Seven phishing emails your team will actually receive, what makes each one work, and the two habits that catch them all.
Phishing emails are built to make you act before you think. Most impersonate a brand or a colleague you deal with routinely, because familiarity is what lowers your guard. With AI-generated phishing, the old giveaways — broken English, clumsy formatting, generic greetings — are largely gone, so recognising the pattern matters more than spotting a mistake.
Here are the seven that actually land, and why each works.
The seven you will see
1. The password expiry. "Your account password expires today. Reset it now to avoid losing access." The hook is urgency, and the payoff is a login page that looks exactly right. This is credential harvesting, the most common phishing goal of all.
2. The failed delivery. "We could not deliver your package. Confirm your address." The hook is that it is probably true — most people are waiting on something. Volume does the work; the attacker does not need to know anything about you.
3. The unpaid invoice. "Please find the attached invoice, now overdue." The hook is worry about owing money, and the attachment carries the payload. Finance teams see this constantly, which is precisely the problem.
4. The shared document. "A file has been shared with you." A notification mimicking a cloud storage or collaboration service, leading to a fake sign-in page. It works because these notifications are genuinely constant, and nobody reads them carefully.
5. The payroll change. "Update your bank details before Friday's payroll run." The hook is a deadline attached to your own money. Aimed at employees, or at HR, where one successful change redirects someone's salary.
6. The urgent request from a senior figure. "Are you at your desk? I need something handled discreetly." Short, plausible, and asking nothing suspicious yet — the real request comes once you reply. This is CEO fraud, and the opening message is deliberately harmless so it passes every filter.
7. The unexpected approval prompt. A message, often paired with real push notifications, asking you to approve a login you did not start. The hook is fatigue: approve it and the attacker is inside an account protected by multi-factor authentication.
What they have in common
Strip the branding away and nearly every phishing email does three things.
It creates time pressure — today, within two hours, before Friday. Urgency is not a communication style legitimate organisations use for routine admin; it exists to shorten the gap between reading and clicking.
It makes a request that bypasses normal process — a payment, a credential, a bank detail change, an approval — arriving by email rather than through whatever system normally handles it.
And it relies on context you cannot immediately verify. An invoice you might genuinely owe. A delivery you might genuinely expect. The attacker does not need to be right, only plausible.
The golden rule
If an email asks you to follow a link and then enter a password, treat it as hostile until proven otherwise. Legitimate organisations do not ask for credentials through a link in an email. That single rule catches examples one, four and, indirectly, seven.
The second rule covers the rest: any request involving money or account changes gets verified on another channel — a phone call to a number you already have, never the number or link in the message.
If something feels off
- Do not click. Hover the link and read where it actually goes. On a phone, long-press to preview rather than tapping.
- Report it. Use your reporting tool or forward it to security. Reporting is what protects the colleagues who received the same message.
- Do not reply. A reply confirms your address is live and monitored, which guarantees more attempts.
- Delete it once reported.
Getting it wrong occasionally is normal — these are designed by people who do this full time. What matters is reporting quickly, because time to report is what decides whether a real campaign gets contained.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
Quick Guide: Human Risk Management
What human risk management is, how it differs from annual awareness training, what it measures, and where it goes wrong.
What Is Social Engineering?
How social engineering manipulates normal human behaviour to bypass security, the forms it takes, and how to build a verify-first culture.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.