CyberPlay

Modern email phishing

Login alerts, invoices and HR notes that look finished, and still are not real

«Modern email phishing» — безкоштовний відеокурс CyberPlay, що триває близько 7 хвилин. Гід пояснює тему, а відео зупиняється на п’ять запитань.

Learn why a clean, polished email is not proof that it is real, and how to check login alerts, invoices, HR notices and account warnings on a path you already trust. You will also know what to do if you already clicked.

Курси озвучено англійською або румунською мовою; кнопки й меню — вашою мовою.

Почати курс

Modern email phishing

Коротко

  • П’ять контрольних запитань у відео
  • Близько 7 хвилин
  • Гідів на вибір: 7
  • Озвучено англійською та румунською мовами
  • Безкоштовно з обліковим записом CyberPlay
  • Сертифікат про проходження з Individual Plus або з планом організації, що включає сертифікати
  • До 160 XP за перше проходження

Що ви вмітимете

  • Perfect writing and a logo do not prove the mail is real.
  • Look at what it is asking you to do.
  • Sign in, pay, or send details only on a path you already trust.

Phishing emails no longer look sloppy. Many have clean spelling, a real-looking logo and a calm tone. This page shows why that proves nothing, and the one check that still works.

What it is

Phishing is a message that pretends to come from someone you trust, so you will do something you would not do for a stranger: sign in, pay, download a file, or send a code or a card number.

It wears four common costumes:

  • Login alert: "Your account is at risk." It wants your password on a copied sign-in page.
  • Invoice: a bill is due, or a boss approved it. It wants a payment, or a click that leads to a sign-in or a file.
  • HR notice: pay, benefits or a staff form. It wants a sign-in or a download.
  • Account warning: a tax office, bank or school says something expires. It wants a form, a file or card details.

It is common. In its 2025 Internet Crime Report, the FBI's IC3 listed 191,561 phishing and spoofing complaints from 2025, the most of any type, with about $215.8 million in reported losses. In its 2026 report, Verizon found that 80% of the attacks blocked by email security gateways were plain phishing, not malware.

How it works

  1. The message looks finished. Clean grammar, the logo in the right place, a calm tone or a professional urgency ("two hours", "account will be limited").
  2. The name you see is not the address. The display name can say "Account security" or "HR". The address behind it can be a free mailbox or a lookalike domain, such as the invented alert@account-notify.example.
  3. The button is the attack. "Review activity", "View my benefits", "Pay". It leads to a site the attacker owns, often a near-copy of a real sign-in page.
  4. The ask is the point. Sign in. Pay. Download. Send a code or a card number.

Spelling is no longer a test. In its 2025 Digital Defense Report, Microsoft reported that AI-automated phishing emails reached a 54% click-through rate, against 12% for standard ones.

Real cases

  • A boss and an invoice. In a post dated 10 September 2026, Microsoft Security described more than one million emails sent between 3 and 5 August 2026. They impersonated a CEO, CFO or president and asked accounts payable to send nearly $50,000. Microsoft found no evidence that the real companies named in the lures were hacked.
  • A calm HR note. In a report dated 20 August 2025, Proofpoint described a campaign of hundreds of thousands of messages. One wave posed as HR and wrote about employee benefits. The button led to a fake Microsoft-branded sign-in page.
  • A tax refund in Romania. In a warning republished on 18 April 2026, DNSC, Romania's national cyber security directorate, described emails that pretend to be ANAF, the tax agency. They promise a refund, then a page asks for your personal ID number (CNP) and card details.

How to spot it

  • It asks you to sign in, pay, download, or send a code or card number.
  • It rushes you: today, two hours, account closed.
  • The real sender address, not the display name, is a free mailbox or an almost-right domain.
  • It hands you the link, the phone number or the form.
  • It has an unexpected attachment or a shortened link.

What to do

  1. Stop and ask: what is this message trying to get me to do?
  2. Do not use the button, the link or the phone number in the message, even if it might be real. Real providers do send warnings: Microsoft Support (2026) says a genuine email or text can follow a sign-in from a new place or device. You still do not need the button.
  3. Check on a path you already trust. Open the app, type the address you know, or call a number you already saved. For an invoice or HR form, use the portal or app you already use.
  4. Do not reply or click "unsubscribe". Report it, then delete it.

If it already happened

  1. Do not reply or follow more links in that email.
  2. From a phone or computer that did not open the link, change the password, and anywhere you reused it. Turn on a second sign-in check (multifactor authentication).
  3. Tell someone: IT at school or work, an adult at home.
  4. If you typed a card or sent money, call the bank on the number printed on the card, not one from the email.
  5. Report it. In Romania, call 1911 or use the DNSC reporting site (pnrisc.dnsc.ro). Fast reports help other people, and there is nothing to hide.

Deleting the email does not undo a sign-in.

Джерела

  1. Microsoft Digital Defense Report 2025 — AI phishing click-through 54% vs 12% — Microsoft, 2025
  2. 2026 Data Breach Investigations Report — phishing 16% of breaches; 80% of blocked email attacks are plain phishing — Verizon, 2026
  3. 2025 Internet Crime Report — phishing/spoofing 191,561 complaints, $215.8 million losses — FBI IC3, 2025 complaints
  4. Phishing Activity Trends Report, Q2 2026 — 1,069,681 attacks — APWG, 2026
  5. Protecting organizations from AI-assisted executive impersonation and invoice fraud — Microsoft Security, 10 Sep 2026
  6. Cybercriminals abuse an AI website-creation app for phishing (HR benefits lure) — Proofpoint, 20 Aug 2025
  7. TA4922: HR, invoice and tax-office email lures — Proofpoint, 3 Jun 2026
  8. Recognize and Report Phishing — CISA, 2024
  9. What happens if there's an unusual sign-in to your account — Microsoft Support, 2026
  10. DNSC alert: emails impersonating ANAF and asking for a tax refund — DNSC, via public republishing, 18 Apr 2026

Поширені запитання

Чи безкоштовний курс «Modern email phishing»?

Так. Курс «Modern email phishing» безкоштовний з обліковим записом CyberPlay. Створіть обліковий запис, щоб переглянути його, відповісти на п’ять запитань і зберегти свій прогрес та XP.

Скільки триває курс «Modern email phishing»?

Близько 7 хвилин разом із п’ятьма запитаннями. Точна тривалість залежить від обраного гіда й мови.

Чи отримаю я сертифікат за курс «Modern email phishing»?

Так, з Individual Plus або з планом організації, що включає сертифікати. Пройдіть курс, відповівши на всі п’ять запитань, і отримайте сертифікат про проходження з результатом першої спроби.

Якими мовами доступний курс «Modern email phishing»?

Відео озвучено англійською та румунською мовами, а веде його гід, якого ви оберете (на вибір: 7). Кнопки й меню доступні дев’ятьма мовами.

Усі відеокурси

Контакти · Про нас