Phishing Emails Are Getting Better. Hereโ€™s What Your Team Should Be Looking For ๐ŸŽฃ

September 1, 2026

Weโ€™ve all seen the obvious phishing emails. Strange spelling, a suspicious email address and an urgent request to click a link immediately... Those are usually fairly easy to spot.

โ€

The problem is that phishing emails are getting much better, which means knowing how to spot phishing emails in the workplace is more important than ever.

โ€

Todayโ€™s phishing emails can be well written, use convincing branding and appear to come from a company or person you recognise. AI is also helping criminals create more convincing messages, without many of the spelling and grammatical mistakes we traditionally associate with scams.

โ€

So, if your advice to employees is still simply โ€œlook out for spelling mistakesโ€, it might be time for an update.

โ€

What is a phishing email?

Phishing is designed to persuade you to do something you normally wouldnโ€™t. In a business, that might mean :

โ€

๐Ÿ‘‰ Clicking a link to a fake Microsoft 365 login page

๐Ÿ‘‰ Opening an unexpected attachment

๐Ÿ‘‰ Entering your email address and password

๐Ÿ‘‰ Changing a supplierโ€™s bank details

๐Ÿ‘‰ Making an urgent payment

๐Ÿ‘‰ Sharing confidential information

โ€

The email itself is often only the starting point. The real objective could be gaining access to your Microsoft 365 account, stealing company information or, ultimately, getting hold of money.

โ€

How do you spot a phishing email?

Rather than relying entirely on how an email looks, pay attention to what it is actually asking you to do.

โ€

Be particularly careful if an email :

โ€

๐Ÿ‘‰ Asks you to log into Microsoft 365 or another business system

๐Ÿ‘‰ Requests a payment or change of bank details

๐Ÿ‘‰ Contains an unexpected attachment

๐Ÿ‘‰ Pressures you to act immediately

๐Ÿ‘‰ Asks you to bypass your normal company process

๐Ÿ‘‰ Contains an unexpected QR code

๐Ÿ‘‰ Comes from somebody you know, but the request seems unusual

โ€

Urgency is a particular tactic... "Your password expires today", "Your mailbox is full", "A payment needs to be made immediately", "Your account is about to be suspended"... you get the idea. The aim is to get you to react before you stop and question the request.

โ€

Watch those QR codes

QR codes are increasingly being used in phishing emails. You might receive an email claiming your Microsoft 365 password is expiring, for example, followed by a QR code you need to scan to keep your account active. You scan it and arrive at what appears to be a Microsoft login page.

โ€

Except it isnโ€™t.

โ€

The National Cyber Security Centre, NCSC, has warned about QR code phishing, sometimes called โ€œquishingโ€. A QR code can hide the destination you are being sent to, making it harder to judge whether a link is genuine.

โ€

What should you do if youโ€™re not sure?

โ€

Check.... and check again. A quick independent check can stop a convincing phishing attempt in its tracks.

โ€

๐Ÿ‘‰ If a supplier asks you to change their bank details, call them using a number you already know.

๐Ÿ‘‰ If Microsoft apparently wants you to log in, donโ€™t use the link in the email. Go to Microsoft 365 in the usual way.

๐Ÿ‘‰ If a colleague sends an unusual request, call them or send them a separate Teams message.

โ€

A couple of minutes spent checking is considerably easier than dealing with a compromised account.

โ€

What if somebody clicks?

Tell your IT team and tell them quickly. People need to feel comfortable reporting mistakes. If someone clicks a suspicious link or enters their password into a fake website, waiting to see whether anything happens wastes valuable time.

Your IT team may need to :

โ€

โœ… Reset the password

โœ… Sign the account out of existing sessions

โœ… Check recent login activity

โœ… Scan the device

โœ… Check whether emails or other company information have been accessed

โ€

The sooner they know, the sooner they can act. Staff awareness is important, but your cyber security shouldnโ€™t depend entirely on every employee spotting every phishing email.

โ€

Good protection should include measures such as :

โ€

โœ… Multi factor authentication

โœ… Email security and filtering

โœ… Appropriate Microsoft 365 security settings

โœ… Endpoint protection

โœ… Secure backups

โœ… Staff cyber security awareness

โ€

Even experienced users can be caught out by a convincing phishing email. The NCSC recommends a layered approach rather than relying solely on users to identify suspicious messages. A simple rule for your team... If an email asks you to do something involving money, passwords, sensitive information or a change to your normal process, stop and check.

โ€

You donโ€™t need everyone in your business to become a cyber security expert. You do want them to feel confident questioning something that doesnโ€™t seem quite right, and to know who to ask when theyโ€™re unsure.

โ€

Need help with your business cyber security?

โ€

From Microsoft 365 security and email protection to backups, cyber security and managed IT support, the Espi IT team can help you understand what protection you currently have in place and where there may be gaps. And if youโ€™ve received a suspicious email and youโ€™re really not sure whether to click it... donโ€™t! Send it over to us and let us take a look first ๐Ÿ˜Š

โ€

๐Ÿ“ง support@espi.net

๐Ÿ“ž 01954 213999

โ€

โ€

Grow your system as your business
Grow your system as your business