Real Examples of Phishing Emails and How to Spot Them

Phishing emails are designed to trick employees into clicking malicious links, opening attachments or sharing sensitive information, often by impersonating trusted organisations or colleagues. By recognising warning signs, verifying unexpected requests and providing regular staff training, businesses can significantly reduce the risk of falling victim to phishing attacks.
Contents

Real Examples of Phishing Emails and How to Spot Them

Phishing emails remain one of the most common cybersecurity threats facing businesses. They’re designed to look legitimate, often appearing to come from a trusted company, colleague or supplier, but a closer look can reveal warning signs that give them away.

At Edmondson's, we help businesses understand the risks of phishing and how to recognise suspicious messages before they result in stolen passwords, compromised accounts or malware infections.

What Does a Phishing Email Look Like?

Phishing emails can take many forms, but they usually have the same goal, convincing you to take an action that benefits the attacker.

This could involve clicking a link, opening an attachment, entering your login details or transferring money. Some emails are poorly written and easy to identify, while others can look remarkably convincing.

Here are some common examples and the warning signs to look out for.

1. A Fake Microsoft 365 Password Alert

You might receive an email claiming that your Microsoft 365 password is about to expire or that suspicious activity has been detected on your account.

The message may include a button such as "Verify Account" or "Keep My Account Active", taking you to a fake login page designed to steal your credentials.

Warning signs

Check the sender's email address carefully. It may look similar to a genuine Microsoft address but contain additional words, unusual characters or a completely different domain.

You should also avoid clicking the link in the email. Instead, access Microsoft 365 directly through your normal login method and check whether there’s actually a problem with your account.

2. A Fake Invoice From a Supplier

Another common phishing tactic involves an email that appears to come from a supplier or business you regularly work with.

The email might say that an invoice is attached or that payment details have changed. The attacker is hoping you'll open a malicious attachment or transfer money to a fraudulent account.

Warning signs

Unexpected invoices should always be treated with caution, particularly if the payment details have changed.

If you're unsure, contact the supplier using a phone number or email address you already have on file. Don't use contact details provided in the suspicious message.

3. A Fake Delivery Notification

Phishing emails aren't always focused on business accounts. You may receive a message claiming that a parcel couldn't be delivered or that additional information is required.

These emails often create urgency by suggesting your delivery will be returned unless you click a link and provide information or make a small payment.

Warning signs

Look for unexpected requests for payment, unusual website addresses and messages that don't relate to anything you've ordered.

If you're expecting a delivery, visit the courier's official website directly rather than following the link in the email.

4. A Message From Your "Manager"

Some phishing attacks are designed to impersonate people within your own business.

An employee might receive an email appearing to come from a director or manager asking them to purchase gift cards, transfer money or provide confidential information.

These attacks can be particularly convincing because the sender may know the names and roles of people within the organisation.

Warning signs

Be particularly cautious about unusual requests that involve money, passwords or confidential information.

If a request seems unusual, verify it using another communication method. A quick phone call can prevent a potentially costly mistake.

Look Beyond Spelling Mistakes

Poor spelling and grammar can be warning signs, but they’re no longer reliable indicators on their own.

Modern phishing emails can be professionally written and may closely imitate genuine business communications. Instead, look at the overall message and ask yourself whether the request is expected, whether the sender is genuine and whether the action being requested makes sense.

One of the simplest ways to identify a suspicious email is to hover over a link without clicking it.

This can show the destination address. If it points to an unfamiliar website, contains unusual characters or doesn't match the organisation it claims to represent, don't click it.

However, remember that a legitimate looking link doesn't automatically mean an email is safe.

What Should You Do If You Receive a Suspicious Email?

If you think an email could be phishing, don't click any links, open attachments or respond to the message.

Report it according to your company's internal procedures and, if necessary, contact your IT support provider. If you've already clicked a suspicious link or entered your credentials, act quickly. Changing your password and reporting the incident immediately can help limit the potential damage.

Protecting Your Business From Phishing

Phishing attacks rely heavily on human error, which is why employee awareness is such an important part of cybersecurity.

Regular training, multi factor authentication, email security and proactive monitoring can all help reduce the risk of a successful attack.

At Edmondson's, we help businesses strengthen their cybersecurity and give employees the knowledge they need to recognise threats. Understanding what phishing emails look like is a simple but important step towards keeping your business, employees and data protected.

Real Examples of Phishing Emails and How to Spot Them
Phishing emails are designed to trick employees into clicking malicious links, opening attachments or sharing sensitive information, often by impersonating trusted organisations or colleagues. By recognising warning signs, verifying unexpected requests and providing regular staff training, businesses can significantly reduce the risk of falling victim to phishing attacks.
The Most Common Cyber Threats for Small Businesses
Small businesses face a growing range of cyber threats, including phishing attacks, ransomware, and data breaches. By investing in strong cybersecurity measures, regular staff training and proactive IT support, businesses can significantly reduce their risk and better protect their systems, data and day-to-day operations.
Microsoft’s Price Increases, Is It Time to Upgrade to Microsoft 365 Business Premium?
Microsoft is increasing the cost of many Microsoft 365 licences, with prices rising by around 5% to 33% depending on the plan. Now's a good time to review your licences to make sure you're getting the best value, security and features for your business.

2 Hour Response Window

FREE IT Health Check

Price Match Guarantee

Rated Excellent On Trustpilot

© Edmondson's IT Services | Co. Reg. No: 07818717 | VAT Reg. No: GB122507059