Phishing attacks have evolved significantly. The obvious warning signs employees were trained to look for ten years ago — poor spelling, generic greetings, suspicious attachments with obvious names — have been replaced by polished, contextually appropriate attacks that are genuinely difficult to distinguish from legitimate communications.
This guide covers the warning signs that matter in 2026: behavioural signals, structural anomalies, and the specific patterns used in attacks targeting NZ employees.
Warning Sign 1: Artificial Urgency
The most reliable indicator of a phishing attempt is pressure to act immediately. Phrases like "your account will be locked in 24 hours," "immediate action required," "respond within the hour," or "failure to act will result in suspension" are designed to override your normal judgment.
Urgency is a psychological technique, not a genuine business requirement. Legitimate services — your bank, Microsoft, your employer's IT team — do not require you to take critical security actions within hours of receiving an email. When you feel rushed, slow down.
Warning Sign 2: The Display Name Does Not Match the Sender Address
Your email client shows you a display name for the sender — the name that appears in your inbox. Display names can be set to anything. The actual email address is what determines where the email came from.
Check the actual sender address, not just the display name:
- An email appearing to come from "Microsoft Security Team" with an address of "alert@microsoft-security-nz.com" is not from Microsoft
- An email appearing to come from your CEO with an address from a free webmail service is not from your CEO
- An email appearing to come from your bank with a domain that has an extra word in it ("anz-nz-banking.com" rather than "anz.co.nz") is not from your bank
On desktop email clients, hover over or click the sender name to see the actual address. On mobile, tap the sender name to expand the full address.
Warning Sign 3: A Link That Goes Somewhere Unexpected
Before clicking any link in an email, check where it actually goes. On desktop, hover your mouse over the link without clicking — the destination URL will appear in the bottom of your browser or email client. On mobile, press and hold the link to preview the destination.
Look for:
- Domain names that are slightly wrong (paypa1.com, rn1crosoft.com, anz.co.nz.helpdesk-verify.com)
- A URL that starts with the correct domain name but has something added after it (anz.co.nz.maliciousdomain.com — the actual domain here is maliciousdomain.com, not anz.co.nz)
- Link shorteners (bit.ly, tinyurl.com) in emails from business contacts — these hide the actual destination
If the destination does not match what you would expect from the claimed sender, do not click.
Warning Sign 4: Requests for Credentials or Verification Codes
No legitimate service will ask you to:
- Reply to an email with your password
- Enter your current password to "verify" your identity before resetting it
- Provide a one-time code sent to your phone to a caller or in a reply email
- Confirm your banking PIN or full card number via email
Verification codes sent to your phone are a second authentication factor. They are only valid for seconds to minutes and should only ever be entered into the legitimate site or app that requested them. If someone calls you and asks for a code that just arrived on your phone, that person is attempting to access your account — hang up.
Warning Sign 5: Unexpected Requests Involving Money or Access
Phishing and social engineering attacks frequently involve unexpected requests:
- An email from your CEO or a manager asking you to make an urgent payment to a new account
- A supplier advising their bank details have changed and requesting payment to a new account
- An IT support contact asking you to install remote access software or provide your login credentials
- A colleague asking you to buy gift cards and send the codes urgently
The word "unexpected" is key. If a request involves financial transactions, credential access, or installing software, and you were not expecting it, verify through a separate channel before acting. Call the person on a number you look up independently. Message them on Teams or Slack if the request came by email.
Warning Sign 6: Attachments You Were Not Expecting
Malicious attachments remain a common phishing technique. Warning signs include:
- Office documents asking you to "enable content" or "enable macros" — this is the trigger for malware execution
- Password-protected ZIP files containing executables or Office documents — the password is included in the email, which exists only to bypass email scanning
- PDF files that prompt you to click a link rather than containing the expected document
If you receive an attachment you were not expecting, even from a known contact, verify with that person before opening it.
What to Do When You Spot a Warning Sign
- Do not click, open, or reply. Taking no action is always safe.
- Report it using your organisation's reporting process — a button in Outlook or Gmail, a message to IT, or a dedicated reporting email address.
- If you already clicked or entered credentials, report it immediately. Time matters — an account can be locked or a password changed quickly if IT knows to act.
- Delete the email after reporting so you are not tempted to revisit it.
Reporting suspicious emails is not overreacting. Every reported phishing email helps your organisation improve its defences and potentially protects colleagues who receive the same attack.
SecureAZ phishing simulations train staff to recognise and report real attacks