4 Email Phishing Scams to Avoid

4 Email Phishing Scams to Avoid

Before you go wading into all your unread emails from over the holidays, it’s a good idea to brush up on phishing email scams, which can lead to financial loss, compromised accounts, identity theft, ransomware infection and insecure data.

Before you go wading into all your unread emails from over the holidays, it’s a good idea to brush up on phishing email scams, which can lead to financial loss, compromised accounts, identity theft, ransomware infection and insecure data. Phishing has been around a long time, but as technology and cybersecurity evolve, so do scammers and their phishing techniques. Here are four types of phishing emails to be wary of and tips to avoid being a victim of phishing.

Deceptive Phishing: Deceptive phishing is the most common type of phishing scam, in which scammers carefully impersonate or “spoof” a real company’s correspondence and attempt to steal users’ personal information or login credentials. These emails frequently use urgent-sounding language to startle users into following through on their directive, often related to resolving a “problem” with an account. Deceptive phishing emails not only spoof legitimate companies to target users, they often direct the victim to resolve the imaginary account issue by clicking through and logging into a matching spoofed website, allowing the phisher to collect their personal information and account login information. Deceptive phishing attacks can imitate companies such as PayPal, internet service providers, banks or credit card companies.

Cloud Storage Phishing: Scammers are now basing many attacks off of Cloud storage services such as Dropbox or Google Drive. This kind of phishing scam usually involves a realistic-looking spoofed email claiming to come from a Cloud storage service and requesting the user to click through to secure an account or download and view a shared document. When the user clicks through, they’re directed to a spoofed login page that harvests the user’s account credentials for the phisher.

IRS Phishing: A more recent type of phishing attack is IRS-related phishing, in which criminals disguise a phishing email to employees in human resources or payroll departments so that it appears to come from a company executive. Phishers do this to request information such as employees’ W-2 data or even social security numbers from companies. These phishing scams are particularly dangerous because the Form W-2 contains an employee’s name, address, Social Security number, income and withholdings, all of which compromises personal identity and data security and can be used to file fraudulent tax returns or even be sold on the Dark Net.

Spear Phishing: Spear phishing is a more personalized type of email scam, in which fraudsters may gather information on a victim over time via social media like LinkedIn, through data breaches or simply by gathering intel via some kind of hack. They then use this information to lend credibility to their phishing email for a specific target. Spear phishing attacks are called such because instead of casting a wider, indiscriminate net, they specifically target high-value victims—even top executives. In “whaling” attacks, the goal is to target executives to steal their login credentials, after which a scammer can conduct CEO fraud by impersonating the victim and abusing their credentials to authorize fraudulent wire transfers.

How to Avoid Being Phished

  • Examine emails closely for inaccuracies or inconsistencies in greetings, headers, signatures or email addresses. If things seem off, it’s a good sign to not trust the sender.
  • Don’t give out personal, company or financial information via email and don’t respond to email solicitations for this information or follow links in these emails.
  • Pay attention to the URL of a website—malicious or phishing websites may replicate a legitimate site well but their URL may use a variation in spelling or a different website domain.
  • Don’t open or download email attachments from senders you don’t recognize—again, check the sender’s email address to verify that the spelling and domain are consistent with who they say they are. Because of the possibility of real but hacked email accounts, you should never download suspicious-looking email attachments from people you DO know.
  • Use two-factor verification on accounts where possible.
  • Install and maintain antivirus software, firewalls and email spam filters to reduce the likelihood of phishing attacks coming through.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • New Research Reveals Global Video Surveillance Industry Perspectives on AI

    Axis Communications, the global industry leader in video surveillance, has released its latest research report, ‘The State of AI in Video Surveillance,’ which explores global industry perspectives on the use of AI in the security industry and beyond. The report reveals current attitudes on AI technologies thanks to in-depth interviews with AI experts from Axis’ global network and a comprehensive survey of more than 5,800 respondents, including distributors, channel partners, and end customers across 68 countries. The resulting insights cover AI integration and the opportunities and challenges that exist with regard to security, safety, business intelligence, and operational efficiency. Read Now

  • SIA Urges Tariff Relief for Security Industry Products

    Today, the Security Industry Association has sent a letter to U.S. Trade Representative Jamieson Greer and U.S. Secretary of Commerce Howard Lutnick requesting relief from tariffs for security industry products and asking that the Trump administration formulate a process that allows companies to apply for product-specific exemptions. The security industry is an important segment of the U.S. economy, contributing over $430 billion in total economic impact and supporting over 2.1 million jobs. Read Now

  • Report Shows Cybercriminals Continue Pivot to Stealthier Tactics

    IBM recently released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks. Read Now

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.