Your phone buzzes at 6:40 on a Tuesday morning with a message saying your power bill is past due and service will be cut off today. The logo looks right. The sender name looks right. Nothing feels strange until you notice the reply address ends in something like .info. That is a phishing email, and every part of it was built to make you act before you think.

Phishing is not new. What changed is how cheap and fast the fakes became. AI writing tools turn out clean, grammar-perfect messages in seconds. A scammer can copy a real brand’s tone, build a working fake login page, and send thousands of variations in an afternoon. Some messages pull details from old data breaches and public profiles, so your first name, your employer, and your city all land in the right places.

The scale is large. The FBI’s Internet Crime Complaint Center has recorded phishing and spoofing as the most-reported internet crime in the United States for several years running, and its most recent report put total internet crime losses at about $16.6 billion in a single year. The FTC reported that consumers lost roughly $12.5 billion to fraud in 2024 as well. You can file a complaint through the FBI IC3 if you get hit. This guide walks through the most common phishing email examples one at a time and points out the exact detail that gives each one away.

Phishing Email Type What It Pretends to Be The Tell That Gives It Away Safest Move
Overdue bill Your utility or internet provider Threatens same-day shutoff and asks for payment by link Log in to your real account to check the balance
Failed delivery A shipping carrier Small redelivery fee and a link on a non-carrier domain Track the package on the carrier’s official site
Bank security alert Your bank or card issuer Asks for a password or one-time code to review a charge Open the bank app and call the number on your card
Payment app request Zelle, Venmo, or Cash App Claims a payment needs approval, which is not a real step Ignore it and check the app directly
Vendor invoice change A supplier or contractor New bank details arrive with no phone call Call the vendor at a number you already have
Subscription renewal Antivirus or cloud storage Large auto-renewal fee plus a support number to call Do not call; find the plan in your real account

What Do Real Phishing Emails Actually Look Like?

A person frowning at a smartphone screen while reading an email at a kitchen table

Most phishing emails are rewrites of a handful of scripts. Learn the shapes and you will spot them in a few seconds. The versions below show up in inboxes every single day.

The overdue bill is the oldest trick still working. A message claims your power, water, or internet service will shut off today unless you pay right now. Real utilities send paper notices and give weeks of warning, not hours.

The fake delivery notice is close behind. A carrier you actually use says a package is stuck and needs a small redelivery fee. Two dollars feels harmless, so people type in a card number without thinking twice. That card number is the whole point.

Then there is the shared document. A file labeled Invoice or Payroll arrives from a name you almost recognize, with a note saying you must sign in with your email password to view it. The login page is fake, and your credentials go straight to the attacker. For a deeper breakdown of the technical tells, see our guide to identifying AI phishing emails.

  • The overdue bill: ‘Service will be disconnected in 12 hours.’ Real utilities do not threaten same-day shutoff by email.
  • The failed delivery: A $2.99 redelivery fee that exists only to capture your card number.
  • The shared document: A file you must ‘sign in to view,’ which harvests your email password.
  • The payroll request: A message that looks like it came from your boss or HR asking for bank details or gift cards.
  • The account alert: ‘We blocked an unusual login.’ The button leads to a copy of the real login page.

Why Are AI-Written Phishing Emails So Much Harder to Catch?

For about twenty years, bad grammar was the easiest way to spot a fake. Typos, broken sentences, and odd capitalization gave the game away. AI writing tools erased that signal almost overnight. A scammer with no English skills can now produce a message that reads better than most real corporate email.

Volume is the second change. Someone with a chatbot can draft fifty versions of the same pitch in an hour and test which one gets clicks. Personalization is the third. Details pulled from old breaches and public profiles get dropped straight into the text. Your first name, your employer, the city you live in, and even your manager’s name can all appear in a message that is entirely fake.

The fake pages improved too. Modern chat tools can write working HTML for a login screen in minutes, complete with your bank’s colors and logo. Some campaigns now add a short voice note or video clip. That is why our breakdown of AI voice cloning scams and deepfake video scams belongs in the same conversation as email. The channel changes, the playbook does not.

So stop grading emails on how polished they look. Clean writing is now the default, not a sign of trust. Verify the request through a second channel instead, using the steps in how to verify AI versus human.

Which Phishing Emails Target Your Bank or Payment App?

A hand holding a bank card beside an open laptop displaying a login screen on a desk

Financial phishing carries the biggest payoff, so the fakes are the most polished. The classic version is a security alert. It says the bank blocked a charge you did not make, usually a round number like $1,249.00 from a store you might actually shop at. A button labeled Review Transaction leads to a page that asks for your username, password, and the six-digit code just texted to your phone.

Payment apps are a favorite target because transfers are instant and hard to reverse. Watch for messages claiming a Zelle, Venmo, or Cash App payment is pending and needs your confirmation. There is no such confirmation step. Approving it just sends your money out the door.

Crypto phishing follows the same pattern with higher stakes. A fake exchange or wallet provider says your account is under review and asks you to verify your seed phrase. No legitimate service will ever ask for a seed phrase. Our article on AI investment scams and crypto fraud covers the longer versions of this con, which often start with a friendly message rather than a threat.

One rule covers all of it. Never log in to a financial account by clicking a link in an email or text. Open the app, or type the address yourself. If you already handed over details, move fast and consider a credit freeze using the steps in freezing your credit after AI identity theft.

How Do Delivery and Invoice Phishing Emails Trick People?

Low-stakes phishing works because the amount feels too small to worry about. A $1.99 shipping fee, a $4.95 customs charge, a $12 storage bill. Nobody calls the bank over twelve dollars, so the scam runs quietly for months and collects thousands of card numbers. The dollar figure is bait, not the goal.

Invoice fraud targets workplaces instead of individuals. An email arrives from a supplier, a law firm, or a contractor saying their banking details have changed. The message is polite, references a real project, and includes a new account number. A finance team that pays it sends company money straight to a scammer. The FBI tracks this as business email compromise, and it remains one of the costliest categories of internet crime year after year.

Subscription renewal scams take the opposite approach. They use a big number to create panic. A message says your antivirus or cloud storage plan will auto-renew for $499 in 24 hours unless you call a support line to cancel. That phone number reaches a call center that walks you through installing remote access software. Once they are on your computer, they can see your accounts and your balance.

Older adults often face the heaviest version of this pressure, mixed with a friendly voice on the phone. Our guide to protecting elderly parents from AI scams walks through the conversations worth having before something happens.

What Red Flags Show Up in Almost Every Phishing Email?

A close up of a hand hovering over a laptop trackpad while reading an email on the screen

Red flags stack up. A single one might mean nothing. Three in the same message is a scam, almost every time.

Look at the full sender address first, not the display name. On a phone, tap the name to expand it. Real companies use their own domain, so a message from Chase Support should not arrive from a Gmail or outlook.com address. Watch for small swaps too, like paypa1.com with a number one, or rnicrosoft.com with an r and an n standing in for the letter m.

Check where links actually go before you click. Hover over the button on a computer and the real destination appears at the bottom of the window. If the words say chase.com and the address is something like chase.secure-login.info, you have your answer.

Read the request itself. Legitimate companies do not ask for passwords, full card numbers, one-time codes, or seed phrases by email. They do not ask you to pay a bill in gift cards, crypto, or a wire transfer either. Those methods are chosen because they cannot be reversed.

Then there is tone. Urgency with a deadline measured in hours is a manufacturing trick, not a real business practice. So is a sudden push to move the conversation to text, WhatsApp, or a personal phone number. When something feels off, take two minutes to check it. Open the company’s app or type its address into a new browser tab. Call the number printed on your card or statement, never the one in the message. Read the email out loud to another person and watch their face. Above all, do not reply to ask whether it is real. A reply confirms your address is live and puts you on more lists.

  • Reply-to address does not match the display name or the company domain.
  • Domain is close but wrong: paypa1.com, rnicrosoft.com, amazon-billing.net.
  • A deadline measured in hours, not days.
  • A request for a password, one-time code, full card number, or seed phrase.
  • The link text and the real destination do not match.
  • An attachment you did not ask for, especially .htm, .html, or .zip files.
  • Payment requested in gift cards, crypto, or a wire transfer.

First, breathe. Clicking a link does not automatically mean your accounts are gone. What matters is how fast you act and whether you typed anything in. Here is the order that limits the damage.

If you only opened the page and closed it, change that account’s password anyway, then clear your browser history and run a security scan. If you entered a password, change it immediately from a different device. If you entered a card number, call the number on the back of the card and ask for a replacement. If you gave someone remote access to your computer, disconnect from the internet, uninstall the remote software, and call your bank from a different phone.

Add two-factor authentication to every account that offers it, and choose an authenticator app or a hardware key over text messages. Codes sent by SMS can be intercepted or talked out of you by a fake support agent. Then look for changes you did not make. Check email forwarding rules, recovery phone numbers, and unfamiliar devices in your account settings.

Report what happened. The FTC’s identity theft site builds a free personal recovery plan, and you can file a report with the FBI’s Internet Crime Complaint Center. Our step-by-step walkthrough on how to report an AI scam covers what to include so the report is actually useful.

Finally, tell the people around you. If the scam used your email account, warn your contacts before the next message goes out under your name.

Frequently Asked Questions

How can I tell if an email is phishing or real?

Expand the full sender address and check the domain, then hover over any link to see where it really goes. Real companies do not ask for passwords, one-time codes, or seed phrases by email. When in doubt, open the company’s app or type its address yourself instead of clicking.

What are the most common phishing email examples right now?

Fake overdue utility bills, failed delivery notices with a small redelivery fee, bank security alerts about a charge you did not make, shared document invites that require a login, vendor invoice changes, and subscription renewal warnings with a support number to call.

Can a phishing email come from an address I actually know?

Yes. If a friend or colleague’s account gets compromised, real messages can come from their real address. Display names are also easy to fake, which is why you should check the domain rather than the name shown in your inbox.

What happens if I open a phishing email but do not click anything?

Usually nothing. Simply opening a message rarely harms you. Some emails load tracking images that confirm your address is active, so avoid clicking links or downloading attachments, and delete the message.

Should I reply to a phishing email and ask them to stop?

No. Replying confirms that a real person reads that inbox, which often leads to more messages. Delete it, or forward it to the company’s fraud team if you want to report it.

Do phishing emails only target older adults?

No. FTC data show adults in their twenties report losing money to fraud at higher rates than adults in their seventies, though older adults tend to lose larger amounts when they do fall for a scam. Everyone is a target.

What Should You Remember?

  • Never log in through a link in an email. Open the company’s app or type the address yourself.
  • Check the full sender address, not the display name, by tapping it on your phone.
  • Treat urgency as a warning sign. Deadlines measured in hours are manufactured, not real.
  • No legitimate company asks for passwords, one-time codes, or crypto seed phrases by email.
  • Verify by phone using the number on your card or statement, never the one inside the message.
  • Act within minutes if you entered credentials: change the password from a different device and turn on two-factor authentication.
  • Report it to the FTC and FBI IC3 so the next version of the scam is easier to trace.

This article is for general educational information only and is not legal, financial, or professional security advice. Scam tactics evolve quickly, so verify current guidance with official sources like the FTC, FBI IC3, or CISA before acting. Some links may be affiliate links that support this site at no cost to you.