Phishing emails used to be fairly easy to spot. Poor spelling, suspicious links, improbable stories about unclaimed inheritances. These days they’re much harder to identify. AI-generated text, convincing branding, and targeted attacks using real information about you and your business have made phishing one of the most effective tools attackers have. Here’s what to look for now.
What’s changed about phishing
The obvious errors that used to give phishing emails away are largely gone. Modern phishing messages are grammatically correct, professionally formatted, and often personalised, referencing your name, your company, or even recent events to make them feel credible.
Spear phishing, attacks targeted at a specific person or business, has become more common. An attacker might research your company online, identify a supplier you use, and send a convincing fake invoice or payment request. These are much harder to catch than a generic mass-email attack.
The signals that still give phishing away
Even sophisticated phishing attempts tend to leave clues. The trick is knowing where to look.
- The sender’s email address doesn’t match the organisation it claims to be from. The display name might say ‘Barclays’ but the actual address is something unrelated.
- The link in the email doesn’t go where it says. Hover over it (without clicking) and check the actual URL that appears.
- The message creates urgency. ‘Your account will be suspended’, ‘Immediate action required’, ‘Payment overdue’, pressure tactics are designed to make you act before you think.
- It asks for login details or sensitive information. Legitimate organisations don’t ask for passwords or payment details via email.
- Something feels slightly off, even if you can’t put your finger on it. Trust that instinct.
Newer tactics to be aware of
QR code phishing has grown significantly. An email with a QR code pointing to a malicious site is harder for email security tools to detect because there’s no obvious link to scan.
Voice phishing (vishing) and SMS phishing (smishing) have also increased. Attackers call or text rather than email, often impersonating banks, HMRC, or IT support. The principles for spotting them are similar, unexpected contact, urgency, requests for sensitive information.
What to do if you’re not sure
If an email asking you to do something feels suspicious, don’t click anything in it. Go directly to the organisation’s website by typing the address yourself, or call them on a number you already have. Never call a number provided in the suspicious email itself.
If someone in your team receives something suspicious, report it to whoever handles your IT. One person flagging something potentially dangerous gives everyone else a chance to avoid the same trap.
Training matters more than any tool
Email security filters catch a lot, but they don’t catch everything. The single most effective thing you can do is make sure your team knows what to look for and feels comfortable raising concerns without embarrassment.
A five-minute conversation about phishing awareness in a team meeting can genuinely reduce your risk more than many technical solutions. We can help you put together simple, practical guidance for your team if it would be useful.



