Highlights
Phishing remains the top initial attack vector, despite years of employee awareness training.
AI is making phishing harder to spot, replacing obvious errors with convincing, personalized messages.
Real attackers move beyond email, increasingly using SMS and voice to reach less-defended channels.
How to Spot Phishing Emails in 2026 (7 Ways)
You can teach someone every red flag on this page and they'll still click the wrong link on a Tuesday afternoon when they're behind on their inbox. That's not a knock on training, it's the reality of how phishing works. This guide covers how to spot phishing emails: the specific signs, a real example annotated against them, and why "can your people spot it" is the wrong question to build a security program around.
Email is still the most common way attackers get in the door. Phishing and spoofing were the most reported cybercrime category to the FBI's Internet Crime Complaint Center in 2025, with more than 190,000 complaints - more than any other crime type tracked (FBI, 2025 Internet Crime Report). Getting good at spotting it matters. It's just not where the story ends.
What are Phishing Emails?
Phishing emails are messages designed to look like it's from someone you trust - a bank, a coworker, a vendor - in order to get you to click a link, hand over credentials, or move money. That's the phishing definition in one sentence, and it covers the vast majority of what lands in an inbox.
Spear phishing is the sharper version: instead of a mass blast, the attacker targets one person or a small group, using details specific to them such as a real vendor relationship, a real coworker's name, a real project. It's slower to run and far more convincing, which is exactly why it works.
The Warning Signs: How to Spot Phishing Emails
Every phishing email is exploiting the same thing: your instinct to respond quickly to things that look legitimate and urgent.
The signs below are what that exploitation looks like from the outside.
1. Mismatched Sender Domain
The display name says "Microsoft IT," but the actual email address is something like support@micr0soft-alerts.com. Attackers count on people reading the display name and never checking the domain underneath it.
2. Urgency or Fear Language
"Your account will be suspended in 24 hours." "Unusual sign-in detected — verify now." Urgency is a tactic, not a coincidence and it's designed to get you moving before you think to check.
3. Generic Greetings
"Dear Customer" or "Dear User" instead of your name is a sign the email was sent to thousands of people, not written for you specifically. Spear phishing emails fix this, which is part of what makes them harder to catch.
4. Suspicious Links
Hover over a link before clicking and the actual destination URL will show at the bottom of most email clients or browsers. If the visible text says "Log in to your account" but the link points somewhere unrelated to the company it claims to be from, that's the tell.
5. Unexpected Attachments
An invoice, shipping label, or "signed document" you weren't expecting is one of the most common malware delivery methods. If you weren't waiting on a file from that sender, treat it as suspicious until confirmed.
6. Requests for Credentials or Payment
Legitimate companies never ever ask you to email your password. Legitimate vendors don't usually change their bank details over email without a verified phone call to confirm. Any message asking you to do either is worth a second look.
7. Poor Formatting or Spoofed Branding
Slightly-off logos, inconsistent fonts, or awkward phrasing can be a sign the email wasn't produced by the company it claims to represent. Although, this sign is getting less reliable.
Generative AI has cut the time it takes to write a convincing phishing email from as long as 16 hours down to about 5 minutes, according to IBM's 2025 Cost of a Data Breach Report, which is a large part of why the sloppy, typo-ridden phishing email is becoming less common (IBM, Cost of a Data Breach 2025).
A Real Phishing Email Example
One of the most well-documented phishing cases in recent history involves two companies most people would assume are too sophisticated to fall for it: Google and Facebook.
Between 2013 and 2015, a Lithuanian man named Evaldas Rimasauskas ran a scheme that duped Google and Facebook out of more than $100 million combined, according to the U.S. Attorney's Office for the Southern District of New York. Rimasauskas set up a company in Latvia using the same name as Quanta Computer, a real Taiwan-based hardware manufacturer that both tech giants did business with. He then sent invoice requests from the fake Quanta to both companies, backed by forged invoices, contracts, letters, and even fake corporate stamps designed to make the payment requests look legitimate to the banks processing them.
Run this case against the red flags above:
Mismatched sender domain: The emails came from a company that merely shared Quanta's name, not Quanta's actual domain.
Requests for payment: The entire scheme hinged on convincing finance employees to wire money to new accounts.
Poor formatting or spoofed branding: The opposite, actually. This case is a useful reminder that the "sloppy, obviously fake" phishing email is not the only kind. The forged documents were convincing enough to fool two companies' finance and legal teams for two years.
This is a textbook case of business email compromise, a category of phishing where fraudsters request money transfers through emails targeting companies with existing foreign supplier relationships.
It's also a reminder that "spot the red flags" advice works best against high-volume, low-effort phishing. Against a patient, well-resourced attacker, the visible signs get harder to find.
Why Spotting Emails Alone Isn't Enough
Here's the uncomfortable part: even a well-trained employee is not a reliable control. People are tired, distracted, and under deadline pressure, the exact conditions phishing is designed to exploit. Training someone once a year to recognize red flags doesn't tell you anything about how they'll behave the day an attacker actually reaches them.
The financial numbers back this up. Phishing was the single most common initial attack vector across the breaches IBM studied for its 2025 Cost of a Data Breach Report, involved in 16% of all incidents and carrying an average cost of $4.8 million per breach (IBM, Cost of a Data Breach 2025). Recognition training helps, but it's competing against an attack that's getting cheaper and faster to run at the same time it's getting more expensive to clean up after.
And email is only one door. When organizations get good at filtering and training against email phishing, attackers move to channels with less scrutiny and more implicit trust such as a text message that looks like it's from IT, a phone call that sounds like the CEO.
That shift isn't hypothetical: Verizon's 2026 Data Breach Investigations Report found that mobile-centric social engineering - fake text messages and voice calls - now succeeds 40% more often than traditional email phishing, as people have gotten more practiced at spotting the email version (Verizon, 2026 DBIR). We've covered both of those shifts in more depth: see our guides to vishing and smishing for how voice and SMS-based social engineering work, and why they're growing faster than email-based attacks.
The honest framing isn't "did this person pass the phishing test." It's "how exposed is this person right now, across every channel an attacker could use, and how would we know before it becomes an incident."
How Cimento Can Help
This is the gap Cimento is built to close. Instead of a once-a-year training completion, Cimento builds a living risk profile for every employee by integrating with the tools they already use such as email, identity providers, cloud platforms, and running realistic social engineering simulations across email, SMS, and voice, often as multi-step sequences rather than single-click tests.
Risk triggers immediate coaching: When a simulation reveals risky behavior, Cimento responds in the moment with short, contextual coaching tied to what the employee just experienced, typically 60 to 90 seconds.
Coaching is specific to the behavior: Instead of assigning a generic training module days or weeks later, employees get guidance that addresses the exact action or decision that created the risk.
Every interaction updates the risk profile: The employee’s response to simulations and coaching feeds back into their profile, creating a continuously updated view of human risk rather than resetting after an annual training cycle.
Risk becomes an ongoing feedback loop: Simulate → identify risky behavior → coach in the moment → measure the next response, so the program continuously adapts to how employees actually behave.
The same model extends to AI agents. As agents take on more day-to-day work inside organizations, they inherit the access and behavior patterns of the person who configured them. This means agent exposure is really an extension of that person's risk profile, not a separate problem requiring a separate tool.
Cimento treats it that way: one continuous, per-person risk score that covers both the human and the agents they operate, rather than a bolt-on product with its own dashboard.
If you want to see where your organization actually stands before deciding what to fix, Cimento's human risk baseline gives you a starting point alongside whatever program you're already running. For a fuller look at how the category works and what to evaluate in a platform, see our complete guide to Human Risk Management.
Real World Case Studies
AI-native companies make a useful proof point here - they carry outsized attacker interest, run lean security teams, and can't afford a program that only looks good on a compliance report.
Together AI, which runs one of the most widely used platforms for building and running open AI models, consolidated security awareness training for close to 400 employees onto Cimento and automated new-hire onboarding through weekly cohorts. As AI agents took on more of the company's actual work, that relationship expanded from training into visibility over agent-level risk.
Read the full story →
Exa AI, the search engine built for AI agents, had run a phishing test through its previous vendor and recorded a single click, not because employees were resilient, but because most of the emails never reached the inbox in the first place. With no reliable baseline and new hires already receiving impersonation texts within days of onboarding, the team needed simulations realistic enough to actually measure exposure across channels.
Read the full story →
How Organizations Are Moving Beyond Email-Only Awareness
The organizations getting this right are shifting from a training-completion model to a continuous, behavior-based one, measuring how people actually respond to realistic, multi-channel simulations over time, rather than testing recall once a year and hoping it holds.
That shift is also where AI agent risk enters the picture: the same person who might click a phishing link is often the same person whose AI agent has broad access to internal tools, which means the exposure question no longer stops at the human inbox.
FAQs About How to Spot Phising Emails
1. What is a phishing email?
A phishing email is a fraudulent message designed to look like it's from a trusted source in order to trick you into clicking a malicious link, providing credentials, or sending money.
2. How do I know if an email is phishing?
Check the sender's actual email domain (not just the display name), look for urgent or fear-based language, hover over links before clicking, and be cautious of unexpected attachments or requests for payment or login credentials.
3. What's the difference between phishing and spear phishing?
Phishing is sent broadly to many recipients using generic messaging. Spear phishing targets a specific person or small group using details tailored to them, which makes it considerably harder to spot.
4. Is phishing still a threat in 2026?
Yes. It was the most reported cybercrime category to the FBI in 2025 and remains the top initial attack vector in IBM's breach cost research. Attackers are increasingly pairing it with SMS (smishing), voice calls (vishing), and AI-generated content to make attacks more convincing and harder to filter.
Key Takeways
Teach employees to verify sender domains, links, attachments, urgency, and payment or credential requests.
Use realistic simulations to measure how employees respond when phishing reaches them under real-world conditions.
Expand testing beyond email to include SMS, voice, and multi-channel social engineering attacks.
Turn risky behavior into immediate, contextual coaching instead of relying solely on annual training.
Maintain a continuously updated risk profile to understand who is exposed and how that exposure changes.




