You’re scanning your inbox, and an email from your “bank” lands with a subject line about a suspicious login. Your pulse ticks up. That’s exactly what the attacker wants. Spotting a phishing email means catching the small tells that bypass your rational brain, and that’s what this guide walks through — the red flags, the verification moves, and how to build a reflex that keeps your data safe.

Phishing email rate: 1 in every 99 emails is a phishing attempt ·
Cost of phishing: Phishing damages average $4.76 million per breach in 2023 ·
User vulnerability: Nearly one-third of users click on phishing links ·
Common red flags: 67% of phishing emails use urgency or threats ·
Best defense: Multi-factor authentication can prevent 99.9% of account takeover attacks

Quick snapshot

1Confirmed facts
2What’s unclear
  • Whether opening a phishing email can trigger infection (attachments yes, plain text no)
  • The exact percentage of phishing emails that are successful
3Timeline signal
4What’s next
  • More sophisticated AI-generated voice and video phishing (vishing) targeting executives

Six key stats, one pattern: phishing is a scale game that preys on human reaction speed, not technical gaps.

The facts in the table below consolidate what the authorities agree on.

Fact Detail Source
Phishing definition Cybercrime using disguised emails to trick recipients into revealing sensitive information FTC (federal consumer watchdog)
Prevalence 1 in 99 emails is a phishing attempt CISA (cybersecurity agency)
Financial impact Average cost $4.76 million per breach SecurityScorecard (risk analytics firm)
Success factor Exploits human trust and urgency CISA (cybersecurity agency)
Click rate Nearly one-third of users click on phishing links Aura (digital security provider)
MFA effectiveness Multi-factor authentication can prevent 99.9% of account takeover attacks CISA (cybersecurity agency)

The pattern: attackers target the gap between what you see and what you verify.

What are common signs of a phishing email?

Urgency and threats

  • Phishing emails create a false time pressure. The Canadian Centre for Cyber Security lists pressure to respond quickly as a core red flag GetCyberSafe Canada (government advisory).
  • Threats of account closure, legal action, or immediate charges are classic hooks GetCyberSafe Canada (government advisory).
  • CISA warns that this emotional language is the fastest indicator — attackers want you to act before you think CISA (cybersecurity agency).

Generic greetings and spelling errors

  • “Dear Customer” or “Dear User” instead of your name is a tell. The FTC emphasizes that real companies know your name FTC (federal consumer watchdog).
  • Spelling or grammar errors beyond an occasional typo can signal phishing GetCyberSafe Canada (government advisory).
  • Aura notes that attackers often copy brand text poorly, creating awkward phrasing Aura (digital security provider).

Suspicious links and attachments

  • Hover your mouse over any link before clicking. The Canadian Centre for Cyber Security says mismatched URLs are a dead giveaway GetCyberSafe Canada (government advisory).
  • Attachments you didn’t request, weird file names (like “invoice.pdf.exe”), and uncommon file types are phishing indicators GetCyberSafe Canada (government advisory).
  • Huntress advises inspecting the URL structure — does the domain exactly match the real company’s domain? Huntress (cybersecurity firm).

The catch: urgency is a shortcut that bypasses your analytical brain. When an email demands you act within 15 minutes, the attacker is counting on you to skip verification.

What are the 5 key signs of phishing?

Unexpected attachments

  • An unexpected invoice, shipping notice, or voicemail attachment from someone you haven’t interacted with is a red flag. The FTC says attachments and links in phishing messages might install harmful malware FTC (federal consumer watchdog).
  • SecurityScorecard warns that unfamiliar webpages linked from attachments are common indicators SecurityScorecard (risk analytics firm).

Request for personal information

  • Legitimate companies never ask for passwords, Social Security numbers, or credit card details via email. The FTC says if you don’t have an account with the company, the message could be a phishing scam FTC (federal consumer watchdog).
  • CISA confirms phishing messages often request personal and financial information CISA (cybersecurity agency).

Mismatched URLs

  • The link text says “secure.bank.com” but the hover text shows “evilclick.net”. The Canadian Centre for Cyber Security says links that don’t go to official websites are a warning sign GetCyberSafe Canada (government advisory).
  • Huntress recommends checking for subtle misspellings — “rnicrosoft.com” instead of “microsoft.com” Huntress (cybersecurity firm).

Unusual sender address

Too good to be true offers

  • You won a lottery you never entered, or a limited-time prize requires immediate action. Canadian Centre for Cyber Security flags these as emotional manipulation GetCyberSafe Canada (government advisory).

The implication: phishing emails are manufactured triggers, not real communications. For everyday users: ignore the urgency and verify the sender through official channels. For IT teams: invest in email filtering that flags public-domain senders and mismatched URLs.

How to verify if an email is phishing?

Check sender address

  • Don’t trust the sender name — look at the actual email address. Huntress says the number one check is whether the email address matches the real domain exactly Huntress (cybersecurity firm).
  • The FTC advises verifying by contacting the company using a phone number or website you already know is real, not the information in the email FTC (federal consumer watchdog).

Hover over links

  • Hover your mouse pointer over the link without clicking. The full URL will appear in a tooltip or status bar. If it doesn’t match the legitimate company’s domain, don’t click GetCyberSafe Canada (government advisory).
  • Huntress adds that shortened URLs (like bit.ly) from untrusted senders should be treated with caution Huntress (cybersecurity firm).

Look for HTTPS and padlock icon

  • If a link leads to a login page, check the browser bar for “https://” and a padlock icon before entering credentials. But note: a padlock alone doesn’t guarantee the site is legitimate — it only confirms the connection is encrypted CISA (cybersecurity agency).

Use official channels to confirm

  • The FTC’s strongest rule: don’t use any contact information from the suspicious email. Instead, go directly to the company’s website or call their official customer service number FTC (federal consumer watchdog).
  • If an email says your account has been compromised, log in through the official app or website — not through the email link — to check for real alerts.

The pattern: employees who habitually verify through official channels cut phishing success rates dramatically. For individuals: making “hover and check” a reflex closes the gap between suspicion and safety.

What does a phishing email look like?

Phishing email examples

  • An email appears to be from your bank with the subject “Urgent: Account Suspended.” Inside, a link directs you to “bank-secure.com” instead of “bank.com”. The FTC has documented these exact campaigns FTC (federal consumer watchdog).
  • A “package delivery failure” from FedEx asks you to download an attachment to rearrange delivery, but the attachment is a .exe file. The Canadian Centre for Cyber Security flags unexpected attachments with weird file names as phishing GetCyberSafe Canada (government advisory).

Common subject lines

  • “Your account has been compromised”
  • “Payment confirmation for purchase you didn’t make”
  • “You’ve won a $500 gift card — claim now”
  • Aura notes that subject lines often trigger strong emotional reactions to bypass rational thought Aura (digital security provider).

Visual cues: logos and branding

  • Incorrect or blurry logos, poor formatting, and inconsistent color schemes are signs. The Canadian Centre for Cyber Security warns that low-quality branding can indicate a spoofed message GetCyberSafe Canada (government advisory).
  • Hoxhunt characterizes phishing red flags as both behavioral and technical cues in messages, sites, or meetings Hoxhunt (security awareness platform).

The takeaway: modern phishing emails look increasingly convincing, which makes verification habits the only reliable defense.

How to prevent phishing emails?

Use spam filters

  • Modern email services (Gmail, Outlook, ProtonMail) use AI to block most phishing attempts before they reach your inbox. Microsoft reports that their filters block billions of phishing emails annually CISA (cybersecurity agency).
  • But filters aren’t perfect — some messages still slip through, which is why user awareness remains critical.

Enable multi-factor authentication

  • Even if a phisher steals your password, MFA keeps them out. CISA says MFA can prevent 99.9% of account takeover attacks CISA (cybersecurity agency).
  • The FTC recommends using an authentication app or hardware key over SMS-based codes, which can be intercepted FTC (federal consumer watchdog).

Regularly update software

  • Most phishing attacks target known vulnerabilities. Microsoft and Apple release patches that close these gaps. The FTC advises keeping your browser, operating system, and antivirus software updated FTC (federal consumer watchdog).

Educate employees and family

  • Training reduces click-through rates dramatically. Security awareness programs that simulate phishing attacks can cut success rates by over 50% Hoxhunt (security awareness platform).
  • The Canadian Centre for Cyber Security publishes free resources to help Canadians train their teams GetCyberSafe Canada (government advisory).

The trade-off: adding MFA and training layers creates friction for users, but the cost of a single successful phishing breach (average $4.76 million) overwhelms any convenience trade-off. For SMBs, the equation is even starker — they’re targeted in 43% of attacks.

Timeline: How phishing evolved

  • Mid-1990s: First reported phishing attacks on AOL. Attackers used instant messages to trick users into revealing passwords (CISA (cybersecurity agency)).
  • 2003-2004: Phishing becomes more common with broadband. Attackers begin targeting banks directly (FTC (federal consumer watchdog)).
  • 2013: Target data breach traced back to a phishing email sent to a third-party HVAC vendor, compromising 40 million customer records (SecurityScorecard (risk analytics firm)).
  • 2016: Democratic National Committee email phishing attack leaks sensitive internal communications (CISA (cybersecurity agency)).
  • 2020: COVID-19 related phishing surges 667% in March alone, preying on health anxiety (FTC (federal consumer watchdog)).
  • 2023: AI-generated phishing emails increase sophistication, target C-suite executives with credible tone and no spelling errors (Hoxhunt (security awareness platform)).

The pattern: phishing adapts faster than most defenses. For users: trust offline verification channels. For IT teams: deploy AI-powered filtering and run simulated phishing drills quarterly.

Clarity section

Confirmed facts

  • Phishing emails often use urgency and threats CISA (cybersecurity agency)
  • Generic greetings are common in phishing FTC (federal consumer watchdog)
  • Hovering over links can reveal mismatched URLs Canadian Centre for Cyber Security (government authority)
  • MFA blocks most account takeover attacks FTC (federal consumer watchdog)

What remains unclear

  • Whether opening a phishing email can trigger an infection (in most cases no, but attachments and links can)
  • The exact percentage of phishing emails that successfully compromise a system

Quotes from experts

“Phishing emails and text messages may look like they’re from a company you know or trust. They may look like they’re from a bank, a credit card company, a social networking site, an online payment website or app, or an online store.”

— FTC Consumer Advice (FTC (federal consumer watchdog))

“Cybercriminals use urgency or emotionally appealing language to try to trick you into giving them your personal information or money.”

— CISA Secure Our World (CISA (cybersecurity agency))

“Spelling and grammar mistakes can be one of the signs that an email or text is a phishing attempt.”

— Microsoft Security (CISA (cybersecurity agency))

The implication across these three authorities is consistent: attackers exploit quick judgment, not technical brilliance. For the average user at home or in the office, the script is simple — when an email triggers a strong emotion, pause and verify. That single habit separates the safe from the compromised.

For the person reading this on their phone between meetings, the choice is clear: ignore the urgency, confirm the sender through official channels, or hit report-spam. The alternative — a $4.76 million breach or a hijacked personal account — isn’t theoretical. It’s the cost of acting on impulse.

To see these red flags in action, check out a real-world phishing email example that breaks down a typical scam message step by step.

Frequently asked questions

What should I do if I clicked a phishing link?

Disconnect your device from the internet to prevent further data exfiltration. Run a full antivirus scan. Change your passwords immediately using a different device. Report the incident to the FTC at ReportFraud.ftc.gov and your IT department if at work FTC (federal consumer watchdog).

Can a phishing email install malware on my device?

Yes, if you open an infected attachment or click a link that triggers a download. However, simply opening the email (without clicking anything) is generally safe for modern email clients CISA (cybersecurity agency).

How do I report a phishing email?

Forward phishing emails to the FTC at spam@uce.gov and to the Anti-Phishing Working Group at reportphishing@apwg.org. For company-specific scams, report directly to that company’s security team FTC (federal consumer watchdog).

What is spear phishing?

Spear phishing targets a specific individual or organization using personalized information — like your real name, job title, or recent purchases — gathered from social media or data breaches. It’s harder to spot because the language feels personal CISA (cybersecurity agency).

Are phishing emails always easy to spot?

No. Modern phishing emails, especially those generated with AI, can be well-written, use correct branding, and mimic real sender addresses. Many still get through because they mimic legitimate business communications Hoxhunt (security awareness platform).

What information does a phisher typically ask for?

Attackers commonly ask for passwords, Social Security numbers, credit card numbers, bank account details, login credentials, or gift card codes. Any email requesting this information is highly likely to be phishing FTC (federal consumer watchdog).

Related reading