Skip to main content

Phishing Emails: The Tells That Still Work in 2026

Media Phishing Emails The Tells That Still Work

 

Phishing emails have become much harder to spot.

The old stereotypes still exist:

terrible spelling

badly copied logos

strange-looking emails

obviously ridiculous stories


But attackers no longer need to rely on those mistakes.

Modern phishing emails can be:

professionally written

correctly branded

personalised

sent from a genuinely compromised account

embedded in an existing email conversation

written or polished using AI


Microsoft’s 2026 threat research shows attackers increasingly favour link-based phishing, QR codes, CAPTCHA-gated pages and credential-stealing infrastructure rather than relying only on obvious malicious attachments.

So the question is no longer:

“Does this email look professional?”

It is:

“Does this request make sense, and can I verify it independently?”

That remains one of the strongest phishing defences available.

What Is Phishing?

Phishing is an attempt to manipulate somebody into doing something that benefits an attacker.

The attacker may want you to:

enter a password

approve an MFA request

scan a QR code

open an attachment

grant access to an application

make a payment

change supplier bank details

install remote-access software

provide confidential information


The National Cyber Security Centre describes phishing as scam emails, messages or calls designed to trick people into visiting malicious websites, revealing information or taking another harmful action.

The Most Important Rule: Judge the Request, Not the Design

A convincing phishing email can have:

the correct Microsoft logo

your company branding

a genuine-looking footer

the sender’s real signature

perfect grammar


Those things are no longer strong proof of authenticity.

Instead ask:

Was I expecting this?

Is this normal for the sender?

Why am I being asked to act now?

What happens if I verify it another way?

Context is increasingly more useful than appearance.

1. The Message Creates Pressure

Urgency remains one of the strongest warning signs.

The NCSC specifically highlights urgency, authority, emotion and scarcity as common psychological techniques used by scammers.

Typical examples include:

Your account will be suspended today

Payment must be made immediately

Your mailbox is full

Your password expires in one hour

Final warning

Review this document now

Your parcel cannot be delivered

This invoice is overdue


Legitimate businesses sometimes send urgent messages.

The warning sign is:

urgency + unusual requested action.

Especially:

urgency + login

or:

urgency + payment

or:

urgency + secrecy.

2. The Request Is Unusual for the Sender

This is more useful than simply asking whether the sender address looks legitimate.

A genuine account can be compromised.

Suppose a supplier you have dealt with for five years suddenly says:

“We've changed bank accounts. Please use these new details immediately.”

The email address may genuinely belong to the supplier.

That still does not make the instruction safe.

Verify unusual requests using another trusted method.

For example:

call the supplier using the telephone number you already have

rather than:

the number provided in the suspicious email.

3. Check the Actual Sender Address

Display names are easy to imitate.

An email application might prominently show:

Microsoft Support

while the actual address belongs to an unrelated domain.

Likewise:

Managing Director

could simply be a display name chosen by the attacker.

Reveal the complete address.

On mobile devices you may need to tap the sender name.

But remember:

a genuine address still does not prove the account has not been compromised.

So sender inspection is useful evidence—not absolute proof.

4. Look Carefully at the Domain

Lookalike domains still work.

For example, attackers may use:

missing letters

additional words

substituted characters

different domain endings

hyphens

subdomains designed to confuse


But do not use a simplistic rule such as:

“If Microsoft appears anywhere in the URL, it's genuine.”

For example:

microsoft.login-security.example

belongs to:

example

not Microsoft.

The important domain is the actual registered domain controlling the destination.

5. Links Still Matter — But They Are Not the Whole Story

A button might say:

View document

Listen to voicemail

Secure account

Track parcel

Open invoice

On a desktop, hover over it without clicking.

Check where it really goes.

Be cautious when:

the destination is unrelated

the domain looks similar but incorrect

the URL is shortened

the destination is an IP address

the link leads to an unexpected login


But modern phishing can also route victims through legitimate services before reaching malicious infrastructure.

So:

familiar-looking URL ≠ automatically safe.

6. A Login Request Should Make You Slow Down

Fake Microsoft 365 login pages remain extremely common.

Instead of following the email link:

1. Open your browser yourself.


2. Use your existing bookmark or official application.


3. Check whether the same request appears there.

 

For example, if an email claims:

“Your Microsoft 365 password expires today.”

do not use its button.

Go directly to your normal Microsoft 365 environment.

This removes the email from the trust chain.

7. QR Codes Are Now a Major Phishing Route

This deserves much more prominence in a 2026 article.

The NCSC specifically warns that attackers increasingly place QR codes inside phishing emails.

Microsoft’s Q1 2026 analysis found QR-code phishing increased from 7.6 million attacks in January to 18.7 million in March, a rise of 146% over the quarter. Around 70% were being delivered through PDFs by March.

A QR code can be used to bypass the normal habit of hovering over a link.

It also moves the victim onto their phone, which may:

have fewer corporate protections

hide the full URL

already have Microsoft credentials signed in


Be especially suspicious of email QR codes claiming:

scan to reauthenticate

scan to view document

scan to prevent password expiry

scan to access voicemail

scan to verify MFA


A QR code in an email should be treated as a link you cannot inspect as easily.

8. The Email May Lead to a Real Microsoft Login Page

This is where traditional “look for the padlock” advice fails badly.

Attackers increasingly abuse legitimate authentication flows.

For example, Microsoft reported a 2026 phishing campaign abusing device code authentication.

A victim could be sent to a genuine Microsoft sign-in page, enter a code supplied by the attacker, complete legitimate MFA—and unknowingly authorise the attacker’s session.

So:

real Microsoft website + genuine MFA prompt ≠ request is automatically legitimate.

Ask:

Why am I entering this device code?

What device am I actually authorising?

If you did not initiate the sign-in yourself, stop.

9. Be Suspicious of Unexpected MFA Prompts

You may receive:

Authenticator approval request

phone notification

verification code

sign-in confirmation


that you did not initiate.

Do not approve it just to make it disappear.

Attackers can use MFA fatigue or social engineering to persuade users to approve fraudulent authentication.

Microsoft’s current guidance increasingly favours phishing-resistant authentication, such as passkeys and FIDO2 security keys, because traditional push, SMS and OTP methods can still be intercepted or socially engineered.

If an unexpected MFA prompt appears:

deny it

and report it according to your organisation’s security process.

10. Watch for OAuth Consent Phishing

This is another area I’d add to the existing article.

Sometimes the attacker does not ask for your password at all.

Instead, they persuade you to approve a malicious cloud application.

You may see an authentic Microsoft permission page asking an app for access to:

email

contacts

files

profile information


Microsoft calls this consent phishing. After consent is granted, the application can gain legitimate access to organisational data.

Be cautious when an unexpected service asks:

Allow this application to access your data?

Especially if you arrived there through an email.

Check:

publisher

requested permissions

why you need the application


A password change may not remove malicious OAuth access because the app itself has been authorised separately.

11. CAPTCHA Does Not Mean the Site Is Legitimate

Attackers increasingly put CAPTCHA pages between the email and the phishing site.

Why?

Because it:

looks reassuring

slows automated scanning

hides the final malicious destination


Microsoft says CAPTCHA-gated phishing grew rapidly during early 2026 as attackers used it to conceal credential-harvesting pages from automated detection.

So if a link from an unexpected email leads to:

“Prove you're human”

that is not evidence the destination is safe.

12. Be Wary of Unexpected Attachments

Dangerous attachments may include:

HTML

ZIP

ISO

script files

Office documents

PDFs containing links or QR codes


Microsoft’s Q1 2026 research found link-based attacks dominated, but malicious payloads remained significant, with HTML and ZIP campaigns particularly prominent at points during the quarter.

Ask:

Was I expecting this file?

Does this sender normally send me this type of attachment?

Can I verify it independently?

A PDF itself is not automatically malicious—but it may simply be the container for:

QR code

credential link

fake invoice

social-engineering instructions


13. Payment and Bank-Detail Changes Need Separate Verification

Business email compromise often aims at money rather than passwords.

Common requests include:

change supplier bank details

pay an urgent invoice

move funds

buy gift cards

keep payment confidential


If payment instructions change:

verify them using a trusted contact method already on record.

Do not verify changed bank details by replying to the same email chain.

If the mailbox itself is compromised, you may simply be asking the attacker whether their fraudulent bank details are correct.

14. Secrecy Is a Strong Warning Sign

Attackers frequently tell employees:

Don't tell anybody yet

I'm in a meeting

This is confidential

Don't involve finance

I need you to handle this personally


The aim is simple:

prevent verification.

A legitimate senior manager should not object to sensible financial controls.

Security procedures should be strongest precisely when somebody claims the request is too urgent or confidential to follow them.

15. A Familiar Conversation Can Still Be Dangerous

A particularly convincing phishing attack can begin inside an existing email thread.

Attackers who compromise a supplier or employee mailbox may read previous conversations and then reply with:

realistic context

genuine signatures

correct invoice references

names of real colleagues


That defeats:

“I recognise the sender.”

Instead ask:

Does the new action make sense?

The change in behaviour is the clue.

16. Don't Rely on Spelling Mistakes

Poor grammar remains a warning sign.

But:

perfect grammar means almost nothing.

The NCSC explicitly says scams have become harder to identify and may fool even experienced people.

AI makes generating polished messages cheap.

So do not teach employees:

“Look for spelling mistakes.”

Teach:

“Look for unexpected pressure, unusual actions and attempts to bypass normal procedures.”

17. “Sent From iPhone” Does Not Prove Anything

Email signatures are just text.

An attacker can copy:

company disclaimer

logo

mobile signature

staff job title

pronouns

office address


in seconds.

Treat the signature as formatting.

Not authentication.

18. Don't Call the Number in the Suspicious Message

Some phishing emails are designed to get you to call the attacker.

Examples include:

Your subscription has renewed for £499 — call immediately to cancel.

or:

Microsoft Security has detected malware — call support now.

If concerned, find the organisation’s contact information independently.

Do not use the suspicious email as your directory.

19. Remote-Access Software Is a Major Red Flag

Be particularly cautious if somebody claiming to be:

Microsoft

your bank

your ISP

antivirus support


asks you to install remote-access software.

Examples might include legitimate remote administration products.

The software itself may not be malicious.

The problem is who you are giving control to.

Never grant remote access because of an unsolicited email or phone call.

The Best Verification Habit

For suspicious messages:

break the communication channel.

Do not:

reply

click

call its number

use its QR code


Instead verify independently.

Examples:

“CEO needs urgent payment”

Call or speak to the CEO.

“Microsoft account problem”

Open Microsoft 365 directly.

“Supplier changed bank details”

Call the known supplier contact.

“Bank security alert”

Use the official banking app or known number.

This single habit defeats a surprisingly large number of phishing attacks.

What If You Already Clicked?

The NCSC says that if you merely opened a suspicious link but did not enter information, download anything or install software, further action may not always be necessary—though you should remain alert.

If you:

entered a password

approved MFA

installed software

supplied financial information


act quickly.

For a work device:

contact IT immediately.

Do not wait to see whether anything happens.

If You Entered Your Password

Take actions such as:

change the password using a trusted device

change it anywhere else it was reused

revoke suspicious sessions

review MFA methods

check mailbox forwarding/rules

alert IT


If an attacker used an adversary-in-the-middle phishing page, simply changing the password may not immediately invalidate every stolen session token, so administrators may need to revoke sessions and investigate the account. Microsoft continues to report AiTM campaigns that capture authentication tokens even after users complete MFA.

If You Approved an Unexpected App

Tell IT that you may have granted application consent, not merely leaked a password.

That wording matters.

An administrator may need to investigate:

Enterprise Applications

OAuth permissions

consent grants

Microsoft Defender alerts


Microsoft specifically notes that ordinary password resets or MFA changes do not necessarily remediate illicit consent grants because the external application itself has been authorised.

Report the Email

For UK users, suspicious emails can be forwarded to the NCSC’s Suspicious Email Reporting Service.

As of July 2026, the NCSC says it has received more than 58 million reports, leading to more than 256,000 scams being removed across around 454,800 URLs.

Inside a business, also use:

Outlook Report Phishing

your security-reporting tool

IT helpdesk


Reporting helps protect other employees from receiving or acting on the same campaign.

Technology Still Matters

Training is one layer.

Businesses should also use technical controls.

Depending on licensing and risk, these may include:

Microsoft Defender for Office 365

anti-phishing policies

Safe Links

Safe Attachments

impersonation protection

Conditional Access

phishing-resistant MFA

OAuth app controls

endpoint protection


Microsoft’s 2026 security guidance increasingly recommends phishing-resistant authentication such as passkeys/FIDO2 because attackers are successfully bypassing traditional phishable MFA techniques.

The 10-Second Phishing Check

Before acting on an unexpected email, ask:

1. Was I expecting this?


2. Is the requested action normal?


3. Is someone pressuring me?


4. Am I being asked to log in, approve MFA, scan a QR code or grant permissions?


5. Can I verify it independently?

 

If the request involves:

money, passwords, MFA, application permissions or remote access

verification should be automatic.

How Hamilton Group Can Help

Hamilton Group can help businesses reduce phishing risk through a combination of technology, processes and employee awareness.

We can assist with:

phishing protection

Microsoft Defender for Office 365

Microsoft 365 security

MFA and passkeys

Conditional Access

email-security configuration

security awareness training

business email compromise

compromised-account investigations

cyber-security monitoring and response


The objective is not to train employees to become forensic email analysts.

It is to give them a simple habit:

when an email asks for something unusual, sensitive or urgent, verify the request outside the email before acting.

Visit hgmssp.com or call 0330 043 0069 to discuss email and cyber security.