Scams Evolve Constantly

Scammers update their tactics to match current events, new technology, and seasonal patterns. The phishing email that works in December (fake delivery notifications) is different from the one that works in April (fake tax refund notices). Here are the most common types circulating right now.

Account Verification Scams

These are the most common type of phishing email. They impersonate companies like Microsoft, Google, Apple, Amazon, or Netflix, claiming there's been "unusual activity" on your account or that you need to "verify your identity."

The email includes a link to a fake login page that looks identical to the real one. When you enter your username and password, the scammer captures them instantly.

Real-world example

Microsoft account alert scam

A very common phishing email claims to be from "Microsoft Account Team" with the subject "Unusual sign-in activity." It mentions a sign-in from an unfamiliar country (often Russia or China) and urges you to "verify your identity" within hours. The sender address is usually something like security@microsft-account.com (note the misspelling).

Payment and Billing Scams

These emails claim your payment has failed, your subscription is about to expire, or you've been charged for something you didn't buy. They target services most people use: Netflix, Spotify, Amazon Prime, or your bank.

The goal is the same — get you to a fake page where you'll enter your credit card details to "update your payment method."

If you receive an email about a failed payment, never click the link. Instead, open the app or website directly and check your payment settings there.

Delivery and Shipping Scams

With online shopping now routine, fake delivery notifications are extremely effective. These emails or texts claim a package is waiting, needs a customs fee, can't be delivered, or requires address confirmation.

They impersonate postal services (USPS, Royal Mail, DHL, PostNL) and delivery companies (FedEx, UPS, Amazon). During holiday shopping seasons, these spike dramatically because people are actually expecting packages.

If you're expecting a package, track it using the tracking number from your original order confirmation email — not from any new email claiming to be from the delivery service.

Tax Refund and Government Scams

These peak during tax season but circulate year-round. They pretend to be from the IRS (US), HMRC (UK), or your national tax authority, claiming you're owed a refund or that you have unpaid taxes.

Government agencies communicate about taxes through official mail and secure online portals — they do not send emails asking you to click links to claim refunds or threatening legal action.

Real-world example

IRS refund scam

Emails with subject lines like "Your tax refund of $3,847.00 is ready" arrive from addresses like refund@irs-taxreturn.com. The real IRS uses irs.gov and never initiates refund claims by email. In 2022, the IRS warned of a massive surge in tax-themed smishing, identifying thousands of fraudulent domains delivering hundreds of thousands of scam texts within hours.

Business Email Compromise (BEC)

These target people at work. A scammer impersonates your boss, a colleague, or a supplier, and asks you to transfer money, buy gift cards, or share sensitive files. They often use a slightly different email address that looks similar to the real one.

BEC scams caused over $2.9 billion in reported losses in the US in 2023, making them one of the most financially damaging types of cybercrime.

If your "boss" emails you asking to buy gift cards or wire money urgently, always verify by calling them directly or asking in person. Real managers won't mind you double-checking.

AI-Generated Phishing

The newest development is scammers using AI to write more convincing phishing emails. These have perfect grammar, natural-sounding language, and can even be personalised with information scraped from your social media profiles.

This means you can no longer rely on poor spelling and grammar as a reliable indicator. Instead, focus on the other red flags: the sender address, the links, the urgency, and whether you were expecting the email.