Phishing Emails: The Tells That Still Work in 2026
Phishing emails have become much harder to spot.
The old stereotypes still exist:
terrible spelling
badly copied logos
strange-looking emails
obviously ridiculous stories
But attackers no longer need to rely on those mistakes.
Modern phishing emails can be:
professionally written
correctly branded
personalised
sent from a genuinely compromised account
embedded in an existing email conversation
written or polished using AI
Microsoft’s 2026 threat research shows attackers increasingly favour link-based phishing, QR codes, CAPTCHA-gated pages and credential-stealing infrastructure rather than relying only on obvious malicious attachments.
So the question is no longer:
“Does this email look professional?”
It is:
“Does this request make sense, and can I verify it independently?”
That remains one of the strongest phishing defences available.
What Is Phishing?
Phishing is an attempt to manipulate somebody into doing something that benefits an attacker.
The attacker may want you to:
enter a password
approve an MFA request
scan a QR code
open an attachment
grant access to an application
make a payment
change supplier bank details
install remote-access software
provide confidential information
The National Cyber Security Centre describes phishing as scam emails, messages or calls designed to trick people into visiting malicious websites, revealing information or taking another harmful action.
The Most Important Rule: Judge the Request, Not the Design
A convincing phishing email can have:
the correct Microsoft logo
your company branding
a genuine-looking footer
the sender’s real signature
perfect grammar
Those things are no longer strong proof of authenticity.
Instead ask:
Was I expecting this?
Is this normal for the sender?
Why am I being asked to act now?
What happens if I verify it another way?
Context is increasingly more useful than appearance.
1. The Message Creates Pressure
Urgency remains one of the strongest warning signs.
The NCSC specifically highlights urgency, authority, emotion and scarcity as common psychological techniques used by scammers.
Typical examples include:
Your account will be suspended today
Payment must be made immediately
Your mailbox is full
Your password expires in one hour
Final warning
Review this document now
Your parcel cannot be delivered
This invoice is overdue
Legitimate businesses sometimes send urgent messages.
The warning sign is:
urgency + unusual requested action.
Especially:
urgency + login
or:
urgency + payment
or:
urgency + secrecy.
2. The Request Is Unusual for the Sender
This is more useful than simply asking whether the sender address looks legitimate.
A genuine account can be compromised.
Suppose a supplier you have dealt with for five years suddenly says:
“We've changed bank accounts. Please use these new details immediately.”
The email address may genuinely belong to the supplier.
That still does not make the instruction safe.
Verify unusual requests using another trusted method.
For example:
call the supplier using the telephone number you already have
rather than:
the number provided in the suspicious email.
3. Check the Actual Sender Address
Display names are easy to imitate.
An email application might prominently show:
Microsoft Support
while the actual address belongs to an unrelated domain.
Likewise:
Managing Director
could simply be a display name chosen by the attacker.
Reveal the complete address.
On mobile devices you may need to tap the sender name.
But remember:
a genuine address still does not prove the account has not been compromised.
So sender inspection is useful evidence—not absolute proof.
4. Look Carefully at the Domain
Lookalike domains still work.
For example, attackers may use:
missing letters
additional words
substituted characters
different domain endings
hyphens
subdomains designed to confuse
But do not use a simplistic rule such as:
“If Microsoft appears anywhere in the URL, it's genuine.”
For example:
microsoft.login-security.example
belongs to:
example
not Microsoft.
The important domain is the actual registered domain controlling the destination.
5. Links Still Matter — But They Are Not the Whole Story
A button might say:
View document
Listen to voicemail
Secure account
Track parcel
Open invoice
On a desktop, hover over it without clicking.
Check where it really goes.
Be cautious when:
the destination is unrelated
the domain looks similar but incorrect
the URL is shortened
the destination is an IP address
the link leads to an unexpected login
But modern phishing can also route victims through legitimate services before reaching malicious infrastructure.
So:
familiar-looking URL ≠ automatically safe.
6. A Login Request Should Make You Slow Down
Fake Microsoft 365 login pages remain extremely common.
Instead of following the email link:
1. Open your browser yourself.
2. Use your existing bookmark or official application.
3. Check whether the same request appears there.
For example, if an email claims:
“Your Microsoft 365 password expires today.”
do not use its button.
Go directly to your normal Microsoft 365 environment.
This removes the email from the trust chain.
7. QR Codes Are Now a Major Phishing Route
This deserves much more prominence in a 2026 article.
The NCSC specifically warns that attackers increasingly place QR codes inside phishing emails.
Microsoft’s Q1 2026 analysis found QR-code phishing increased from 7.6 million attacks in January to 18.7 million in March, a rise of 146% over the quarter. Around 70% were being delivered through PDFs by March.
A QR code can be used to bypass the normal habit of hovering over a link.
It also moves the victim onto their phone, which may:
have fewer corporate protections
hide the full URL
already have Microsoft credentials signed in
Be especially suspicious of email QR codes claiming:
scan to reauthenticate
scan to view document
scan to prevent password expiry
scan to access voicemail
scan to verify MFA
A QR code in an email should be treated as a link you cannot inspect as easily.
8. The Email May Lead to a Real Microsoft Login Page
This is where traditional “look for the padlock” advice fails badly.
Attackers increasingly abuse legitimate authentication flows.
For example, Microsoft reported a 2026 phishing campaign abusing device code authentication.
A victim could be sent to a genuine Microsoft sign-in page, enter a code supplied by the attacker, complete legitimate MFA—and unknowingly authorise the attacker’s session.
So:
real Microsoft website + genuine MFA prompt ≠ request is automatically legitimate.
Ask:
Why am I entering this device code?
What device am I actually authorising?
If you did not initiate the sign-in yourself, stop.
9. Be Suspicious of Unexpected MFA Prompts
You may receive:
Authenticator approval request
phone notification
verification code
sign-in confirmation
that you did not initiate.
Do not approve it just to make it disappear.
Attackers can use MFA fatigue or social engineering to persuade users to approve fraudulent authentication.
Microsoft’s current guidance increasingly favours phishing-resistant authentication, such as passkeys and FIDO2 security keys, because traditional push, SMS and OTP methods can still be intercepted or socially engineered.
If an unexpected MFA prompt appears:
deny it
and report it according to your organisation’s security process.
10. Watch for OAuth Consent Phishing
This is another area I’d add to the existing article.
Sometimes the attacker does not ask for your password at all.
Instead, they persuade you to approve a malicious cloud application.
You may see an authentic Microsoft permission page asking an app for access to:
contacts
files
profile information
Microsoft calls this consent phishing. After consent is granted, the application can gain legitimate access to organisational data.
Be cautious when an unexpected service asks:
Allow this application to access your data?
Especially if you arrived there through an email.
Check:
publisher
requested permissions
why you need the application
A password change may not remove malicious OAuth access because the app itself has been authorised separately.
11. CAPTCHA Does Not Mean the Site Is Legitimate
Attackers increasingly put CAPTCHA pages between the email and the phishing site.
Why?
Because it:
looks reassuring
slows automated scanning
hides the final malicious destination
Microsoft says CAPTCHA-gated phishing grew rapidly during early 2026 as attackers used it to conceal credential-harvesting pages from automated detection.
So if a link from an unexpected email leads to:
“Prove you're human”
that is not evidence the destination is safe.
12. Be Wary of Unexpected Attachments
Dangerous attachments may include:
HTML
ZIP
ISO
script files
Office documents
PDFs containing links or QR codes
Microsoft’s Q1 2026 research found link-based attacks dominated, but malicious payloads remained significant, with HTML and ZIP campaigns particularly prominent at points during the quarter.
Ask:
Was I expecting this file?
Does this sender normally send me this type of attachment?
Can I verify it independently?
A PDF itself is not automatically malicious—but it may simply be the container for:
QR code
credential link
fake invoice
social-engineering instructions
13. Payment and Bank-Detail Changes Need Separate Verification
Business email compromise often aims at money rather than passwords.
Common requests include:
change supplier bank details
pay an urgent invoice
move funds
buy gift cards
keep payment confidential
If payment instructions change:
verify them using a trusted contact method already on record.
Do not verify changed bank details by replying to the same email chain.
If the mailbox itself is compromised, you may simply be asking the attacker whether their fraudulent bank details are correct.
14. Secrecy Is a Strong Warning Sign
Attackers frequently tell employees:
Don't tell anybody yet
I'm in a meeting
This is confidential
Don't involve finance
I need you to handle this personally
The aim is simple:
prevent verification.
A legitimate senior manager should not object to sensible financial controls.
Security procedures should be strongest precisely when somebody claims the request is too urgent or confidential to follow them.
15. A Familiar Conversation Can Still Be Dangerous
A particularly convincing phishing attack can begin inside an existing email thread.
Attackers who compromise a supplier or employee mailbox may read previous conversations and then reply with:
realistic context
genuine signatures
correct invoice references
names of real colleagues
That defeats:
“I recognise the sender.”
Instead ask:
Does the new action make sense?
The change in behaviour is the clue.
16. Don't Rely on Spelling Mistakes
Poor grammar remains a warning sign.
But:
perfect grammar means almost nothing.
The NCSC explicitly says scams have become harder to identify and may fool even experienced people.
AI makes generating polished messages cheap.
So do not teach employees:
“Look for spelling mistakes.”
Teach:
“Look for unexpected pressure, unusual actions and attempts to bypass normal procedures.”
17. “Sent From iPhone” Does Not Prove Anything
Email signatures are just text.
An attacker can copy:
company disclaimer
logo
mobile signature
staff job title
pronouns
office address
in seconds.
Treat the signature as formatting.
Not authentication.
18. Don't Call the Number in the Suspicious Message
Some phishing emails are designed to get you to call the attacker.
Examples include:
Your subscription has renewed for £499 — call immediately to cancel.
or:
Microsoft Security has detected malware — call support now.
If concerned, find the organisation’s contact information independently.
Do not use the suspicious email as your directory.
19. Remote-Access Software Is a Major Red Flag
Be particularly cautious if somebody claiming to be:
Microsoft
your bank
your ISP
antivirus support
asks you to install remote-access software.
Examples might include legitimate remote administration products.
The software itself may not be malicious.
The problem is who you are giving control to.
Never grant remote access because of an unsolicited email or phone call.
The Best Verification Habit
For suspicious messages:
break the communication channel.
Do not:
reply
click
call its number
use its QR code
Instead verify independently.
Examples:
“CEO needs urgent payment”
Call or speak to the CEO.
“Microsoft account problem”
Open Microsoft 365 directly.
“Supplier changed bank details”
Call the known supplier contact.
“Bank security alert”
Use the official banking app or known number.
This single habit defeats a surprisingly large number of phishing attacks.
What If You Already Clicked?
The NCSC says that if you merely opened a suspicious link but did not enter information, download anything or install software, further action may not always be necessary—though you should remain alert.
If you:
entered a password
approved MFA
installed software
supplied financial information
act quickly.
For a work device:
contact IT immediately.
Do not wait to see whether anything happens.
If You Entered Your Password
Take actions such as:
change the password using a trusted device
change it anywhere else it was reused
revoke suspicious sessions
review MFA methods
check mailbox forwarding/rules
alert IT
If an attacker used an adversary-in-the-middle phishing page, simply changing the password may not immediately invalidate every stolen session token, so administrators may need to revoke sessions and investigate the account. Microsoft continues to report AiTM campaigns that capture authentication tokens even after users complete MFA.
If You Approved an Unexpected App
Tell IT that you may have granted application consent, not merely leaked a password.
That wording matters.
An administrator may need to investigate:
Enterprise Applications
OAuth permissions
consent grants
Microsoft Defender alerts
Microsoft specifically notes that ordinary password resets or MFA changes do not necessarily remediate illicit consent grants because the external application itself has been authorised.
Report the Email
For UK users, suspicious emails can be forwarded to the NCSC’s Suspicious Email Reporting Service.
As of July 2026, the NCSC says it has received more than 58 million reports, leading to more than 256,000 scams being removed across around 454,800 URLs.
Inside a business, also use:
Outlook Report Phishing
your security-reporting tool
IT helpdesk
Reporting helps protect other employees from receiving or acting on the same campaign.
Technology Still Matters
Training is one layer.
Businesses should also use technical controls.
Depending on licensing and risk, these may include:
Microsoft Defender for Office 365
anti-phishing policies
Safe Links
Safe Attachments
impersonation protection
Conditional Access
phishing-resistant MFA
OAuth app controls
endpoint protection
Microsoft’s 2026 security guidance increasingly recommends phishing-resistant authentication such as passkeys/FIDO2 because attackers are successfully bypassing traditional phishable MFA techniques.
The 10-Second Phishing Check
Before acting on an unexpected email, ask:
1. Was I expecting this?
2. Is the requested action normal?
3. Is someone pressuring me?
4. Am I being asked to log in, approve MFA, scan a QR code or grant permissions?
5. Can I verify it independently?
If the request involves:
money, passwords, MFA, application permissions or remote access
verification should be automatic.
How Hamilton Group Can Help
Hamilton Group can help businesses reduce phishing risk through a combination of technology, processes and employee awareness.
We can assist with:
phishing protection
Microsoft Defender for Office 365
Microsoft 365 security
MFA and passkeys
Conditional Access
email-security configuration
security awareness training
business email compromise
compromised-account investigations
cyber-security monitoring and response
The objective is not to train employees to become forensic email analysts.
It is to give them a simple habit:
when an email asks for something unusual, sensitive or urgent, verify the request outside the email before acting.
Visit hgmssp.com or call 0330 043 0069 to discuss email and cyber security.