How to Spot Phishing in 2026
Security researchers now find AI behind roughly 83 to 86 percent of phishing emails, and the typos that used to give scammers away are gone. What survives is a short list of structural tells that no language model can fix. Here they are in one table, three real-looking messages dissected line by line, the 2025 numbers from the FBI and FTC, and exactly what to do if you already clicked.

- Read time9 min
- Data tables1
- StatusUpdated September 2026
What changed: the numbers
The FBI's Internet Crime Complaint Center logged 1,008,597 complaints in 2025 with $20.9 billion in reported losses, up 26 percent on 2024. Phishing and spoofing was the single most reported crime type at 191,561 complaints. Reported direct losses to phishing were $216 million, which understates it badly: phishing is the entry point for the business email compromise ($3.05 billion), investment fraud ($8.65 billion), and account takeovers that fill the rest of the report. The 2025 report also added an AI category for the first time: 22,364 complaints and $893 million in losses from scams that used AI-generated text, voice, or video. The FTC counted 3 million fraud reports and a record $15.9 billion lost in 2025, with text messages as the most common way scammers made first contact.
On the attacker side, KnowBe4's Threat Lab reported in June 2026 that 86 percent of phishing attacks it observed over the previous six months involved AI assistance. Kaseya's March 2026 email security report put AI-generated content in 83 percent of phishing emails and measured a 54 percent click rate for AI-written lures against 12 percent for the old hand-written kind. Hoxhunt's simulation network saw AI-generated phishing jump from 4 percent to 56 percent of reported attacks in December 2025 alone. The practical conclusion: grammar is no longer evidence of anything.
The red flags that still work
An AI can write flawless English, copy a brand's tone, and personalize a message from your LinkedIn profile. It cannot change where the link goes, which domain the sender controls, or the fact that the scam needs you to act before you think. Those are the tells to check, in this order.
| Check | What a scam looks like | How to check it in 10 seconds | Still reliable in 2026? |
|---|---|---|---|
| Sender's real address | Display name says "Microsoft Account Team," address is [email protected] or a random Gmail | Tap the sender name to expand the full address. On a phone this takes one tap | Yes. The domain is the one thing they cannot fake without owning it |
| Link destination | Text says portal.office.com, link goes to office-portal-login.co or a URL shortener | Hover on desktop; press and hold on a phone to preview. Read the part just before the first slash | Yes |
| Manufactured urgency | "Your account will be suspended in 24 hours," "final notice," "payment failed, update now" | Ask: what happens if I do this tomorrow? Real companies survive a day | Yes. Urgency exists to stop the next check |
| Request for a credential or code | Asks you to sign in, enter a 2FA code, or "verify" card details | No real security alert ever needs your password or a code you were just texted | Yes |
| Unexpected attachment or QR code | Voicemail.htm, Invoice.pdf with a "view" button, a QR code to "re-authenticate" | Treat the QR code as a link you cannot preview. Do not scan it from an email | Yes. QR codes bypass link scanners, which is why attackers use them |
| Channel mismatch | Your bank texts a link; your boss emails from a personal account; HR asks for your password | Ask whether this organization has ever contacted you this way before | Yes |
| Spelling and grammar | Formerly the giveaway | Unreliable either way. Perfect prose proves nothing; a typo in a real email happens | No |
| Generic greeting | "Dear customer" | Weak signal. AI lures now use your name, employer, and recent purchases | No |
The 30-second habit that beats all of it.
Never act on a message through the message. Close it, open the app or type the site address yourself, and look for the alert there. If your bank really flagged a charge, it is in the app. If Microsoft really needs a new password, the prompt appears when you sign in normally. This one rule defeats phishing you cannot detect, including the perfect ones.
Three real-looking examples, taken apart
Example 1: the Microsoft 365 password-expiry email
From: Microsoft 365 Admin <[email protected]>. Subject: Action required: your password expires today. Body: "Hi Dana, your Office 365 password for [email protected] expires in 4 hours. To avoid interruption to Outlook and Teams, keep your current password by verifying it below. [Keep my password]"
- The sender domain is not microsoft.com or your company's domain. Microsoft sends account mail from microsoft.com addresses; your employer's IT sends from your employer's domain.
- The link resolves to a lookalike sign-in page that captures the password and, with a real-time relay, the 2FA code you type next. Passkeys and hardware keys are immune to this; SMS and app codes are not.
- "Keep my password" is the tell. No password system lets you keep an expiring password by re-entering it. The button exists only to collect it.
- Four hours is the urgency lever. Real expiry notices come from your IT team, days ahead, and appear as a prompt at sign-in.
Example 2: the unpaid-toll text
Text from +1 (something) or an overseas number: "E-ZPass Final Reminder: You have an outstanding toll balance of $6.99. To avoid a late fee of $50.00 and suspension of your vehicle registration, settle at ezpass-tollservice.com within 24 hours."
- This exact campaign hit millions of Americans in 2025, run by a phishing-as-a-service operation that Chainalysis and others identify as the Smishing Triad. The same kit produces USPS, FedEx, and DMV variants.
- Toll agencies do not text payment links. Most do not text at all. Checking your balance means opening the toll app or the official site you type yourself.
- The domain is close but wrong, and often changes every few days. The fake page asks for a card number and then a "verification" code, which is the real one-time code your bank sends to approve adding the card to a mobile wallet.
- The small amount is deliberate. $6.99 feels too trivial to be a scam and too annoying to ignore.
Example 3: the AI-written spear phish from your boss
From: your CEO's real name <[email protected]>. "Hi Marcus, great work on the Henderson proposal last week. I am in back-to-back meetings until 5 but need a quick favor: our new vendor Northline needs the attached W-9 and updated banking details confirmed today so their first invoice clears. Can you handle it and confirm to me here? Thanks, Priya."
- The personalization comes from LinkedIn, your company's press releases, and a previous mailbox compromise. AI drafted it in seconds. The flattery lowers your guard; the "in meetings" line prevents you from calling.
- The domain is a lookalike registered last week. Expand the sender. If Priya normally emails from yourcompany.com, this is not Priya.
- "Confirm to me here" keeps you inside the attacker's channel. Business email compromise cost $3.05 billion in 2025 per the FBI, mostly through changed banking details on real invoices.
- The defense is procedural, not technical: any change to payment details is confirmed by phone to a number already on file. No exceptions for executives, and no exceptions for urgency.
2026's growth variants
- QR-code phishing (quishing). A QR code in an email or PDF points to a credential page. Email filters cannot follow it, and your phone camera decodes it outside any corporate protection. Microsoft, Cofense, and Abnormal Security all recorded triple-digit growth in early 2026; Palo Alto Networks' Unit 42 finds about 15 percent of QR codes it crawls lead to malicious sites. Rule: never scan a QR code that arrived in a message.
- Voice cloning. A few seconds of audio from a social video is enough to clone a family member or executive. Set a family code word and treat any urgent money request by phone as unverified until you call back on a known number.
- Shared-document lures. "Priya shared Q3 budget.xlsx" from a real Google or Microsoft notification address, but the document itself contains the phishing link. The notification is real; the document is the trap.
- Browser-in-the-browser pop-ups. A fake sign-in window drawn inside the web page, complete with a fake address bar. Try dragging the pop-up outside the browser window; a real one moves, a fake one cannot.
If you clicked
- Clicked but typed nothing (0 min). Close the tab. Modern browsers and phones make drive-by infection rare. Note the message and expect follow-ups; you have confirmed the address is live.
- Typed a password (10 min). From a different device, change that password now, then sign out of all sessions in the account's security settings. Change it anywhere else you reused it. Turn on two-factor authentication, preferring an app or passkey over SMS.
- Entered a 2FA code or approved a prompt (15 min). Treat the account as taken over. Change the password, revoke sessions and any new app passwords or recovery addresses the attacker added, and check the sent folder and forwarding rules in email.
- Gave card or bank details (20 min). Call the number on the back of the card, report it, and get a new card. Your liability on a credit card is capped at $50 under federal law; on a debit card it is $50 only if you report within two business days.
- Work credentials (now). Tell IT or security immediately. They can revoke tokens and check for lateral movement, and they would much rather hear it in minutes than find it in weeks.
- Report it (5 min). Use the report-phishing button in your mail app, file at reportfraud.ftc.gov, and at ic3.gov if money moved. Forward texts to 7726 (SPAM) on most US carriers.
Warning: the second wave targets people who already fell for the first. After any incident, expect calls from a "fraud investigator" or "recovery service" offering to get your money back for a fee. That is a second scam. Real agencies never charge victims.
The structural fix: switch your email, bank, and password manager to passkeys where offered. A passkey only works on the real domain, so the fake sign-in page in Example 1 collects nothing. It is the one defense that does not depend on you noticing anything.
Quick answers
How can you tell a phishing email in 2026?
Ignore the writing quality; most phishing is now AI-written and reads perfectly. Check the sender's actual address, not the display name. Press and hold or hover on the link to see the real destination. Ask why the message wants you to act in the next hour. Then verify through a channel the message did not give you: open the app yourself, or call the number on the back of your card. If a message survives all four checks it is almost certainly real.
What is the most common phishing trick right now?
Fake sign-in pages for Microsoft 365 and Google, delivered through shared-document alerts, password-expiry notices, and voicemail attachments, remain the top lure. Text-message phishing about unpaid tolls and undelivered packages was the top scam contact method reported to the FTC in 2025. QR-code phishing grew fastest, because a QR code sails through email filters that scan links.
What should I do if I clicked a phishing link?
If you only clicked and closed the page, change nothing but watch for follow-up messages. If you typed a password, change it now from a different device, sign out all sessions in that account's security settings, and turn on two-factor authentication. If it was a work account, tell IT immediately; speed matters more than embarrassment. Report the message to your email provider and at reportfraud.ftc.gov, and file at ic3.gov if you lost money.
Sources
- FBI Internet Crime Complaint Center: 2025 Internet Crime Report, complaint counts and losses by crime type (April 2026)
- FBI: Cryptocurrency and AI scams bilk Americans of billions, 2025 report summary (April 2026)
- FTC: Testimony on 2025 fraud reports, $15.9 billion in losses and top contact methods (March 2026)
- KnowBe4 Threat Lab: 86 percent of phishing attacks involve AI assistance (June 2026)
- Kaseya INKY 2026 Email Security Report summary: 83 percent AI-generated, 54 versus 12 percent click rates (April 2026)
- CISA: Recognize and report phishing, current red flags (September 2026)
- Chainalysis: 2026 Crypto Crime Report, the E-ZPass smishing campaign and the Smishing Triad (January 2026)


