Add Think Technology as a trusted source Hackers' favourite phishing lures | TTA

Hackers’ favourite phishing lures

Hackers Favorite Phishing Lures

Phishing is still how most cyberattacks begin. Over 90% of successful breaches start with a phishing message, according to CISA, and the emails landing in Australian inboxes today are harder to spot than ever. The ACSC’s Annual Cyber Threat Report 2024-25 recorded 84,700 cybercrime reports, roughly one every six minutes. A large share of those started with a deceptive email.

Understanding what these emails look like, and why they work, is one of the most practical things you can do for your team’s security. Our email security work with Queensland businesses shows that most people can spot the old-style scam. The new ones are a different problem.

Why phishing emails are harder to spot in 2025 and 2026

The classic tells are gone. Spelling mistakes, awkward phrasing, and generic greetings used to flag a phishing attempt. Now, most targeted phishing emails are written with AI assistance. They are fluent, personalised, and formatted to match the real thing. Microsoft is the most impersonated brand in active campaigns, appearing in roughly a quarter of all branded phishing pages tracked globally in late 2025. Attackers also regularly spoof the ATO, Australia Post, banks, and DocuSign.

The result is that even cautious employees get caught. KnowBe4’s 2026 Phishing Benchmarking Report found that across Australia and New Zealand, around one in four employees at small businesses clicked a simulated phishing link before any training. At larger organisations, the rate was even higher.

The subject lines attackers use most

Attackers choose subject lines that feel routine. The goal is to get the email opened without triggering suspicion. Research across thousands of confirmed phishing campaigns consistently shows these as the most-clicked categories:

  • HR and payroll themes“Your payslip for June is now available”, “Update your direct deposit details before Friday”, “Important update to your employee benefits”. These make up roughly half of the most-clicked simulated phishing emails, because anything touching pay feels too important to ignore.
  • Urgent action required“Urgent”, “Review”, and “Sign” remain the top three trigger words in phishing subject lines. The pressure to act fast bypasses careful thinking.
  • Requests and follow-upsSimple openers like “Request”, “Follow up”, and “Re:” suggest the email is part of an existing conversation. Familiarity lowers the guard.
  • Invoice and payment prompts“Invoice due”, “Payment status”, and “Purchase” target finance staff and business owners who process payments regularly.
  • Account and security alertsFake Microsoft 365 sign-in warnings, password reset notices, and “unusual activity” alerts prompt users to enter credentials on copycat login pages.
  • Document sharingA message appearing to come from a colleague sharing a file via SharePoint or Google Drive. Because the sender name and link can look legitimate, these often bypass email filters entirely.

New delivery methods to watch for

Email is still the main channel, but phishing has spread. Teams and Slack messages now account for an estimated 15-20% of enterprise phishing entry points. Attackers use compromised accounts or external guest access to send malicious links inside a trusted collaboration tool.

QR code phishing, sometimes called “quishing”, has also grown sharply. The email body contains little text and a QR code image. Scanning with a personal phone bypasses corporate email filters and takes the user to a credential-harvesting page. Any email that asks you to scan a QR code to log in or re-enrol in multi-factor authentication (MFA) should be treated with caution.

Business email compromise (BEC) sits at the serious end of the scale. An attacker impersonates a CEO, supplier, or colleague and asks someone to transfer funds or change payment details. There is no malicious link and no attachment, just a convincing message. Business email compromise causes significant financial losses for Australian businesses every year, and the ACSC warns that BEC attempts continue to rise.

How to tell a phishing email from the real thing

There is no single giveaway anymore. Good phishing emails pass most quick checks. These habits help:

  • Check the sender domain, not the display name. The name shown can say anything. Hover over or tap the sender address to see the actual domain. A legitimate DocuSign email comes from docusign.net or docusign.com, not docusign-secure.net or similar variations.
  • Hover over links before clicking. The URL that appears at the bottom of your browser is the real destination. If it does not match the organisation it claims to be, do not click.
  • Verify unexpected requests through a second channel. If someone sends an urgent email asking you to transfer money or update payment details, call them directly. Do not reply to the email. This one step stops most BEC attempts.
  • Be sceptical of urgency and secrecy. “Do this before end of day”, “don’t mention this to anyone”, these are pressure tactics, not normal business practice.
  • Never scan a QR code to authenticate. Legitimate IT systems do not ask you to scan a QR code in an email to log in or set up MFA.

The ACSC Small Business Cyber Security Guide covers these habits in plain language and is worth sharing with your whole team.

What your business can do beyond training

Staff awareness is essential but not enough on its own. Email filters, DNS filtering, and multi-factor authentication all reduce the damage when a phishing email does get through.

At TTA, we help Brisbane and South-East Queensland businesses put the right layers in place. That means configuring email security at the gateway before a suspicious message reaches anyone’s inbox, setting up DNS filtering to block known malicious domains, and making sure MFA is active on every account that matters. We also work with clients on security training that sticksshort, practical sessions rather than once-a-year compliance tick-boxes.

The businesses we work with that handle phishing best share one thing: they have a simple, agreed process for what to do when something looks suspicious. Pause, check through a second channel, report it. That process is worth more than any piece of software alone.

Frequently asked questions

What is phishing in simple terms?

Phishing is a scam where someone sends a fake email, or message, pretending to be a trusted organisation or person. The goal is to trick you into handing over a password, clicking a malicious link, or transferring money. The name comes from “fishing”: attackers cast a lure and wait for someone to bite.

Are phishing emails easy to spot in 2026?

Not always. AI tools have made phishing emails much more convincing. Spelling mistakes and broken English are rare in targeted attacks now. The safest approach is to verify any unexpected request through a second channel, phone or in-person, rather than relying on how the email looks.

What are the most common phishing subject lines?

HR and payroll themes dominate current campaigns, messages about payslips, direct deposit updates, and benefit changes make up roughly half of the most-clicked phishing emails. Urgency words like “Urgent”, “Review”, and “Sign” also appear frequently. Simple openers like “Request”, “Follow up”, and “Re:” are common in spear-phishing targeted at specific people.

What is business email compromise and how does it work?

Business email compromise (BEC) is a type of phishing where an attacker impersonates an executive, supplier, or colleague and asks someone to transfer funds or change payment details. There is no malicious link, just a convincing email. BEC causes serious financial losses for Australian businesses and is one of the most costly forms of cybercrime reported to the ACSC.

What should my business do if an employee clicks a phishing link?

Act quickly. Disconnect the affected device from the network, reset the employee’s passwords and revoke active sessions, check for inbox rules the attacker may have set, and notify your IT provider or managed services partner. Report the incident to the ACSC via ReportCyber at cyber.gov.au. Speed matters, most damage from phishing happens in the first hour after a click.

Where do we get started with phishing protection?

Start with the basics: multi-factor authentication on all accounts, an email security gateway, and a simple policy for staff on what to do when an email looks suspicious. From there, DNS filtering and regular training sessions add meaningful layers. TTA can assess your current setup and help you close the gaps that matter most.

How do we get started?

If you want to review your email security posture or train your team to spot phishing, we are happy to help. Get in touch with the TTA team for a straightforward conversation about where your biggest risks are and what to do about them.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.