How to recognize phishing in 2026 (with AI-generated examples)

Editorial Team Avatar

AI has taken away the easiest tell of phishing: bad grammar. Fluent, polite, well-formatted scam emails are now cheap to produce. But five signals still work in 2026. Learn them once and use them every time.

What changed

Older phishing was often easy to spot:
– Bad grammar (“Your account has been compromise”)
– Odd formatting (random capitals, mixed fonts)
– Obvious typos in the domain (paypa1.com)

Today, generative AI tools can write a convincing email in any language in seconds. Grammar is no longer a reliable signal.

Five signals that still work

1. Check the sender’s domain (zoom in)

Real: support@netflix.com
Fake: support@netf1ix.com (a 1 instead of an l)
Fake: support@netflix.support-team.com (the real domain here is support-team.com)

Un passo avanti. Sempre.

Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.

Icona Telegram Entra nel Canale

Action: do not trust the display name. On a phone, tap or hold the sender to see the full address. When in doubt, go to the site yourself.

2. Check where the link really goes

Phishing emails contain links that look right (“Click here to update your account”) but lead somewhere else.

Action:
– On a computer: hover over the link and read the address that appears at the bottom of the window
– On a phone: press and hold the link to see the real address
– If you are unsure: do not click, and go to the official site yourself

3. Urgency and fear

Be suspicious when a message:
– Threatens that “your account will be deleted in 24 hours”
– Demands that you “verify within 1 hour or lose access”
– Keeps shouting “URGENT” or “IMMEDIATE ACTION REQUIRED”

Real organizations usually give you reasonable time, and they do not rely on a threatening email alone.

4. A request that makes no sense

Things legitimate organizations do not ask for by email:
– Your password (no real IT department asks for it)
– Your full card number or bank login
– Your 2FA codes (those codes are for you to type, never to share)
– Payment with gift cards or cryptocurrency: the US Federal Trade Commission says that only scammers tell you to pay that way

If the email asks for one of these, treat it as phishing.

5. A pretext that does not fit the sender

If your bank writes about a parcel delivery, it is almost certainly phishing.
If a courier writes about your bank account, it is almost certainly phishing.
If an email claims to come from the IRS, be very suspicious: the IRS says it does not start contact with taxpayers by email, text or social media to ask for personal or financial information. Most of its first contacts arrive by post.

Ask yourself: is this the way this sender would normally contact me, about this subject?

Three realistic examples

These are examples we wrote to show the signals; they are not real emails.

Example 1: a fake bank alert

From: security@chase.bank-verification.com
Subject: Action required: Suspicious activity on your account

Dear customer,

We detected unauthorized login attempts on your Chase account from
IP 192.168.x.x located in [your city]. To prevent account suspension,
please verify your identity within 24 hours.

[Verify identity now]

Thank you for choosing Chase.

Signals:
– Domain: chase.bank-verification.com, not chase.com
– Urgency: “24 hours”
– Request: “verify” through an outside link
– Perfect grammar, which proves nothing

Example 2: the fake boss (business email compromise)

From: ceo@your-company-name.com
Subject: Quick task

Hey, need your help.

I'm in a meeting and can't take calls. Can you wire $5,000 USD to
[vendor name] for an urgent invoice? I'll explain when out.

Don't loop in finance, I'll handle that.

Sent from my iPhone

Signals:
– An urgent money request by email, with the phone ruled out
– Pressure to skip the normal procedure (“don’t loop in finance”)
– A vague reason (“vendor invoice”)
– “I’m in a meeting”: a reason not to check

Example 3: fake tech support

From: noreply@apple-id.support
Subject: Your Apple ID has been disabled

We have temporarily disabled your Apple ID due to security concerns.
To reactivate within 24 hours, sign in:

[Restore Apple ID]

Apple Support

Signals:
– Domain: apple-id.support, not apple.com
– Urgency: “24 hours”
– A link to an outside site

What to do if you clicked

Don’t panic. In most cases the damage comes from typing your credentials, not from the click itself.

  1. Don’t enter any credentials once you realize what happened
  2. If you entered them: change the password right away on the real site, and turn on 2FA
  3. Check Have I Been Pwned to see whether your email appears in known breaches
  4. Run a malware scan with a reputable tool (Windows Security is built into Windows)
  5. Report it: to your email provider, and to your IT team if it was a work account
  6. Watch your accounts: check bank statements and, in the US, your credit reports over the following weeks

Defenses that work even if you click

  • A password manager: it will not autofill your password on a fake domain, which is itself a warning
  • A hardware security key for 2FA (for example a YubiKey): designed to resist phishing
  • Bookmarks: open important sites from your bookmarks, never from email links
  • Your email provider’s filters: Gmail, Outlook and Proton Mail all filter phishing; keep them on

Bottom line

Phishing in 2026 looks legitimate. Don’t trust grammar or formatting. Use the five signals, a password manager and 2FA. When in doubt, go to the site yourself and never log in from an email link.

Sources

Frequently asked questions

What if I clicked a phishing link?

Don't panic. (1) Don't enter any credentials. (2) If you did, change the password right away on the real site and turn on 2FA. (3) Check your email address on Have I Been Pwned. (4) If you gave financial details, call your bank and consider freezing your credit. (5) Run a malware scan. In most cases the damage comes from typing your credentials, not from the click alone.

Un passo avanti. Sempre.

Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.

Icona Telegram Entra nel Canale

Is reporting phishing useful?

Yes: reports help providers block the senders and take down the fake sites. Use the 'report phishing' button of your email service. In the US you can also forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org, and emails pretending to be the IRS to phishing@irs.gov. In the UK, forward it to report@phishing.gov.uk. For a work email, tell your IT helpdesk.

AI-generated phishing: how do you spot it?

It is the hardest kind to spot, because the grammar is perfect. Focus on (1) the sender's domain, (2) where the link really goes, (3) pressure to act now, and (4) what is being asked: a real IT department never asks for your password by email.

Tagged in :

Editorial Team Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *