Data Protection & Information Security
20 Jan 2026

Recognizing phishing: 8 warning signs for employees

Bridgly Editorial Team
Reading time:
7
minutes
Employee at a laptop in a bright office checking a suspicious phishing email with a warning notice
Table of contents

Why phishing is the most important awareness topic

Phishing refers to the attempt to obtain login credentials, payments, or confidential information through fake emails, websites, or messages. Being able to recognize phishing is therefore one of the most important everyday skills in the area of data protection & information security. It is by far the most common entry point for attacks: ENISA identifies phishing in the Threat Landscape 2025 as the leading initial access vector – around 60% of the observed cases begin with it. The BSI's 2025 report on the state of IT security also confirms the tense threat situation; a large proportion of ransomware attacks affect small and medium-sized enterprises.

Because attacks hinge on a single careless click, trained employees are the most effective line of defense – technical filters are far from catching every message. A single person who exposes a fake message for what it is can prevent attackers from gaining access to accounts, networks, or payment flows. The following eight warning signs help to expose suspicious messages in everyday life. Important: No single sign is proof on its own, but the more of them come together, the higher the probability of a fraud attempt. The concrete examples for each point show what the respective scam looks like in practice – and make recognizing it in hectic everyday work much more tangible. Anyone who has internalized the patterns once will notice them even when a message seems completely unsuspicious at first glance.

The 8 warning signs by which you can recognize phishing

  1. Urgent pressure to act and threats. "Your account will be blocked in 24 hours" or "final reminder": Phishing deliberately creates time pressure and fear so that recipients act before they think. Reputable organizations rarely set such short ultimatums. A typical example is an alleged parcel notification that demands a small "customs fee" within two hours – otherwise, it claims, the shipment will be sent back. Anyone who consciously notices the pressure being created and pauses briefly has already taken the decisive step toward exposing it. Rule of thumb: The more urgent a message sounds, the more calmly you should react.
  2. Requests to enter confidential data. Banks, public authorities, and service providers never ask for passwords, PINs, or complete credit card details by email or via a link. That is precisely the core goal of every phishing email. A common pattern: An email in bank design asks recipients to "confirm" their login credentials along with a TAN via a linked form because of an alleged "security check". No genuine institution requires anything like this – if in doubt, contact the bank via the official app or a website address you type in yourself, never via the link in the message. A request to pass on codes from an authenticator app is also a clear alarm signal.
  3. Fake or mismatched sender address. The displayed name looks familiar, but the actual address behind it does not match the organization (e.g., additions, swapped characters, or an unfamiliar domain). A look at the real sender address is always worthwhile. Instead of "service@paypal.de", the actual sender behind it is something like "service@paypal-sicherheit.info" – visible only when you expand the sender or hover over it with the pointer. Swapped letters such as "rn" instead of "m" are similarly treacherous, as they are hardly noticeable at a quick glance.
  4. Links that lead somewhere else. Hover the mouse pointer over a link without clicking: If the target URL that appears points to a different or cryptic address, caution is advised. It is better to open login pages manually in the browser. An example: The visible link text reads "www.microsoft.com/login", but the target URL actually stored behind it points to an unfamiliar domain such as "ms-login-secure.xyz". On a smartphone, a long tap on the link helps to display the real destination. Shortened links or addresses with many special characters are an additional warning sign.
  5. Unexpected attachments. Invoices, job applications, or delivery notifications that you are not expecting may contain malware – especially Office files with macros or executable files. If in doubt, do not open them. Classic examples are a ZIP archive named "Invoice_outstanding.zip" or a Word document that, after opening, prompts you to "enable editing to view the content" – that is, to switch on macros, which then execute malicious code. Anyone who was not expecting an invoice or application should briefly check via a known channel whether the sender really sent the file.
  6. Impersonal or inappropriate greeting. "Dear Customer" from a provider who knows your name is a warning sign. Conversely, a correct greeting does not rule out phishing – targeted attacks research names in advance. A typical example is the message "Dear User, your mailbox has reached its storage limit", even though the real provider otherwise always addresses you by your full name. It is also conspicuous if the message suddenly switches to an informal form of address or is written in a completely different style than usual.
  7. Unusual requests from known senders. In spear phishing, attackers pose as a colleague, supervisor, or partner. An atypical request – such as an urgent, confidential bank transfer – should be verified via a second channel. In practice, such an email seems to come from management: "Are you at your desk? Please get some gift cards at short notice and send me the codes – I'm in a meeting and can't be reached." A quick call to the known number exposes the fraud.
  8. Requests for payments or account changes. In Business Email Compromise (BEC) or CEO fraud, attackers request bank transfers or changed bank details. Such instructions always require approval via a verified, second route. A widespread example: A supposed supplier reports "new bank details" by email and asks for the next outstanding invoice to be transferred to the changed account – the money goes straight to the attacker. A firm principle should be: Changed bank details are never confirmed by email alone, but always cross-checked by phone using a known number.

Irregularities in the overall picture – but be careful with spelling. Logos, layout, or tone can seem inconsistent, for example a slightly distorted company logo, an inappropriate subject line, or an unusual closing. Important: The BSI expressly points out that spelling and grammar mistakes are no longer a reliable indicator – modern, partly AI-generated phishing emails are often error-free and professional. You should therefore rely on the content-related signals, not on a typo.

What should you do if you suspect phishing?

The most important rule is: If in doubt, do not click, do not open attachments, do not enter any data. Suspicious messages are not simply deleted but forwarded to the IT department or an internal reporting address – this way, the company can recognize patterns and warn others before the campaign causes greater damage. If in doubt, it is also worth calling back the supposed sender using a known phone number you have looked up yourself – never using the contact details from the suspicious message. A quick call to check with the colleague whose name appears under an unusual request also takes only a minute and, if in doubt, prevents a costly mistake.

If someone has already clicked or entered a password, speed counts: inform IT immediately, change the affected password, and – where possible – log out of existing sessions. Anyone who has entered login credentials on a fake page should also change the same password everywhere else it is used. An open error culture is crucial here, because anyone who is afraid of reporting does not report – and then an attack may go unnoticed until it is too late. That is exactly why every good awareness concept includes the message: Reporting is welcome and will not be punished. Anyone who reports protects not only themselves but the entire team from the next wave of the same campaign.

From individual cases to a system: protecting employees permanently

Knowing individual warning signs is the first step. Defenses only become robust when recognizing and reporting are practiced regularly – for example, in a structured security awareness program with recurring learning units and phishing simulations. Why people are at the center of IT security is explained in the article What is security awareness?. There is no such thing as complete protection, however. A note on our own behalf: Bridgly bundles ready-made, standardized phishing and awareness training courses that drill exactly these warning signs in its data protection and information security training courses. This turns individual knowledge into a lived routine that employees can rely on in an emergency. What remains crucial is to ask if in doubt and to report suspected cases.

FAQ

What is the difference between phishing and spear phishing?

Classic phishing is widely distributed and identical for many recipients – for example, a fake parcel or bank message sent to thousands of addresses. Spear phishing, on the other hand, is targeted: Attackers research the name, role, and environment of a specific person in advance and write the message individually. This makes it seem more credible and much harder to recognize.

What is Business Email Compromise (BEC)?

In BEC – also called CEO fraud – attackers pose as a manager, colleague, or business partner and initiate urgent bank transfers or changes to bank details. The messages often look deceptively genuine and rely on time pressure and authority. Protection is provided by a fixed approval process in which such instructions are always confirmed via a second, verified channel.

Are spelling mistakes a sure sign of phishing?

No. The BSI expressly makes clear that spelling and grammar mistakes are no longer a reliable indicator. Many phishing emails today are linguistically flawless and professionally designed, partly because generative AI helps write them. You should therefore not rely on mistakes, but on the content-related warning signs such as time pressure, suspicious links, and unusual requests for data.

What should employees do after a click?

Inform the IT department immediately, do not make any further entries, and change affected passwords – also everywhere else the same password is used. Where possible, log out of existing sessions. The faster the report is made, the sooner the damage can be limited. Important: It should be possible to report without fear of consequences and without assigning blame.

Sources

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.