For years, the standard advice was “look for bad spelling and dodgy grammar.” That advice is now obsolete. Modern phishing emails are fluent, well-formatted, personalised with details scraped from your website and LinkedIn, and increasingly written with AI assistance. The tells have changed — and so must the way your team evaluates email.
What modern phishing looks like
Business email compromise (BEC). An email appearing to come from a director or the finance manager, asking for an urgent payment or a change to supplier banking details. Often sent from a lookalike domain one character off the real one, or from a genuinely compromised mailbox inside a supplier’s business.
Invoice and banking-detail fraud. Criminals sit quietly inside a compromised email account, watch real invoice conversations, then insert themselves at the perfect moment with “updated banking details.” The invoice is real; only the account number has changed.
Credential harvesting. “Your mailbox is full”, “a document has been shared with you”, “verify your account” — all leading to a pixel-perfect fake login page. Increasingly these pages proxy the real service, capturing MFA codes in real time.
QR code and SMS phishing. Attackers push the click onto your phone — where you can’t hover over a link and where security filtering is weaker.
The signals that still work
- Urgency plus secrecy. “Handle this now, don’t discuss with anyone” is the fingerprint of BEC. Legitimate business rarely needs both speed and silence.
- Any change to payment details. Treat every banking-detail change as fraudulent until verified by phone, using a number you already have — never one in the email.
- The actual sending address and domain. Display names are trivially faked. Check the real address, character by character — rn masquerading as m is a classic.
- Login pages reached via email links. If an email asks you to sign in, go to the site directly through your browser instead. Legitimate services survive this detour; fakes don’t.
- Unexpected context. A supplier who has never emailed an invoice suddenly sending one; a director emailing at midnight about gift cards. Trust the “this feels off” instinct — it’s usually right.
Process beats vigilance
You cannot proofread your way to safety anymore. What works is fixed process: verbal verification for all payment changes and unusual payment requests, no exceptions — including for the MD. Dual approval on payments above a threshold. A no-blame culture where reporting a suspicious email (or a clicked link) is praised, because fast reporting is what limits damage.
Technical backstops
Email filtering, SPF/DKIM/DMARC on your domain to prevent spoofing, MFA on every mailbox, and endpoint protection to catch what slips through. None of these replace the human process above — they buy it time.
We deploy layered email security and run practical awareness guidance for teams as part of our managed IT service. If you’re not sure how exposed your mail setup is, ask us for a quick assessment.
