Phishing Attacks Still Work: How to Spot Them Before You Click

Phishing has been around for over three decades, yet it remains one of the most effective attack methods used by cybercriminals. All it takes is one distracted moment — an urgent email from what looks like a familiar source, a quick click, and an attacker has their foot in the door. From compromised personal bank accounts to breached corporate systems, the consequences can be severe. According to CISA, 90% of cyber attacks begin with a phishing email, and business email compromise (BEC) alone represents a $43 billion problem for organizations.

Phishing attacks are also becoming more difficult to detect. Attackers now have access to AI tools that can generate convincing, error-free messages, and they increasingly target users across multiple communication channels, including Teams, Slack, LinkedIn, and SMS.

The Basics of Phishing and Why It Works

Email phishing is a social engineering technique where attackers use deceptive messages or links to trick victims into surrendering sensitive information or downloading malware. The attacker only needs to succeed once. While general phishing campaigns cast a wide net, spear phishing targets specific individuals with personalized details to increase the chance of success.

High-profile breaches at companies like Reddit, Twilio, and Cloudflare have demonstrated how effective these attacks can be. In some cases, attackers have even compromised an employee's home computer to gain access to corporate networks weeks later. National security agencies, including the UK's NCSC and the White House's National Cybersecurity Strategy, have flagged phishing as a growing threat across sectors.

Red Flags That Signal a Phishing Attempt

Don't click links in unsolicited messages. If you receive an email from your bank or a government agency, go directly to the official website rather than clicking any links in the message. This simple habit eliminates the risk of landing on a look-alike phishing page.

Inspect the sender's email address carefully. Phishing attempts often rely on look-alike domains. Watch for extra or switched letters (like microsogft[.]com), omissions (microsft[.]com), or characters that look similar, such as the letter "o" replaced by zero (micr0soft[.]com).

BLOG-1754 Embedded Image - WJor62

The link appears to point to a legitimate Chase domain, but when clicked, it routes through a SendGrid URL before redirecting to a phishing site impersonating Chase.

Question urgent requests to "unlock" or "update" accounts. Technology services are a top target for phishing because of the sensitive data stored in email, cloud storage, and social media accounts. Hover over links to verify the destination URL before clicking.

Be skeptical of financial messages. Financial institutions are the most impersonated industry in phishing campaigns. Pause before responding to any message asking you to accept or make a payment.

Watch for manufactured urgency. Emails warning of a final chance to pick up a package or confirm an account are classic lures. The rise in online shopping has made retail and logistics companies prime targets for these tactics, often delivered via SMS phishing (smishing).

BLOG-1754 Embedded Image - q7UnNk

If it sounds too good to be true, it is. Limited-time offers for free gifts, exclusive deals, or discounted vacations are designed to override rational thinking. Pause, even briefly, and search online to see whether others have received similar offers.

Beware of authority impersonation. Attackers often mimic high-ranking executives or public figures, requesting urgent money transfers or credential sharing. Scrutinize such requests and verify their authenticity by contacting the person through a known, trusted channel.

Watch for poor grammar, but don't rely solely on it. Spelling and sentence structure errors can signal a phishing attempt, but AI tools now enable attackers to produce convincingly professional messages. Errors are a clue, not a definitive test.

Be cautious of romance scams and "mistaken" emails. Scammers adopt fake online identities to build trust, and they may send unsolicited messages designed to provoke a response and start a conversation, eventually leading to a request for money or information.

Use a password manager. Password managers validate domain names before autofilling credentials. If you land on a look-alike domain, the manager will warn you that the address doesn't match your expected site.

BLOG-1754 Embedded Image - A9tn7Q

This example shows vendor invoice fraud, where a legitimate vendor's email account was hacked and used to send fraudulent payment requests.

Beyond email, attackers also use voice phishing (vishing) over phone calls to impersonate trusted entities like tax authorities or employers. Another technique is the watering hole attack, where hackers compromise websites frequented by employees of target organizations to distribute malware. Calendar phishing, where fake invites are injected into employee calendars through a compromised cloud email account, is another vector seen in the wild.

Building a Safety Net for Human Error

Even well-trained employees can mistake a malicious link for a legitimate one. Email Link Isolation provides a safety net by rewriting and isolating potentially dangerous links in email. When a user clicks a link, the page opens in an isolated browser environment, keeping the user safe from malware. The system also alerts users when a website's legitimacy is uncertain.

For malicious links delivered outside email — through Slack, iMessage, WhatsApp, or other messaging platforms — Zero Trust and Remote Browser Isolation extend similar protections to all web traffic.

Two-factor authentication (2FA) adds another essential layer of defense. Even if an attacker obtains your password, they still cannot access your account without the second factor. However, not all 2FA methods are equal. Codes generated by mobile apps or sent via SMS can also be intercepted by phishing sites or SIM-jacking attacks. Hardware security keys are the safest option because they are tied cryptographically to the genuine site and cannot be used on look-alike domains.

Staying Vigilant Against a Persistent Threat

Phishing remains one of the most exploited attack vectors simply because it targets human nature. Tactics range from mass campaigns impersonating top brands to highly targeted spear phishing, vendor invoice fraud, and new variations that exploit emerging channels. Individual caution, combined with layers of technical protection — from email isolation to phishing-resistant hardware keys — creates the best defense against an attack that has worked for decades and will continue to evolve alongside the tools attackers use to craft it.