How to Spot and Report Phishing Emails

Apr 28, 2025 | Featured, Risk, Security

Phishing emails are among the most common cyber threats today. Designed to trick recipients into giving up sensitive information or downloading malware, they account for over 90% of successful cyberattacks. These emails exploit human behavior rather than technical flaws—making awareness your best defense.

This guide covers real phishing email examples, how to recognize common red flags, and what steps to take when you encounter one.

What Is Phishing?

Phishing is a form of cyberattack where scammers pose as trusted sources to:

  • Steal login credentials or financial information

  • Install malware via links or attachments

  • Trick users into transferring money or data

While email is the most common medium, phishing now also includes text (smishing) and voice calls (vishing).

Common Phishing Email Examples

1. Fake Account Alerts (e.g., PayPal)

Example:

From: security@paypa1.com
Subject: Your account is limited – verify now

“We detected suspicious activity. Click here to verify or risk suspension.”

Red Flags:

  • Misspelled domain

  • Generic greeting

  • Threats and urgency

  • Suspicious links

2. Fake Delivery Notices

Example:

From: delivery@fedex-alert.com
“We couldn’t deliver your package. Download the form to reschedule.”

Red Flags:

  • Fake domain

  • Vague package details

  • Malicious attachment

3. Tech Support Scams

Example:

From: microsoft365@secure-outlook.com
“Your account was accessed from an unknown device. Act now.”

Red Flags:

  • Suspicious sender

  • Urgent language

  • Link to non-Microsoft domain

4. Fake Shared Documents

Example:

From: noreply@googledoc-share.com
“A file has been shared with you. Sign in to view.”

Red Flags:

  • Spoofed domain

  • Vague content

  • Fake login page

5. HR or Executive Impersonation

Example:

From: jennifer.smith@benefits-update.com
“Urgent: Review changes to your healthcare plan.”

Red Flags:

  • Non-company domain

  • Impersonated internal contact

  • Urgency to log in

How to Spot a Phishing Email

Check for these common warning signs:

1. Sender’s Address

  • Look past the display name

  • Watch for slight domain changes or unusual suffixes

2. Generic Greetings

  • “Dear Customer” instead of your actual name

  • Misspelled names or strange formality

3. Suspicious Links/Attachments

  • Hover to preview URLs before clicking

  • Watch for shortened links or unexpected file formats (.exe, .zip, .doc with macros)

4. Urgency or Pressure

  • Threats (“Act now or lose access”)

  • Limited-time offers or scare tactics

5. Poor Formatting or Grammar

  • Spelling errors

  • Odd layouts, inconsistent fonts, or broken logos

How to Report Phishing

1. Internal Reporting

  • Forward the email to your IT/security team

  • Use your company’s reporting tools

2. Email Providers

  • Gmail: Click the three-dot menu > “Report phishing”

  • Outlook: Right-click > “Mark as phishing”

3. Authorities

  • Forward to reportphishing@apwg.org

  • Report to the FTC at reportfraud.ftc.gov

  • Notify the impersonated brand via their website

4. If You Clicked or Responded

  • Change your passwords immediately

  • Enable two-factor authentication

  • Monitor financial and email accounts

  • Alert your bank if financial data was shared

Advanced Phishing Tactics

As awareness increases, attackers are getting smarter. Be on alert for:

  • Spear Phishing: Personalized attacks using real data

  • Business Email Compromise (BEC): Impersonating executives to request wire transfers

  • Clone Phishing: Copying real emails and inserting malicious content

  • Multi-Channel Attacks: Email scams followed by phone calls to build credibility

Conclusion

Phishing emails are evolving, but so can your defenses. By understanding the signs, you can avoid being tricked and help others do the same.

Stay safe by remembering:

  • Verify the sender before acting

  • Don’t click unfamiliar links or attachments

  • Report suspicious emails to your team and authorities

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more