The 10 Most Common Phishing Lures in 2026: And How to Spot Them

Phishing works because it looks familiar. An email from Microsoft. A text from Royal Mail. A security alert from your bank. The brand is one you recognise, the message sounds plausible, and before your guard goes up, you’ve clicked.
Attackers know this. In Q2 2026, Microsoft alone appeared in 23% of all brand phishing attempts tracked globally, nearly one in four phishing campaigns is impersonating a single company. The top five brands; Microsoft, LinkedIn, Google, Apple, and Amazon, together account for more than half of all brand phishing activity worldwide.
Understanding which lures are being used right now, and what gives them away, is the most practical phishing defence available. Here are the 10 most common phishing lures in 2026 and exactly how to spot each one.
1. Microsoft 365: “Your password is expiring” / “Unusual sign-in detected”
Why it works: Microsoft is the most impersonated brand in phishing attacks worldwide in 2026, accounting for 23% of all brand phishing attempts in Q2 2026. With over 400 million Microsoft 365 users globally, the chances of hitting an active user with a Microsoft-themed lure are extremely high. A Microsoft 365 credential is also uniquely valuable — it unlocks email, files, Teams, and identity across an entire organisation.
What the lure looks like:
- “Your Microsoft 365 password will expire in 24 hours. Click here to update it.”
- “We detected an unusual sign-in to your account from [city]. If this wasn’t you, secure your account immediately.”
- “Your Microsoft Authenticator registration has expired. Re-register now to avoid losing access.”
- A SharePoint notification telling you someone has shared a document — clicking opens a fake OneDrive login page.
How to spot it:
- The sender domain is not @microsoft.com — look for variations like @micros0ft.com, @microsoft-security.net, @account-microsoft.com
- Hover over any link before clicking — the URL will show a domain that is not microsoft.com
- Microsoft never emails you asking for your password or to click a link to avoid account suspension
- Genuine Microsoft security alerts appear inside the Microsoft 365 security portal — go there directly by typing portal.microsoft.com in your browser, never by clicking an email link
- Check the email header — legitimate Microsoft emails are sent from microsoft.com with valid DKIM signatures
2. HMRC: “You have a tax refund waiting” / “You owe an overdue tax payment”
Why it works: HMRC is the most impersonated UK government body in phishing campaigns. Tax refund lures are timed to peak around self-assessment deadlines (January 31) and the end of the tax year (April 5), when millions of people are genuinely expecting communication from HMRC. The combination of money owed or money to claim creates urgency that bypasses rational thinking.
What the lure looks like:
- “HMRC: You are entitled to a tax refund of £342.50. Claim your refund here.”
- “HMRC: You have an outstanding payment of £800. Failure to pay may result in legal proceedings.”
- Fake HMRC Government Gateway login pages that harvest your credentials and National Insurance number.
- Text messages with shortened URLs claiming to be from HMRC.
How to spot it:
- HMRC will never contact you by email or text to offer a refund — refunds are processed automatically or through your Government Gateway account
- HMRC will never threaten immediate legal action by text or email
- Genuine HMRC emails come from @hmrc.gov.uk — no other domain
- HMRC specifically warns that it will never ask for payment by gift card, iTunes voucher, or cryptocurrency
- Report HMRC phishing to phishing@hmrc.gov.uk and forward suspicious texts to 60599
3. Royal Mail: “Your parcel could not be delivered”
Why it works: The UK ships millions of parcels every day. A missed delivery notification is something almost every person expects at some point, making Royal Mail one of the most effective UK-specific lures. The lure typically demands a small redelivery fee — £1.99 or £2.99 — which lowers the victim’s resistance. But the real goal is capturing full payment card details.
What the lure looks like:
- “Royal Mail: Your parcel [tracking number] could not be delivered. Pay £1.99 to reschedule delivery.”
- Text messages with Royal Mail branding and a link to a convincing fake Royal Mail payment page.
- Emails claiming customs duty is owed on an international parcel.
How to spot it:
- Royal Mail never charges redelivery fees by email or text for standard parcels
- The sender will be a personal email address or a domain unrelated to royalmail.com
- Genuine Royal Mail tracking is available at royalmail.com — always go there directly
- The payment page will ask for far more card details than a legitimate £1.99 payment requires — attackers are capturing your full card number, expiry, and CVV
- If you’re expecting a parcel, track it directly at royalmail.com rather than clicking any link
4. PayPal: “Your account has been limited” / “Suspicious transaction detected”
Why it works: PayPal phishing exploits fear of financial loss. A notification that your account has been limited — meaning you can’t send or receive money — creates immediate urgency to click and resolve the issue. PayPal mentions in phishing rose 237.9% year-over-year in late 2025, making it one of the fastest-growing lure categories.
What the lure looks like:
- “Your PayPal account has been limited due to suspicious activity. Resolve this now to restore full access.”
- “A payment of £450 has been authorised from your PayPal account. If you did not authorise this, click here.”
- Fake PayPal invoice emails — attackers actually send real PayPal invoices for fraudulent amounts, meaning the email technically comes from PayPal’s own servers.
How to spot it:
- Go to paypal.com directly — never click a link in a PayPal email. If there is genuinely a problem with your account, it will be visible when you log in directly.
- Fake PayPal invoice attacks are harder to spot because the email genuinely comes from PayPal — check the invoice sender’s details carefully and never call any phone number listed in a suspicious invoice
- PayPal never asks you to confirm payment details by email
- Check the “To:” field — genuine PayPal emails are addressed to your full name, not “Dear Customer” or your email address
5. LinkedIn: “You have a new connection request” / “Your profile appeared in searches”
Why it works: LinkedIn is the second most impersonated brand in Q2 2026 phishing campaigns globally. Professional context lowers guard — people expect to receive connection requests and messages from strangers on LinkedIn. Attackers target LinkedIn users specifically because they tend to be employed, making them valuable targets for business email compromise and credential theft.
What the lure looks like:
- “You have 3 new connection requests waiting.” — clicking leads to a fake LinkedIn login page.
- “Your profile appeared in 47 searches this week. See who’s looking for you.”
- Fake recruiter messages with links to job descriptions that are actually malware downloads.
- “Congratulations — your post is performing well! View your analytics.” — leading to a credential harvest page.
How to spot it:
- Go to linkedin.com directly — all notifications are visible in your actual LinkedIn account
- Hover over any link — legitimate LinkedIn emails link to linkedin.com, not any variation of it
- Be especially sceptical of job offer lures — LinkedIn phishing targeting job seekers surged in 2025-2026, with fake recruiter profiles becoming increasingly convincing
- LinkedIn will never ask you to log in via an email link to view a notification
6. Amazon: “Your order has been cancelled” / “Your Prime membership is expiring”
Why it works: Amazon processes hundreds of millions of orders. An email claiming an order has been cancelled, a payment has failed, or Prime membership is about to expire triggers immediate concern in anyone who has recently shopped on Amazon — which is most people. Amazon phishing peaks sharply around Prime Day and the Christmas shopping period.
What the lure looks like:
- “Your Amazon order #204-3849201-2994721 has been cancelled. Click here to reinstate.”
- “Your Amazon Prime membership could not be renewed. Update your payment method to avoid losing benefits.”
- “You have a gift card balance of £50 — claim it before it expires.”
How to spot it:
- Go to amazon.co.uk or amazon.com directly — every genuine order and account notification is visible in Your Account
- Amazon order numbers are real-looking but easy to fabricate — verify in Your Orders, not by clicking the email
- Amazon Prime payment failure notices appear in your account dashboard — they never require clicking an email link to resolve
- Be especially careful of gift card lures — Amazon will never ask you to claim a balance by clicking an email link
7. DocuSign: “You have a document waiting for your signature”
Why it works: DocuSign and similar e-signature platforms have become standard in business workflows. A notification that a document requires your signature is expected and routine — making DocuSign one of the most effective business-targeted phishing lures in 2026. DocuSign overtook Microsoft as the most-impersonated brand in certain months of early 2026. The lure works particularly well against finance, legal, HR, and executive targets.
What the lure looks like:
- “John Smith has sent you a document to review and sign via DocuSign.” — clicking leads to a credential harvest page or malware download.
- A convincing DocuSign-branded email with a yellow “Review Document” button that links to a fake login page.
- Fake contracts, NDAs, or employment offer letters delivered as DocuSign lures targeting job seekers.
How to spot it:
- Go to docusign.com directly and check your inbox — genuine DocuSign documents appear in your account
- Legitimate DocuSign emails contain a unique security code at the bottom — verify it at docusign.com/security before opening any document
- The sender email should come from @docusign.com or @docusign.net — nothing else
- If you’re not expecting a document from the named sender, contact them directly through a known channel before clicking
8. Your Bank: “Unusual activity on your account” / “Action required to avoid account suspension”
Why it works: Banking phishing exploits the most powerful fear trigger available — potential loss of money. A notification of unusual account activity or a threat of account suspension creates immediate urgency. Banking phishing in the UK primarily impersonates Barclays, NatWest, HSBC, Lloyds, Santander, Halifax, and Monzo. Smishing attacks targeting UK banking customers increased 230% in Q1 2026.
What the lure looks like:
- “NatWest: Unusual activity has been detected on your account. Verify your identity now.”
- “Barclays: Your online banking has been temporarily suspended. Click here to restore access.”
- SMS messages with a link to a convincing fake banking login page.
- Fake fraud department calls following up a phishing text.
How to spot it:
- Your bank will never ask you to click a link in an email or text to verify your identity or restore account access
- Go to your bank’s app directly or type the URL yourself — never click a link from an SMS or email
- Genuine bank fraud teams will never ask for your full PIN, password, or one-time passcodes
- The number in a banking text can be spoofed to appear as your bank’s real number — this does not mean the text is genuine
- Call your bank on the number on the back of your card if concerned — never call a number provided in a suspicious message
9. ChatGPT / OpenAI: “Your ChatGPT subscription has failed” / “Claim your free ChatGPT Plus”
Why it works: ChatGPT entered the top ten most impersonated brands for the first time in Q2 2026 — showing how attackers adapt lures to target the most widely recognised new technologies. With millions of ChatGPT users worldwide and a paid Plus subscription at $20/month, billing failure and free upgrade lures are highly effective.
What the lure looks like:
- “Your ChatGPT Plus subscription could not be renewed. Update your payment details to continue access.”
- “Claim your free ChatGPT Plus upgrade — limited offer for verified users.”
- Fake ChatGPT login pages harvesting OpenAI credentials.
- Malware distributed as fake ChatGPT desktop apps or browser extensions.
How to spot it:
- Go to chat.openai.com directly — subscription status is visible in your account settings
- OpenAI does not offer free Plus upgrades via email — any such offer is fraudulent
- Be especially cautious of browser extensions or desktop apps claiming to enhance ChatGPT — only install from official sources
- OpenAI billing issues appear in your account dashboard, not via email links requiring immediate action
10. HR and Payroll: “Your salary payment has been updated” / “Employee handbook review required”
Why it works: HR-themed lures made up 31% of all phishing in January 2026. They arrive appearing to be from inside the organisation, reference things employees genuinely care about — salary, benefits, policies — and are often personalised with the employee’s name and job title.
What the lure looks like:
- “Your salary payment for this month has been updated. Please review and confirm your bank details.”
- “Action required: All employees must review and acknowledge the updated employee handbook by Friday.”
- “Congratulations — you have been selected for a performance bonus. Complete the form to receive payment.”
- “Your payslip for [month] is now available. Click here to view.”
How to spot it:
- Your HR team will never ask you to confirm bank details by email — payroll changes require identity verification through official HR processes
- Employee handbook acknowledgements happen through your HR platform such as Workday or BambooHR — not via email links
- Bonus notifications are communicated through official channels, not unsolicited emails
- If the email asks you to take financial action, call HR directly on a number you already have — never use contact details in the suspicious email
- Check whether the email domain matches your organisation exactly — a single character difference means it is spoofed
The Red Flags That Apply to Every Phishing Lure
Regardless of which brand is being impersonated, every phishing lure shares common tells:
Urgency — “Act within 24 hours or your account will be closed.” Real organisations give you time to respond. Urgency is a pressure tactic designed to prevent you from thinking clearly.
Unexpected contact — You weren’t expecting an invoice, a delivery, or a security alert. If you didn’t initiate something, be suspicious of a message about it.
Mismatched sender domain — The display name says “Microsoft Support” but the email address is microsoft-help@support-desk.net. Always check the actual email address, not just the display name.
Suspicious links — Hover over every link before clicking. The URL should match the brand being impersonated exactly. Any variation — a hyphen, a different TLD, a subdomain — means it is fake.
Requests for credentials or payment — Legitimate organisations do not ask you to log in via an email link to confirm payment details or restore access. Navigate to the website directly.
Generic greetings — “Dear Customer” or “Dear User” instead of your actual name. Most legitimate service providers address you by your full name.
What to Do If You Spot a Phishing Lure
- Do not click any links or open any attachments
- Forward the email to report@phishing.gov.uk
- Forward suspicious texts to 7726 (free from all UK networks)
- Report HMRC phishing to phishing@hmrc.gov.uk
- Submit the phishing URL to PhishScout at phishscout.net
- Delete the email after reporting
If you already clicked, read our step-by-step guide: What to Do If You’ve Been Phished at phishscout.net/what-to-do-if-youve-been-phished-a-step-by-step-guide
Sources: Check Point Q2 2026 Brand Phishing Report · KnowBe4 Phishing Trends 2026 · Guardio Labs Q2 2026 · APWG Phishing Activity Trends Q2 2026 · VikingCloud Phishing Statistics 2026