Scam category

Email phishing scams

Email phishing is the gateway to most online fraud. Attackers send emails that mimic banks, employers, software providers, or government agencies, directing victims to fake login pages that capture credentials in real time. Spear phishing targets specific individuals using personal details scraped from social media or data breaches.

17 scams trackedAll categories

Category activity

“phishing email”

↑ 215%

Watch for

  • The email asks you to verify your account, confirm your identity, or reset your password through an embedded link.
  • Hovering over links reveals a URL that does not match the company's official domain.
  • The email contains generic greetings, spelling errors, or formatting inconsistencies that differ from real communications.

Common searches

how to spot a phishing emailbank phishing email examplespear phishing attackemail scam asking for password

OpenScam · Live feed

OpenScam News Feed

Live reports from government agencies, cybersecurity researchers, and consumer watchdogs that match email phishing scams.

Email phishing scams
↑ 80%

CEO urgent request phishing scam

An email appears to come from a company executive urgently requesting a wire transfer, gift card purchase, or sensitive data, exploiting the recipient's desire to comply with authority.

What to do first

Always verify unusual financial or data requests through a separate communication channel — call the executive directly.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

password reset phishing scam

A fake password reset notification urges the recipient to click a link and enter their current credentials, which are captured by attackers.

What to do first

Never click password reset links you did not request — navigate directly to the service's website.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

shared document notification phishing scam

A fake notification claims someone has shared a document with you via Google Drive, OneDrive, or Dropbox, leading to a credential-harvesting login page.

What to do first

Hover over the link to inspect the URL before clicking — legitimate shares come from official domains.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

invoice attachment malware scam

An email with a fake invoice attachment installs malware when opened, giving attackers access to the victim's computer and network.

What to do first

Never open attachments from unknown senders — verify invoices by contacting the vendor directly.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

account suspension notice phishing scam

A fake email warns that your email, bank, or streaming account will be suspended unless you verify your identity immediately, directing you to a credential-stealing page.

What to do first

Log into your account directly by typing the URL in your browser — never use links from warning emails.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

two-factor authentication bypass phishing scam

Attackers use real-time phishing toolkits to capture both passwords and two-factor authentication codes simultaneously, defeating standard MFA protections.

What to do first

Use hardware security keys (FIDO2/WebAuthn) which are resistant to real-time phishing proxy attacks.

Targets

IT administrators

Seen in

U.S.

Email phishing scams
↑ 80%

email forwarding rule hijack scam

After compromising an email account, attackers silently create forwarding rules that copy all incoming messages to an external address, enabling long-term surveillance.

What to do first

After any account compromise, immediately check your email rules and forwarding settings — remove anything you did not create.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

calendar invite phishing scam

Attackers send calendar invitations containing phishing links in the event description or location field, which automatically appear in the victim's calendar.

What to do first

Change your calendar settings to not automatically add events from email invitations.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

unsubscribe link trap scam

Phishing emails include a malicious unsubscribe link that, when clicked, confirms your email address is active and leads to credential theft or malware installation.

What to do first

Do not click unsubscribe in emails from unknown senders — mark the email as spam instead.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

reply-chain hijacking scam

Attackers compromise an email account and insert malicious messages into existing email threads, exploiting the trust established in ongoing conversations.

What to do first

Be cautious of unexpected attachments or links even in existing email threads.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

PayPal unauthorized transaction email scam

A fake email alerts you to a large unauthorized PayPal transaction, urging you to click a link or call a number to dispute it — leading to credential theft or remote access fraud.

What to do first

Check your PayPal account directly at paypal.com — if there is no matching transaction, the email is fake.

Targets

PayPal users

Seen in

U.S.

Email phishing scams
↑ 80%

PayPal fake payment confirmation scam

A buyer sends a forged PayPal confirmation email to a seller to make it appear that payment has been sent, tricking the seller into shipping goods before discovering no actual payment was received.

What to do first

Never rely on email notifications alone — always verify payments by logging into your PayPal account directly.

Targets

Online sellers

Seen in

U.S.

Email phishing scams
↑ 80%

Teams meeting invite phishing scam

A fake Microsoft Teams meeting invitation arrives by email, and clicking the join link leads to a credential harvesting page disguised as the Teams login.

What to do first

Hover over the meeting link before clicking to verify it points to a legitimate Microsoft domain.

Targets

Business professionals

Seen in

U.S.

Email phishing scams
↑ 80%

Outlook account suspended phishing scam

A phishing email warns that your Outlook or Hotmail account has been suspended for violating terms of service, urging you to verify your identity on a fake page.

What to do first

Sign in to your Outlook account directly at outlook.com to verify its status — if you can log in, it is not suspended.

Targets

Email users

Seen in

U.S.

Email phishing scams
↑ 80%

OneDrive sharing notification phishing scam

A fake OneDrive sharing notification email claims someone shared a document with you, but the link leads to a credential-stealing page.

What to do first

Verify the sender by contacting them through a separate channel before clicking any shared document link.

Targets

Business professionals

Seen in

U.S.

Email phishing scams
↑ 80%

Google Calendar invite spam scam

Scammers send unsolicited Google Calendar invitations containing phishing links or fake prize notifications that automatically appear on the victim's calendar.

What to do first

Change your Google Calendar settings to only show invitations you have explicitly accepted.

Targets

Gmail users

Seen in

U.S.

Email phishing scams
↑ 80%

Google Workspace admin phishing scam

IT administrators receive fake Google Workspace notifications about policy changes, license issues, or security alerts, leading to admin credential theft.

What to do first

Access the admin console directly at admin.google.com — never through email links.

Targets

IT administrators

Seen in

U.S.

Related categories