
Phishing email examples are most useful when they match what employees actually receive. These six lures are landing in corporate inboxes now, each with the tell that gives it away and the control that stops it. If you are building an awareness program, they double as a scenario list.
Key takeaways
- Corporate phishing relies on context and process abuse, not spelling mistakes or odd greetings.
- Vendor bank changes and IT support follow-ups often carry no link and no attachment, so email gateways have nothing to inspect.
- Two signals survive generative tools: manufactured urgency and a request to bypass a process.
Phishing emails are a common cyber threat that can lead to serious consequences, such as data theft and financial loss. Cybercriminals craft these emails to deceive recipients into clicking on malicious links or providing sensitive information. Understanding various phishing email examples can help you identify and avoid potential threats. At Arsen, we provide next-generation awareness training to equip employees with the knowledge to spot these scams. Here are some examples of phishing emails and tips on how to prevent falling victim.
1. The "Unusual Activity Detected" Scam
Example
You receive an email claiming to be from a well-known service, such as your cloud storage provider. The subject line reads: "Unusual Activity Detected on Your Account." The email states that there have been multiple failed login attempts and urges you to "secure your account" by clicking a link to verify your identity.
The link leads to a website that looks nearly identical to the provider’s legitimate login page, prompting you to enter your username and password. Once you input your credentials, they are sent directly to the attacker.
The corporate version is worse. The same lure branded as Microsoft 365 or Okta, delivered to an employee, and hosted on an adversary-in-the-middle proxy. The victim's password and one-time code are both captured, the session cookie is stolen, and multi-factor authentication is never triggered again because authentication already succeeded.
Prevention Tips
Verify the Source: Before clicking on any link, verify the sender's address. Official companies use standard domain addresses (e.g., "@serviceprovider.com"). If the sender’s address appears suspicious or contains slight misspellings, do not engage with the email.
Access Accounts Directly: Never click on links in unsolicited emails. Instead, visit the website by typing the URL directly into your browser and logging in through the official site to check for any account issues.
2. The "Invoice Attached" Scam
Example
You receive an email from an unknown sender with the subject line "Invoice for Payment." The message claims to be a follow-up on a previous transaction and includes an attachment labeled "Invoice_1234.pdf." The sender urges you to open the attachment to view payment details.
If you open the attachment, it may contain malware that infects your device, allowing the attacker to access personal files, monitor your activity, or steal sensitive information.
Prevention Tips
Be Wary of Unexpected Attachments: Do not open attachments from unfamiliar senders or unexpected emails. Even if the sender appears to be known, verify the legitimacy of the message by contacting them through a different communication channel.
Use Anti-Malware Software: Ensure your device has updated antivirus software to detect and block malicious attachments. Most modern antivirus solutions can scan attachments for potential threats.
3. The "Security Alert" Email
Example
A phishing email arrives with the subject line: "Security Alert: Suspicious Login Detected." The message appears to be from your email provider and claims that someone has accessed your account from an unknown device. It urges you to click a link to "review the login attempt."
The link leads to a fake login page designed to capture your credentials. By logging in, you inadvertently give the attacker access to your email account, which can be used to reset passwords for other online services.
Prevention Tips
Hover Over Links: Before clicking any link, hover over it to reveal its destination. If the URL looks suspicious or does not match the official website of the company, do not click.
Enable Multi-Factor Authentication (MFA): MFA adds an extra layer of security to your accounts. Even if an attacker obtains your password through phishing, they will need the second authentication factor (e.g., a code sent to your phone) to access your account.
Worth stating the limit: MFA is enforced at login. It does not stop an attacker replaying a stolen session cookie, and it does not stop MFA fatigue. It raises the cost of an attack rather than closing the channel.
4. The vendor bank detail change
Example
An email arrives in accounts payable from a supplier you genuinely work with, referencing a real invoice number and an ongoing project. It announces that the company has changed banking provider and gives new account details for the next payment. The tone is routine and the timing matches a payment cycle.
There is often no link and no attachment, which means nothing for a gateway to catch. The attacker has usually been reading the mailbox of a compromised supplier contact for weeks, which is how the invoice numbers and the project references are correct. This is spear phishing at its most patient.
Prevention Tips
Callback on a number you already hold. Any change of bank details is verified by calling the supplier on the number in your records, never the one in the email signature. This single control defeats the whole category.
Dual authorization on payment detail changes. Treat a bank change as a change to a master record, not as correspondence.
5. The IT support follow-up
Example
An employee receives a call from someone presenting as internal IT, reporting a sync problem with their account. The caller is friendly, knows the employee's manager and their department, and says they will send a verification link to complete the fix. The email then arrives, and it is expected.
This is the pattern that matters most, because the email is not the attack. The call is. By the time the message lands, the recipient has been told to expect it, and every instinct trained by awareness programs has been disarmed by a human voice. Google attributes 23% of cloud compromises to voice phishing calls, and CrowdStrike recorded a 134% rise in vishing intrusions between 2024 and 2025.
Prevention Tips
Treat expectation as a warning sign, not a reassurance. An email you were told to expect by an unsolicited caller is more suspicious, not less.
Unsolicited calls claiming to be IT get called back through the service desk. Make it policy rather than judgment.
6. The ClickFix or QR lure
Example
A message asks the recipient to complete a verification step: press Windows key and R, paste a string, press Enter. Or it presents a QR code to scan "to authenticate on mobile". In both cases the user performs the compromise themselves.
Neither carries a malicious attachment or a link for a gateway to rewrite. Microsoft now reports ClickFix lures as the leading initial access technique at 47%, ahead of phishing at 35%. The QR variant moves the payload onto a personal phone, outside every managed control.
Prevention Tips
No legitimate verification asks a user to run a command. Make this an absolute rule; it has no exceptions.
Never scan a work QR code with a personal device. If the resource is legitimate there is a way to reach it on the managed machine.
What the six examples have in common
None of the corporate examples depends on bad spelling, a strange greeting or an obviously wrong domain, which is what most awareness training teaches people to look for. Generative tools removed those tells first.
Two signals survive, and they are behavioral rather than linguistic:
Manufactured urgency. A deadline that prevents verification is the mechanism, not a side effect.
A request to bypass a process. Skip the approval, use these new details, run this command, authenticate on your phone instead.
Teach those two and the examples stop mattering individually.
Final Thoughts
Phishing emails can take many forms, from security alerts and fake invoices to vendor bank changes and ClickFix lures. Recognizing these phishing email examples and understanding their tactics is crucial for protecting your information. By verifying the source, avoiding unexpected attachments, and using multi-factor authentication, you can significantly reduce the risk of falling victim.
At Arsen, we provide advanced training to help employees identify phishing attempts and implement best practices to secure their communications.
Frequently Asked Questions
-
Credential harvesting disguised as an account security alert, usually branded as a service the recipient uses daily. In a corporate setting the invoice and vendor bank change variants cause the largest direct losses, because they move money rather than credentials.
-
Check the sending domain rather than the display name, and treat two things as signals in themselves: urgency that prevents verification, and any request to bypass an established process. Spelling and grammar are no longer reliable tells.
-
Routinely. Gateways filter against known indicators, and a lure generated for one campaign has none. Messages with no link and no attachment, such as a vendor bank change, give a gateway nothing to inspect at all.
-
With simulations using these exact lures, sent to the populations that receive them, followed by immediate coaching. Measure susceptibility rate, reporting rate and mean time to report rather than completion.
You have the examples. Now find out who clicks them.
Reading a lure and receiving one produce very different responses. Run these six against your own teams and get your susceptibility and reporting rates as a baseline with phishing simulation.