Below are some phishing email examples (and the cases that follow will illustrate why) that best read by pattern and not “gut feel.
In 2025 and 2026, eight attack problems caused the bulk of the mailbox overflow in the organization. Attacks that were chosen and the results produced from known incidents are listed below.
Here is the Recognition Problem: phishing email examples do their work before they look like phishing, which is the point of the examples below.
Catch them you could, the phishing email examples of a decade ago – the typos were obvious, the sender addresses were implausible, and the greetings were stock.
Those indicators of current attacks are no longer displayed. The goal in an attack is to make the recipient act first, before looking at the technical indicators.
Technical indications that persist: the domain of the sender does not match up with the domain of the link destination, the link destination URL is suspicious, the attachment type is unexpected. These identify the attacks in all eight types, selecting a “time out” action, such as restriction on an account, payment due date or delivery hold. Eight types of attacks are described below. The two most expensive are BEC and AI-generated targeted phishing. The most common warnings are for account compromise.
The warning emails and lookalike login pages that follow are examples of the Credential Theft Problem. Here they are.
The business problem is that the volume scale credential harvesting is posing as “legitimate” Microsoft, Google or “big” SaaS security alerts. The attack goal is to have access to a business email or cloud-based accounts with authentication. Those accounts are the prize.
The attackers impersonate the sender domain with a lookalike name – microsoft-security.net or microsoftalerts.co as opposed to @microsoft.com or @accountprotection.microsoft.com. The landing page looks the same as the legitimate login page, but is under the control of the attacker. The framing: a password reset is required, indicated by the term “subject line” (or similar terms) in the subject line of an email. The account will be blocked in 24-hours. Credentials typed on the lookalike page end up with the attacker. The selected defense is Multi Factor Authentication for all Business email accounts. The stolen credentials can’t log in to an account that is protected with MFA. Check the domain a link leads to before clicking it, by placing your cursor over it and comparing it to the sender’s known domain, to make sure the link is legitimate.
Business email compromise and no-link attack emails are also known as the Wire Fraud Problem.
BEC cost US businesses $2.9 billion in 2023, says the FBI Internet Crime Complaint Center annual report. That year it was the top dollar loss of any cybercrime category, out of 21,489 complaints. The three-year run: 2021 at $2.4B with 19,954 complaints, 2022 at $2.74B with 21,832 complaints, 2023 at $2.9B with 21,489 complaints – every year above $2.4 billion.
The preferred tool of the attacker: executive impersonation or forged vendor email correspondence, no links, no attachments, that get around filter on email links. The recognition problem is that the sender address is only one character away from the executive’s actual address, or is a free provider and uses a display name for the executive.
Case 1. His name: Evaldas Rimasauskas. Citizenship: Lithuanian. Scheme: the period 2013 to 2015. Forgery of invoices, contracts and letters pretending to be from hardware vendor. Focus companies: Google & Facebook. Facebook: ~$99 million was transferred. The quantity of funds transferred to Google: around $23 million. Total: roughly $123 million. Indictment Issued: Dec. 2016 in Southern District of NY. Arrest: Lithuania, March 2017.
Extradited to the USA. A guilty plea followed. The sentence was December 2019: 60 months in the U.S. Federal prison. The two firms were later to say they had clawed back most of the money.
Case two.
Ubiquiti Networks Inc. of San Jose, disclosed on August 5, 2015. The fraud ran from May 20 to June 5, 2015 – 17 days. Wire Transfer Fraud: 14 fraudulent wire transfers through the Hong Kong subsidiary. Amount: $46,703,232. The attacker pretended to be company executives and an outside law firm. $8.1 million was directly recovered. $6.8 million was court-ordered. The net loss was ~$39.1 million (Q4 FY2015). The source is an Ubiquiti SEC 8-K filing from August 2015.
The tool selected for defense: Call back protocol verification. The callback procedure is this: if a request for wire or banking detail change is made, a callback is made to a verified number from existing records, not any number included in the suspicious e-mail.
The Vendor Trust Problem: e-mail invoices and payment diversion are used for the scams.
Business problem: using the services of vendors to defraud the expected payments. Attack sequence: the attacker is able to identify an active vendor relationship. An attack e-mail message is received from one of the domains that are identical, except for one character change or top-level domain change. An e-mail is sent asking for an up-to-date bank account to be given for future payments. The finance staff keeps the payment record up to date. Once the money is transferred to the attacker’s account, it will be the next payment. Then case three. TBC – the parts supplier: Toyota Boshoku Corporation. Disclosure: September 6, 2019. Fraud date: August 14, 2019. Its European subsidiary. Email from a fake contact claiming to be the real person that asks for payment. The amount of transfer: about 4 billion yen, at an estimated cost of $37 million. At the time of disclosure there was a criminal investigation in progress. Publicly named perpetrator does not exist. And then case 4. Leoni AG of Bavaria. German maker of cables and wires for the automotive industry, from Bavaria. Fraud date: August 2016, per the disclosure. Fake President fraud – the German word Fake-Prazidentenbetrug. Attacker sent emails to Leoni’s Romania subsidiary Finance staff in an attempt to steal from them, pretending to be from a high-level correspondent within the company and urging an urgent wire transfer. Losses: estimated to be nearly 40 million euros. No recovery was announced when discovering. The incident was revealed to Leoni on 17th August 2016. The data comes from Reuters, the BBC and the corporate statement from Leoni AG from August 2016. The €40 million reported loss for Leoni is one of the largest BEC losses reported in Europe.
The defense tool used is a verbal confirmation protocol. The banking instructions are different, and require a call to a known name in the vendor, not to the email that sent the instructions for the change.
This is an overview of losses and recovery rates for BECs in the public sector. Here it is.
Government departments that are the victims of the banking change requests are specific targets of BEC attacks, and the format for change is identical to that used for private-sector BEC. Impersonate a financial institution and ask for an update of financial information for government payments: that is the attacker’s trick.
Case five. This could be an organization such as the Government of Puerto Rico. The fraud timeframe ran from the end of 2019 through to the end of January 2020, and $2.6 million of government money was transferred. The FBI was notified of this incident in January, 2020. The Associated Press and CyberScoop covered the story on Friday, Feb. 4, 2020. When the government agency targeted, Puerto Rico Industrial Development Company, found the fund transfer to go to fraudulent accounts, they reported to the FBI right after the discovery.
The FBI Recovery Asset Team handled $742 million in BEC wire fraud cases referred for recovery action in FY2023. The identified, recovered or frozen sum was $433 million. The recovery rate is ~58 per cent of the referred amounts. The faster a case is reported, the sooner a recovery will be made. The domestic and international wire recall procedures have to be implemented within hours of the fraudulent wire.
Routine-Format Problem – shipping notification and HR phishing emails.
The business problem is that high-volume routine email formats are expected, and so reduce suspicion. The formats that get exploited are package delivery notifications and payroll platform messages.
The shipping notification format. The impersonation is of FedEx, UPS, or DHL delivery alerts. Delivery exception, customs fee, address confirmation: reported. The link sends you to a credential-capture page. Downloaded: malware. The defense is to go to the carrier’s website and enter the tracking number there. Carriers do not take credit card payment by email link before releasing a domestic package, not ever.
HR phishing emails go after the employees that have payroll access. The impersonation is of a company payroll platform, and the platforms are Gusto, Rippling, or ADP. Confirmation of the banking details on a direct deposit change is what gets asked for. Before the next pay cycle, an emergency banking update is told to the employee. The defense is a separate channel for verification. Direct deposit changes are never sent by email link from payroll platforms. Urgent or not, they are not sent. Out-of-band confirmation is required for emailed banking changes, and urgent or not does not matter, with a pay date coming up.
The grammar filter is beaten by AI-generated phishing email examples in 2025 and 2026. That is what the shift to AI tools did.
Grammar-based detection of phishing email examples: done. As a filter: no. AI-produced copy reads the same as legitimate professional correspondence. Cofense researchers recorded the shift in 2024: targeted business phishing campaigns stopped having any grammar tells left.
Grammar has not been a signal since years ago, and is not in 2026 either. Sender domain: still a signal. Link destination URL: so is that. The unusual request pattern counts. And so does urgency framing around a financial transaction or a credential action.
The Remediation Problem: what to do after a phishing incident, and here it is.
The business problem is that faster reporting makes for better recovery. Here is the five-year escalation. In 2019 it was $1.77 billion, 23,775 complaints. In 2020 it was $1.87 billion, 19,369 complaints. In 2021 it was $2.4 billion, 19,954 complaints. In 2022 it was $2.74 billion, 21,832 complaints. In 2023 it was $2.9 billion, 21,489 complaints. The five-year cumulative loss 2019 through 2023 adds up to around $11.69 billion. Dollar losses grew 64 per cent from 2019 to 2023. Complaints plateaued: 19,000 to 24,000. What that suggests is this: attack sophistication went up, and targeted transaction size went up.
The immediate response is this: compromised credentials are changed from a clean device, not the machine that opened the phishing email. IT is notified and, if financial fraud occurred, your bank and the FBI IC3 (ic3.gov). The attack email and its headers are documented. In a BEC wire fraud, the sending bank is contacted immediately and a SWIFT recall is requested. Got back: $433 million of the $742 million referred in FY2023, by the FBI Recovery Asset Team. The sooner it is reported, the more is recovered.
Every business email account has MFA on it. Bitwarden is free for individuals. For teams it is $3/user/month. 1Password for business accounts is $4/user/month. Most phishing attempts are caught before delivery, by email filtering in Google Workspace and Microsoft Defender for Office 365. The subscribers do not pay extra for it.
Three characteristics are shared by these phishing email examples from prosecuted BEC cases: sender domain impersonation, urgency language, a payment or credential request. The case documentation above is for this: the three elements are spotted before clicking. Free guidance for businesses that have no security staff: That is CISA’s Small Business Cybersecurity Corner at cisa.gov. Security-adjacent tools worth evaluating are listed in our best AI tools for business guide. The annual BEC and phishing loss numbers are published by the FBI-run IC3 at ic3.gov. Its phishing guidance is adapted by the FTC as the attack formats evolve. For what changes when a business’s data is compromised, see our general liability insurance cost guide. Here is the list.




