Skip to content
Back to blog

Cybersecurity

6 Phishing Email Examples Your Staff Will Actually See (And How to Train Against Them)

Real-world phishing email examples: fake invoices, MFA fatigue, payroll redirects, vendor bank-change scams, and more. What gives each one away, plus how to run simulation training.

By Wakeem Williams 9 min read

Phishing email examples are easiest to learn from when they look like the ones actually landing in your team’s inbox, not the obviously fake ones with broken grammar and a Nigerian prince. Below are six patterns we see most in Hampton Roads small businesses, what tips each one off, and how to run the kind of ongoing simulation training that turns “I think I would have caught that” into something you can actually measure.

None of the examples below reference a real company or person. They’re illustrative, built from the patterns the FBI and CISA both flag as most common. Phishing and spoofing were among the most frequently reported complaint types in the FBI’s 2025 IC3 Internet Crime Report, which logged over a million complaints and more than $20 billion in reported losses. That’s not a reason to panic. It’s a reason to make the training specific instead of generic.

Why generic phishing training doesn’t stick

Most small businesses run one phishing training video a year, everyone clicks through the slides, and nobody remembers a single tell three months later. It’s not that people are careless. It’s that the training doesn’t match what they’ll actually see.

The CISA phishing guidance makes the same point in plainer terms: attackers exploit trust and routine, not ignorance. Someone who processes 40 vendor invoices a week isn’t going to pause on the 41st unless they know exactly what to look for on that specific type of email. Generic “don’t click suspicious links” advice doesn’t give them that.

That’s the reasoning behind the six examples below. Each one is a pattern, not a one-off, and each has a specific tell your team can actually watch for.

1. The fake invoice

What it looks like: An email that appears to come from a vendor you already work with, referencing a real-sounding invoice number, with a PDF attachment or a “view invoice” link.

Subject: Invoice #48213 - Payment Due

Hi, attached is the invoice for last month’s services. Please process payment by Friday to avoid a late fee. Let us know if you have any questions.

[View Invoice - accountspayable-portal.net]

The tell: The domain in the link doesn’t match the vendor’s actual domain, and the email creates urgency around a deadline that wasn’t discussed anywhere else. Real vendors don’t usually threaten late fees in the same email as a brand-new invoice format you’ve never seen before.

Train your team to: Hover over links before clicking (or better, don’t click at all) and verify new or unusual invoices through a phone call to a number you already have on file, not one in the email.

2. MFA fatigue (push bombing)

What it looks like: Not an email at all, but a wave of MFA approval requests hitting someone’s phone, sometimes a dozen in a row, hoping the person taps “approve” just to make the notifications stop.

The tell: You didn’t just try to log in. If MFA prompts show up when nobody on your team is actively signing in, that’s not a glitch. It means someone already has a valid password and is trying to get past the second factor.

Train your team to: Deny and report any MFA prompt they didn’t trigger themselves, immediately, rather than assuming it’s a fluke. Microsoft and Google both recommend switching from simple approve/deny push notifications to number-matching MFA specifically because it kills this attack, since the app now shows a number the user has to match on their sign-in screen instead of just tapping approve.

3. The payroll redirect

What it looks like: An email, often sent to HR or payroll, that appears to come from an employee asking to update their direct deposit information before the next pay run.

Subject: Update Direct Deposit

Hi, I switched banks recently and need to update my direct deposit info before payroll runs this week. New account details attached. Thanks so much for the quick turnaround.

The tell: No phone call, no in-person confirmation, and often a tone that’s slightly more formal or slightly more rushed than that employee usually writes. These attacks work because payroll changes feel routine and HR staff process a lot of them.

Train your team to: Require voice or in-person verification for any banking or direct deposit change, no exceptions, even when the request seems to come from someone they know well.

4. The vendor bank-change scam

What it looks like: Similar to the payroll redirect, but aimed at accounts payable. An email claims to come from a long-standing vendor, stating their bank has changed and providing new wire instructions for the next payment.

The tell: This is one of the most expensive phishing patterns because payments to vendors are often larger than payroll deposits, and the request usually times itself to an invoice that’s already due. The email address is frequently a close lookalike of the real vendor’s domain, off by one letter or a swapped top-level domain.

Train your team to: Treat every vendor bank-change request as its own security event. Call the vendor using a number from a past invoice or your CRM, not the number in the new email, and confirm before a single dollar moves.

5. The executive gift-card request

What it looks like: A short, urgent email that appears to come from an owner or executive, asking someone (often an assistant or newer employee) to buy gift cards for a “client thank-you” or similar, and to send the codes right away.

Subject: Quick favor

Are you at your desk? I need you to grab some gift cards for a client thing before I head into a meeting. Can’t talk right now, just reply here.

The tell: The urgency, the vague reason, the request to reply instead of call, and the fact that legitimate executives essentially never ask for gift cards by email. This pattern specifically targets newer or lower-tenure employees who are less likely to question a request from someone senior.

Train your team to: Build in a standing rule: nobody buys gift cards or makes financial transfers based on an email request alone, regardless of who it appears to be from. A two-second phone call kills this scam every time.

6. The Microsoft 365 credential harvest

What it looks like: An email mimicking a Microsoft notification: a shared document, a voicemail, a password expiration warning, or a mailbox storage alert, linking to a fake Microsoft sign-in page designed to capture the username and password typed into it.

The tell: Check the URL bar before typing anything. A real Microsoft sign-in page lives on a login.microsoftonline.com domain. A fake one uses a lookalike domain, a shortened URL, or sometimes a legitimate-looking form hosted on a compromised third-party site. This is consistently one of the highest-volume phishing categories because almost every small business runs on Microsoft 365 or Google Workspace, which makes the lure believable to nearly everyone who gets it.

Train your team to: Never sign into Microsoft from a link in an email. Open a new tab and go to office.com directly. If a document link demands a login that feels unexpected, that’s the moment to stop and verify.

How to run phishing simulation training that actually works

Reading about six examples helps once. Testing your team against realistic versions of them, on a recurring schedule, is what actually changes behavior. That’s the difference between phishing email examples for training and a slide deck nobody remembers.

A working simulation program has three parts:

Realistic phishing simulation tools. Platforms like KnowBe4, Proofpoint Security Awareness, and Microsoft’s built-in Attack Simulation Training send safe, fake phishing emails modeled on real attack patterns, then track who clicked, who entered credentials, and who reported it correctly. Pricing on third-party platforms usually runs per-user per-year, and most vendors offer a lower per-seat rate once you cross a certain headcount, so it’s worth asking about volume pricing before you commit.

A no-blame reporting culture. If clicking a simulated phishing email results in public shame, staff will stop reporting real ones too. The point of the click data isn’t punishment. It’s finding out which specific patterns your team needs more practice on.

Quarterly cadence, not annual. A single training in January doesn’t hold up against an invoice scam in October. Quarterly simulations, mixed across the patterns above, keep the muscle memory current.

Microsoft Attack Simulation Training

If your business already runs Microsoft 365, you may not need to buy a separate platform. Attack Simulation Training is built into Microsoft Defender for Office 365 and lets you launch credential harvest, link-click, and attachment-based simulations directly against your own tenant, using templates modeled on real attack techniques.

It’s included with Microsoft 365 E5 and Defender for Office 365 Plan 2, and available as an add-on for Business Premium and E3 customers. If you’re already paying for Business Premium, this is worth checking before you shop separately: you may already own the tool and just haven’t turned it on. The simulator reports click rates and reporting rates per employee, which gives you the same data a third-party platform would, without a second vendor invoice.

The tradeoff is setup. Microsoft’s simulator assumes some Defender familiarity, and the template library is smaller than a dedicated platform like KnowBe4. For a business under 20 people running Business Premium, that tradeoff usually favors trying the built-in tool first. For a larger team or one that wants a bigger library of industry-specific templates, a dedicated platform earns its cost.

What to do next

Print or forward the six patterns above to your team this week. That alone puts you ahead of most small businesses, since most never write down what a scam email in their specific industry actually looks like.

For a printable version with all six patterns, the tells, and a response checklist your team can keep at their desk, grab the Phishing Defense Checklist. It’s free, and it’s built to hand to a new hire on day one.

If phishing is one gap in a bigger list you haven’t mapped yet, our Cybersecurity for Small Business Guide walks through the rest: MFA, backups, patching, and access control. And if you want a specific read on where your business stands right now, the Free IT Assessment takes about three minutes and tells you what to prioritize first.

Why Helix Stax

Phishing defense isn’t one email filter and a training video. It’s email security configuration, simulation training, MFA enforcement, and a documented response plan that all work together, which is exactly what our Cybersecurity & Compliance engagements cover. If your team runs on Microsoft 365, our Cloud & Microsoft 365 work includes turning on tools like Attack Simulation Training that most businesses are already paying for and never activate.

We’re based in Hampton Roads and work with small businesses who’d rather fix this once, correctly, than buy another tool and hope it helps.

Questions

Frequently asked questions about Helix Stax managed IT services

Most phishing emails imitate something your team already expects: an invoice, a password reset, a shipping notice, or a message from a coworker. The giveaways are usually in the details, not the design: a sender address that's close but wrong, a link that doesn't match the display text, urgency that skips your normal process, or a request to act outside your usual channel like a text instead of email.

The FBI and CISA generally group phishing into email phishing (the broad, high-volume version), spear phishing (targeted at a specific person using research about them), whaling (targeted at executives or finance staff, often to redirect a wire transfer), and smishing/vishing (the same tactics over text or phone). Business email compromise, where an attacker impersonates a real vendor or executive, usually combines spear phishing with a payment request.

Check the URL bar before you type a password, not after. A real Microsoft sign-in page lives at a login.microsoftonline.com domain. A fake one uses a lookalike domain, a URL shortener, or a domain that has nothing to do with Microsoft at all. If a link in an email takes you to a password prompt, open a new browser tab and go to office.com directly instead of trusting the link.

Phishing simulation training sends staff realistic, safe test phishing emails and tracks who clicks, who reports it, and who enters credentials. Employees who click get immediate, specific feedback instead of a lecture six months later. Programs like KnowBe4 and Microsoft's built-in Attack Simulation Training report meaningful drops in click rates over repeated quarterly campaigns, though results vary by industry and how consistently the training runs.

Attack Simulation Training is included with Microsoft 365 E5, Microsoft Defender for Office 365 Plan 2, and available as an add-on for Microsoft 365 Business Premium and E3 customers through Defender for Office 365 Plan 2. If your business already runs Business Premium, check your Defender license before you shop for a separate paid platform.

Tell IT immediately. Don't wait to see if anything bad happens, and don't try to fix it yourself. If they entered a password, that account needs a forced password reset and an MFA check right away, because the faster access gets cut off, the smaller the damage. A no-blame reporting culture matters more than any single training module, since employees who fear getting in trouble tend to stay quiet instead of speaking up.