Why phishing still works in 2026
Phishing remains the number-one entry point for fraud and ransomware because AI removed its biggest tell: bad grammar. Modern phishing emails are perfectly written, personalized with breach data and LinkedIn details, and timed to moments of pressure. Recognizing them now depends on behavioral signals, not spelling mistakes.
The 7 signs of a phishing email
- Urgency and fear — "Your account will be closed," "Action required in 24 hours."
- A mismatched sender — display name looks right, but the actual address or domain is off by a character.
- Unexpected links or attachments — hover before clicking; the URL doesn't match the brand.
- Requests for credentials, OTPs, or payment changes.
- Generic or slightly-wrong greetings despite knowing your name elsewhere.
- "Reply-to" differs from "From."
- Out-of-band pressure — a follow-up text or call referencing the email.
Phishing variants to know
- Spear phishing — highly targeted, personalized to you specifically.
- Smishing — phishing by SMS, often "delivery failed" or "bank alert."
- Vishing — voice phishing, increasingly using AI voice clones.
- Quishing — malicious QR codes that route to credential-harvesting pages.
- AiTM phishing — adversary-in-the-middle kits that steal your password and your MFA code together.
What to do when you receive a phishing email
- Don't click, reply, or download.
- Verify any request through a separate, known channel — type the company's website fresh, or call the number on your card.
- Report it to your IT/security team and your email provider's "report phishing" button.
- If you already clicked or entered credentials, change your password immediately and enable phishing-resistant MFA.
How to protect your organization
- Deploy phishing-resistant MFA (passkeys/FIDO2) — it defeats AiTM kits that bypass SMS and app codes.
- Enforce DMARC at p=reject and add external-sender banners.
- Run AiTM-aware phishing simulations quarterly, not annually.
- Make reporting one click, and thank — never shame — people who report.
Frequently asked questions
How can I tell if an email is phishing?
Check the real sender address, hover over links to see the true URL, and be suspicious of any urgency or request for credentials, codes, or payment changes. When in doubt, verify through a separate channel you trust.
What should I do if I clicked a phishing link?
Change the affected password right away, enable phishing-resistant MFA, scan your device, and report it to your security team. If financial details were entered, contact your bank immediately.