dangerous | Free |
| Bitwarden / 1Password | Password managers that generate and store unique passwords | Free / Paid |
Video Lesson
Watch: Phishing explained
A clear, accessible walkthrough of how phishing attacks work, the different types of phishing (email, spear, whaling, smishing), and practical steps to protect yourself. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — Report phishing and access the latest cybercrime statistics → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Government guidance on recognising and avoiding phishing → cisa.gov/phishing
- Action Fraud (UK) — Report phishing emails and get advice if you have been targeted → actionfraud.police.uk
Research & reports
- IBM — "Cost of a Data Breach Report 2024" — annual benchmark study on the financial impact of phishing-related breaches → ibm.com/reports/data-breach
- Anti-Phishing Working Group (APWG) — Quarterly phishing activity trends reports with global data → apwg.org
Investigative coverage
- DMARC Report — "A Roundup of the Top Phishing Attacks in 2024" — detailed breakdown of notable real-world cases → dmarcreport.com
Related articles on this platform
- Spear Phishing — targeted phishing using personal details to appear credible
- Smishing (SMS Phishing) — fraudulent text messages with malicious links
- Business Email Compromise (BEC) — phishing that targets payment processes in organisations