Most phishing advice is a decade out of date. Look for spelling mistakes, check for generic greetings, be suspicious of poor formatting — none of which describes what actually lands in inboxes now.
Modern phishing is well written, correctly branded, and frequently sent from a legitimate compromised account belonging to someone the recipient knows. The old tells are gone, and training built around them produces false confidence.
What the tells actually are now
The reliable signals are behavioural rather than cosmetic.
An unexpected request for action
The single most useful signal. Not the sender, not the formatting — whether you were expecting this. An invoice you did not anticipate, a password reset you did not request, a document share from someone who does not normally share documents.
Urgency combined with unusual process
Legitimate urgent requests usually still follow normal process. Phishing requires the recipient to bypass something — approve without the usual sign-off, act before verifying, keep it confidential.
The confidentiality request is particularly diagnostic. "Do not discuss this with anyone until it is announced" exists solely to prevent the verification that would expose the fraud.
Any change to payment details
Treat every one as fraudulent until verified by voice to a number you already hold. This single rule prevents the most expensive incidents most businesses will face, and it requires no technical skill to apply.
The link destination, not the link text
Hover before clicking. Look at the actual domain, reading right to left from the last dot before the first slash. Attackers rely on people scanning left to right and stopping at the recognisable brand name.
Requests that route around normal systems
Being asked to log in through a link rather than your usual bookmark, to open a document on an unfamiliar portal, or to move a conversation to a personal channel.
The variants worth naming
- Business email compromise — no malicious link or attachment, just a plausible request for a payment or a change of banking details. Invisible to most filtering because there is nothing technically malicious in the message.
- Consent phishing — you are asked to grant an application access to your account rather than to enter a password. Because you authenticate legitimately, MFA does not help, and the granted access persists after a password change.
- Adversary-in-the-middle — a proxy that relays your login and captures the session token. This defeats most MFA methods, and it is why phishing-resistant authentication matters for privileged accounts.
- Callback phishing — an email with no link, asking you to phone a number about a subscription charge. The person answering talks you into installing remote access software.
- QR code phishing — the destination is not visible before scanning, and phones are frequently less protected than managed laptops.
The pattern across the newer variants is that they avoid the things filtering detects. Which is why training matters, and why it cannot be the only control.
Training that changes behaviour
Annual compliance training produces a completion record, not a change in behaviour. What works looks different:
- Short and frequent. Ten minutes monthly beats an hour annually. Recognition degrades quickly without reinforcement.
- Use real examples, ideally ones that reached your own organisation, with identifying details removed. Generic examples feel like someone else's problem.
- Simulated phishing, run as measurement rather than as a trap. The purpose is to identify where reinforcement is needed, not to catch people out.
- Never punish reporting. A culture where people fear admitting a click is a culture where compromises stay hidden until they are severe.
- Make reporting trivial — a one-click button in the mail client, not an instruction to forward to an address nobody remembers.
- Acknowledge reports, including false alarms. Someone who reports a legitimate email and gets thanked will report the next one.
That fourth point is the one most often violated. Businesses that publish click rates by individual or discipline repeat clickers get quieter staff rather than safer ones, and the click that matters is then the one nobody mentions.
What training cannot do
It is worth being honest about the ceiling. A sufficiently well-crafted, well-timed phishing email will get clicked by a competent, trained person having a busy day. Treating any click as a training failure misplaces the responsibility.
Training reduces frequency. The technical controls determine what happens on the occasions it fails:
- MFA, so a captured password alone is insufficient
- Phishing-resistant authentication for privileged accounts, which defeats token theft
- Email filtering and correctly configured SPF, DKIM and DMARC so your own domain cannot be trivially spoofed
- Restricting which applications users can grant access to, which addresses consent phishing
- Endpoint detection, to catch what follows a click
- Payment verification procedures, which stop the fraud even when the email succeeds completely
That last control is worth restating because it is procedural rather than technical, costs nothing, and defeats the single most expensive category of attack even when every other layer has failed.
What to do after a click
Make the response known in advance so people act quickly rather than hesitating:
- Report immediately, even if unsure, and even if hours have passed
- Disconnect the device from the network if anything was downloaded or installed
- Change the password from a different device, and terminate active sessions
- IT reviews account activity for anything that happened in the interval
- Check specifically for mail forwarding rules, which attackers create early and which persist silently after a password change
That final check is the one most often missed. A forwarding rule quietly copying mail to an external address survives password resets and is the groundwork for business email compromise weeks later.