Phishing used to be recognisable by broken language and odd phrasing. Those days are gone. Today's scam messages are written by AI, grammatically flawless, fluent, often laced with details about your company scraped from the web and social media. The technology has changed. The psychology hasn't.
The tricks stay the same
Every phishing message, however convincing, tries to trigger one of these reactions:
Urgency. "Your account will be blocked within 24 hours." Panic switches off thinking, and that's exactly what the attacker is counting on.
Authority. A message "from the CEO" in the field: pay this invoice urgently, I'm in a meeting, don't call me. Fake payment-order fraud is among the costliest scams for small companies, one click by an accountant can move thousands of euros.
Curiosity or fear. "A problem was detected with your delivery", "someone signed in to your account". The link leads to a login page that looks identical to the real one, except it sends your password to the attacker.
Three checks that catch most scams
First, the sender's address: not the display name, the actual address. Anyone can type "John Smith" as a name; the domain after the @ sign is harder to fake. A one-letter difference is a classic.
Second, the link before the click. Hover over it (long-press on mobile) and see where it really leads. If "your bank" points to a strange domain, you have your answer.
Third, and most important, verification through a second channel. Every request for payment, IBAN change or data handover gets confirmed by phone, on a number you already have, not the one in the message. This single rule, applied consistently, stops practically all fake-invoice fraud.
Employees: weakest link or best sensor?
Technical protection (filters, MFA, link scanning) catches a large share of attacks, but never all of them. Culture makes the difference: an employee who can say "this looks suspicious, please check" without embarrassment is worth more than expensive software. That's why training shouldn't be a one-off lecture but short, regular exercises: including simulated phishing campaigns that show the real state of readiness, without singling anyone out.
The goal isn't employees who fear every message. The goal is a reflex: pause, verify, then click.