The five email attack patterns worth watching in 2025 are AI-polished credential phishing, QR-code phishing (quishing), business email compromise, device-code phishing, and targeted impersonation or spear phishing. They overlap: a payment scam may use an AI-written message, a QR code, or a stolen mailbox. What unites them is an attempt to make a risky action feel routine—sign in, scan, approve, send money, open a file, or disclose a code.
This is a practical selection, not a measured ranking or an authoritative list of the five most common attacks worldwide. The observations below combine 2025 reporting with security guidance reviewed in 2026.
The five patterns at a glance
| Attack | Typical action requested | Primary risk | Best immediate check |
|---|---|---|---|
| AI-polished credential phishing | Click a sign-in link or reply to start a conversation | Stolen passwords or sessions | Open the service through a known bookmark or app, not the message |
| QR-code phishing | Scan a code in an email, image, or document | Hidden or redirected credential theft | Inspect the destination and refuse unexpected scans |
| Business email compromise | Change payment details, transfer funds, or send sensitive data | Fraudulent payment or data loss | Confirm through a previously known phone number or channel |
| Device-code phishing | Enter a supplied code into a legitimate authorization page | Attacker access to the account | Never enter an unsolicited code; contact IT independently |
| Targeted impersonation and spear phishing | Trust an apparent colleague, executive, official, or partner | Account takeover, fraud, or disclosure | Verify identity and unusual requests outside the message thread |
1. AI-polished credential phishing
Generative AI lets attackers produce fluent, personalized messages quickly. Microsoft Threat Intelligence has reported threat actors using large language models to support social-engineering operations, including drafting phishing emails. Microsoft also described a suspected AI-generated campaign in which an initial message encouraged a reply and a later message supplied a link to an adversary-in-the-middle phishing site.
The important change is not that every suspicious email is written by AI. It is that grammar, spelling, and a convincing tone are weaker evidence than they used to be. A message can sound like your supplier, manager, or help desk while its link sends you to a page that relays credentials to the attacker.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
How to check one
- Do not use the email’s sign-in button. Open the service from a saved bookmark, the official app, or a manually typed address.
- Hover over links on a computer and examine the complete domain. On a phone, use the browser’s link preview or avoid the link entirely.
- Be cautious when a harmless conversation suddenly becomes a request to authenticate, download, or provide information.
- Report the message even when the wording looks professional; reporting helps your organization block related messages.
2. QR-code phishing (quishing)
Quishing hides a destination inside a QR code placed in an image, PDF, or email. Scanning moves the interaction to a phone, where the destination may be harder to inspect before it opens. Microsoft documented QR codes directing targets to adversary-in-the-middle phishing pages, including a spear-phishing sequence that used a broken code followed by a legitimate WhatsApp device-linking code.
Proofpoint identified 4.2 million QR-code threats in the first half of 2025. That is Proofpoint’s observed threat volume, not a count of confirmed victims or an industry-wide total.
Safer scanning habits
- Treat an unexpected QR code that asks you to sign in, approve access, or update payment information as a link you would not click.
- Preview the URL before opening it. A familiar logo or a page that looks like Microsoft, Google, or your bank does not establish authenticity.
- If a code fails and a second code appears, stop rather than following a new device-linking or verification instruction.
- For workplace requests, navigate to the service yourself or ask the sender through a known channel.
3. Business email compromise (BEC)
BEC attacks manipulate a business process rather than merely stealing a password. Criminals impersonate an executive, supplier, lawyer, or employee—or use a compromised mailbox—to request a wire transfer, change invoice details, send payroll information, or disclose sensitive files. Microsoft describes BEC as a professionalized criminal economy that uses stolen inboxes and credentials to scale payment fraud and account takeover. Lookalike domains and spoofing can make the request appear to come from a real business.
A familiar display name, an ongoing thread, or a real colleague’s compromised account is not authorization for a financial change. Payment instructions deserve a separate verification step.
Free tools Windows power users keep installed
One-click scans. No signup required.
Use an independent approval path
- Pause any request that changes bank details, urgency, beneficiaries, payroll, gift cards, or a large payment.
- Contact the requester using a phone number, directory entry, or previously used address already on file—not the contact details in the message.
- Have a second authorized person review the change under your organization’s payment policy.
- Preserve the original message and report suspected fraud to finance, IT, or security immediately.
4. Device-code phishing and authorization abuse
In device-code attacks, the email sends you to a genuine Microsoft authorization flow and supplies a code to enter. The page may be legitimate; the authorization is not. By entering the attacker’s code, you can approve a device or session that gives the attacker access to your Microsoft 365 account.
Proofpoint reported multiple state-aligned and financially motivated threat clusters using this method against Microsoft 365 accounts. A legitimate sign-in or verification page therefore cannot, by itself, prove that the request is safe.
The rule for unexpected codes
Never enter a code supplied in an unsolicited email or during an unexpected sign-in. The FBI’s 2025 advisory states: “Never provide a two-factor code to anyone over email, SMS/MMS text message or encrypted messaging application.” If a work prompt appears unexpectedly, close it and contact IT through your normal help-desk address or phone number.
5. Targeted impersonation and spear phishing
Spear-phishing messages are tailored to a person, role, organization, or current task. Attackers may study public profiles, previous correspondence, calendars, suppliers, and organizational language before making contact. The FBI’s 2025 advisory describes malicious actors impersonating senior U.S. officials and using messages and other channels to build rapport before seeking account access.
These lures often avoid obvious errors. The warning sign is the requested action and the pressure surrounding it: secrecy, urgency, a new communication channel, an unusual attachment, or a request to bypass normal approval.
Verify the person, not just the message
- Call the person using a known number or start a new conversation in your normal collaboration tool.
- Ask for confirmation of the specific request, not merely whether they sent “an email.”
- Do not reply to the suspicious thread, click its links, or use its attachments to perform the check.
- Be alert when the same identity appears across email, text, social media, or messaging apps; cross-channel impersonation is still impersonation.
Why ordinary email clues are no longer enough
Proofpoint’s 2025 Human Factor Vol. 2 findings reported that URLs were used four times more often than attachments in malicious emails, within the scope of that report. A clean-looking message with no attachment can still be dangerous. Sender names, logos, reply threads, and legitimate cloud-hosted pages are all easy to imitate or abuse.
Microsoft Incident Response reported that phishing or social engineering initiated 28% of breaches in its 2025 Digital Defense Report breach set. That figure describes Microsoft’s incident set, not a universal share of breaches across every industry.
Protection that covers the different risks
For everyone
- Enable multi-factor authentication and never disclose an MFA code.
- Prefer phishing-resistant MFA where the service supports it. CISA identifies FIDO/WebAuthn methods and physical security keys as strong options; number-matching authenticator prompts can be an interim control in some environments.
- Use a password manager and unique passwords so a stolen password cannot unlock multiple services.
- Keep browsers, phones, and mail apps updated, and use built-in reporting controls for suspicious messages.
For organizations
- Publish a clear, fast reporting route and make it acceptable to pause a payment or access request.
- Require independent confirmation for payment-detail changes and high-value transfers.
- Deploy phishing-resistant MFA where compatible, with enrollment, replacement, and account-recovery procedures.
- Combine technical filtering with recurring security-awareness training. A security key protects authentication; it does not by itself stop BEC or a fraudulent payment-authority request.
What to do after a suspicious click or approval
- Stop interacting with the message. Do not continue a conversation with the sender.
- For a work account, contact IT or security immediately through a known route and explain exactly what you clicked, scanned, entered, or approved.
- Change affected credentials from a trusted device, revoke unfamiliar sessions or app grants if your service provides that control, and follow your organization’s incident process.
- Contact your bank or payment team urgently if money or account details were involved.
- Keep the message, headers, URLs, screenshots, and timestamps for investigators; do not forward sensitive material broadly.
The Bottom Line
Assume that a polished message, familiar sender, QR code, or genuine sign-in page can still be part of an attack. Verify the requested action through a separate trusted channel, never share authentication codes, and use phishing-resistant MFA where your accounts support it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

