Skip to main content Scroll Top
Advertising Banner
920x90
Top 5 This Week
Advertising Banner
305x250
Recent Posts
Subscribe to our newsletter and get your daily dose of TheGem straight to your inbox:
Popular Posts
8 Phishing Email Examples Every Business Should Know (2026)

Below are some phishing email examples (and the cases that follow will illustrate why) that best read by pattern and not “gut feel.

In 2025 and 2026, eight attack problems caused the bulk of the mailbox overflow in the organization. Attacks that were chosen and the results produced from known incidents are listed below.

Here is the Recognition Problem: phishing email examples do their work before they look like phishing, which is the point of the examples below.

Catch them you could, the phishing email examples of a decade ago – the typos were obvious, the sender addresses were implausible, and the greetings were stock.

Those indicators of current attacks are no longer displayed. The goal in an attack is to make the recipient act first, before looking at the technical indicators.

Technical indications that persist: the domain of the sender does not match up with the domain of the link destination, the link destination URL is suspicious, the attachment type is unexpected. These identify the attacks in all eight types, selecting a “time out” action, such as restriction on an account, payment due date or delivery hold. Eight types of attacks are described below. The two most expensive are BEC and AI-generated targeted phishing. The most common warnings are for account compromise.

The following warning emails and lookalike login pages are examples of the Credential Theft Problem. Here they are.

The business problem is that the volume scale credential harvesting is posing as “legitimate” Microsoft, Google or “big” SaaS security alerts. The attack goal is to have access to a business email or cloud-based accounts with authentication.

The attackers impersonate the sender domain with a lookalike name – microsoft-security.net or microsoftalerts.co as opposed to @microsoft.com or @accountprotection.microsoft.com). The landing page looks the same as the legitimate login page, but is under the control of the attacker. Framing it: a password reset is required, indicated by the term “subject line” (or similar terms) in the subject line of an email. The account will be blocked in 24-hours. Credentials typed on the lookalike page end up with the attacker. The defense selected is Multi Factor Authentication for all Business email accounts. The stolen credentials can’t log in to an account that is protected with MFA. Check the domain a link leads to before clicking it, by placing your cursor over it and comparing it to the sender’s known domain, to make sure the link is legitimate.

Business email compromise and no-link attack emails, also known as the Wire Fraud Problem.

BEC cost US businesses $2.9 billion in 2023, says the FBI Internet Crime Complaint Center annual report. That year it was the top dollar loss of any cybercrime category, out of 21,489 complaints. The three-year run: 2021 ($2.4B, 19,954 complaints), 2022 ($2.74B, 21,832 complaints), 2023 ($2.9B, 21,489 complaints), every year above $2.4 billion.

Executive impersonation or forged vendor email correspondence is the preferred tool of the attacker – no links, no attachments, so it gets around filter on email links. The recognition problem is that the sender address is only one character away from the executive’s actual address, or is a free provider and uses a display name for the executive.

Case 1. His name: Evaldas Rimasauskas. Citizenship: Lithuanian. Scheme: the period 2013 to 2015. Forgery of invoices, contracts and letters pretending to be from hardware vendor. Focus companies: Google & Facebook. Facebook: ~$99 million was transferred. The quantity of funds transferred to Google: around $23 million. Total: roughly $123 million. Indictment Issued: Dec. 2016 in Southern District of NY. Arrest: Lithuania, March 2017.

Extradited to the USA. A guilty plea followed. The sentence was December 2019: 60 months in the U.S. Federal prison. The two firms were later to say they had clawed back most of the money.

Case two is next.

Ubiquiti Networks Inc. of San Jose, disclosed on August 5, 2015. The fraud ran from May 20 to June 5, 2015 – 17 days. It was wire transfer fraud: 14 fraudulent wire transfers through the Hong Kong subsidiary. The amount was $46,703,232. The attacker pretended to be company executives and an outside law firm. $8.1 million was directly recovered. $6.8 million was court-ordered. The net loss was ~$39.1 million (Q4 FY2015). The source is an Ubiquiti SEC 8-K filing from August 2015.

Here is the defense tool selected: call back protocol verification. The callback procedure is: if a request for wire or banking detail change is made, a callback is made to a verified number from existing records, not any number included in the suspicious e-mail.

The Vendor Trust Problem: e-mail invoices and payment diversion are used for the scams.

Business problem: using the services of vendors to defraud the expected payments. Attack sequence: Attacker is able to identify an active vendor relationship. An attack e-mail message is received from one of the domains that are identical, except for one character change or top-level domain change. An e-mail is sent asking for an up-to-date bank account to be given for future payments. The finance staff keeps the payment record up to date. Once the money is transferred to the attacker’s account, it will be the next payment. Then case three. TBC – the parts supplier: Toyota Boshoku Corporation. Disclosure: September 6, 2019. Fraud date: August 14, 2019. Its European subsidiary. Email from a fake contact claiming to be the real person that asks for payment. The amount of transfer: about 4 billion yen. At an estimated cost of $37 million. At the time of disclosure there was a criminal investigation in progress. Publicly named perpetrator does not exist. And then case 4. Leoni AG of Bavaria. German maker of cables and wires for the automotive industry, from Bavaria. Fraud date: August 2016, per the disclosure. Fake President fraud – the German word Fake-Prazidentenbetrug. Attacker sent emails to Leoni’s Romania subsidiary Finance staff in an attempt to steal from them, pretending to be from a high-level correspondent within the company and urging an urgent wire transfer. Losses: estimated to be nearly 40 million euros. No recovery was announced when discovering. The incident was revealed to Leoni on 17th August 2016. The data comes from Reuters, the BBC and the corporate statement from Leoni AG from August 2016. The €40 million reported loss for Leoni is one of the largest BEC losses reported in Europe.

The defense tool used is a verbal confirmation protocol. The banking instructions are different, and require a call to a known name in the vendor, not to the email that sent the instructions for the change.

This is an overview of losses and recovery rates for BECs in the public sector. Here it is. Losses and recovery rates for public-sector BECs: this overview covers them.

Government departments that are the victims of the banking change requests are specific targets of BEC attacks, and the format for change is identical to that used for private-sector BEC. Attacker’s trick – impersonate a financial institution and ask for an update of financial information for government payments.

Case five. This could be an organization such as the Government of Puerto Rico. The fraud timeframe was from the end of 2019 through to the end of January 2020 with $2.6 million of government money transferred. The FBI was notified of this incident in January, 2020. The Associated Press and CyberScoop covered the story on Friday, Feb. 4, 2020. When the government agency targeted, Puerto Rico Industrial Development Company, found the fund transfer to go to fraudulent accounts, they reported to the FBI right after the discovery.

The unit is the FBI Recovery Asset Team. Referred for recovery action in FY2023 was $742 million in BEC wire fraud cases. $433 million of that sum was identified, recovered or frozen. ~58 per cent of the referred amounts is the recovery rate. The faster a case is reported, the sooner a recovery will be made. The domestic and international wire recall procedures have to be implemented within hours of the fraudulent wire.

Routine-Format Problem – shipping notification and HR phishing emails. Here it is.

High-volume routine email formats are expected, and so they reduce suspicion: that is the business problem. The formats that get exploited are package delivery notifications and payroll platform messages.

The shipping notification format. The impersonation is of FedEx, UPS, or DHL delivery alerts. Delivery exception, customs fee, address confirmation: reported. The link sends you to a credential-capture page. Downloaded: malware. The defense is to go to the carrier’s website and enter the tracking number there. Carriers do not take credit card payment by email link before releasing a domestic package, not ever.

HR phishing emails go after the employees that have payroll access. The impersonation is of a company payroll platform, and the platforms are Gusto, Rippling, or ADP. Confirmation of the banking details on a direct deposit change is what gets asked for. Before the next pay cycle, an emergency banking update is told to the employee. Defense: verify on a separate channel. Direct deposit changes are never sent by email link from payroll platforms. Urgent or not, they are not sent. Out-of-band confirmation is required for emailed banking changes, and urgent or not does not matter, with a pay date coming up.

The grammar filter is beaten by AI-generated phishing email examples in 2025 and 2026. That is what the shift to AI tools did.

Grammar-based detection of phishing email examples: done. As a filter: no. AI-produced copy reads the same as legitimate professional correspondence. Cofense researchers recorded the shift in 2024: targeted business phishing campaigns stopped having any grammar tells left.

Grammar has not been a signal since years ago, and is not in 2026 either. Sender domain: still a signal. Link destination URL: so is that. The unusual request pattern counts. And so does urgency framing around a financial transaction or a credential action.

What to do after a phishing incident: that is the Remediation Problem. Here it is.

The business problem is that faster reporting makes for better recovery. Here is how the five-year losses escalated. It was $1.77 billion in 2019 (23,775 complaints). $1.87 billion in 2020 (19,369 complaints). $2.4 billion in 2021 (19,954 complaints). $2.74 billion in 2022 (21,832 complaints). $2.9 billion in 2023 (21,489 complaints). The five-year cumulative loss 2019 through 2023 adds up to around $11.69 billion. Dollar losses grew 64 per cent from 2019 to 2023. Complaints plateaued: 19,000 to 24,000. What that suggests is this: attack sophistication went up, and targeted transaction size went up.

Compromised credentials get changed from a clean device, not the machine that opened the phishing email: that is the immediate response. IT is notified and, if financial fraud occurred, your bank and the FBI IC3 (ic3.gov). The attack email and its headers are documented. In a BEC wire fraud, the sending bank is contacted immediately and a SWIFT recall is requested. Got back: $433 million of the $742 million referred in FY2023, by the FBI Recovery Asset Team. The sooner it is reported, the more is recovered.

Every business email account has MFA on it. Bitwarden is free for individuals. For teams it is $3/user/month. 1Password for business accounts is $4/user/month. Most phishing attempts are caught before delivery, by email filtering in Google Workspace and Microsoft Defender for Office 365. The subscribers do not pay extra for it.

Three characteristics are shared by these phishing email examples from prosecuted BEC cases: sender domain impersonation, urgency language, a payment or credential request. The case documentation above is for this: the three elements are spotted before clicking. Free guidance for businesses that have no security staff: That is CISA’s Small Business Cybersecurity Corner at cisa.gov. Security-adjacent tools worth evaluating are listed in our best AI tools for business guide. Published by the FBI-run IC3 at ic3.gov: the annual BEC and phishing loss numbers. Adapted by the FTC as the attack formats evolve: its phishing guidance. For what changes when a business’s data is compromised, see our general liability insurance cost guide. Here is the list.

Related Posts

Add Comment

More news