What phishing emails actually look like in 2026
Fewer princes. More Microsoft 365 notices, freight invoices, and threads that were already in the mailbox.
ITSIGN Administrator · April 16, 2025 · 2 min read
The mail that works does not look like a scam. It looks like a SharePoint share, a stalled payment, or a CEO who is "in an airport."
Attackers replay real threads. They register lookalike domains one character off your legal name. They call after the email.
What to train
The pause. The callback on a known number. The report button. Not a colour-theory lecture about the padlock.
That is security awareness training. The technical side is SPF, DKIM, DMARC and 365 controls — see our email-security pieces on this blog.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
