Business

4 devious email scams hitting inboxes right now, and how to spot them

For the last decade, email scams have run rampant on the internet. And corporate IT departments have handed out the exact same advice like clockwork: Look for bad grammar, hover over links, and turn on two-factor authentication.

But those recommendations have fallen behind the times. Thanks to AI and clever architectural work-arounds, today’s email scams don’t look like scams. They don’t contain spelling errors. And in many cases, they don’t even care if you have 2FA enabled.

Here’s a handful of new tricks flooding inboxes right now, how they work, and how to stay ahead of them.

1. QR code mobile bypass (“Quishing”)

You open an email claiming your Microsoft 365 password is about to expire, or that an urgent HR document needs a DocuSign signature. But instead of a clickable link, there’s a crisp graphic with a QR code asking you to scan with your phone’s camera to verify your identity.

The ruse is particularly sneaky. Your work laptop is heavily guarded by corporate firewalls and link-checkers. The moment you pull out your phone and scan that code, you leave that protected umbrella entirely, loading a malicious page on a personal mobile browser with zero security filters.

If an unexpected email asks you to scan a code on your personal device to handle workplace credentials, treat it like a live grenade.

2. “ClickFix” clipboard trap

This one hits you with a psychological trick right when you’re trying to be productive.

You click a notification email to open a document, but the web page freezes with an official-looking error pop-up claiming a rendering error occurred. It kindly asks you to press Win + R, paste a provided verification code into your Windows Run prompt, and hit Enter.

There’s no software error. The scammer tricked you into copying malicious code onto your clipboard and manually executing it in your operating system terminal.

Never paste text from a browser into your computer’s command terminal just because a website asked you to. Browsers don’t need system-level commands to display a file.

3. Adversary-in-the-Middle login cloning

Most people assume two-factor authentication makes login pages bulletproof. But Adversary-in-the-Middle attacks break that assumption wide open.

An email directs you to a portal that looks identical to your company’s login screen. You type in your username, password, and even the six-digit code from your authenticator app.

This fake login page acts like a sneaky middleman standing between you and the real website. When you enter your password and two-factor code, the middleman passes them along to the actual site in real time.

Once the real site confirms your info and unlocks your account, the scammer snatches the session cookie that the website handed back, giving him full, instant access to your account as if he were sitting at your keyboard.

In other words, your 2FA code worked, it just worked for the attacker.

Before typing your credentials anywhere, always look closely at the URL address bar to verify the domain name is legitimate.

4. Fake (but real) invoices

One of the hardest scams to filter is the one sent from a legitimate tech company. With this scam, you receive an official invoice notification from QuickBooks, PayPal, or Google Workspace containing your name, an order number, and a phone number to call if you suspect fraud.

Spam filters pass these straight into your primary inbox, because the email actually came from Intuit or Google. Attackers simply set up free business accounts on these platforms and abuse their built-in invoicing tools to blast out scam messages.

If an invoice note contains a suspicious support phone number, never call it. Always log in to your account directly through the official website to check your billing history first.

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Secret Link