4 devious email scams hitting inboxes right now, and how to spot them
For the last decade, email scams have run rampant on the internet. And corporate IT departments have handed out the exact same advice like clockwork: Look for bad grammar, hover over links, and turn on two-factor authentication. But those recommendations have fallen behind the times. Thanks to AI and clever architectural work-arounds, today’s email scams don’t look like scams. They don’t contain spelling errors. And in many cases, they don’t even care if you have 2FA enabled. Here’s a handful of new tricks flooding inboxes right now, how they work, and how to stay ahead of them. 1. QR code mobile bypass (“Quishing”) You open an email claiming your Microsoft 365 password is about to expire, or that an urgent HR document needs a DocuSign signature. But instead of a clickable link, there’s a crisp graphic with a QR code asking you to scan with your phone’s camera to verify your identity. The ruse is particularly sneaky. Your work laptop is heavily guarded by corporate firewalls and link-checkers. The moment you pull out your phone and scan that code, you leave that protected umbrella entirely, loading a malicious page on a personal mobile browser with zero security filters. If an unexpected email asks you to scan a code on your personal device to handle workplace credentials, treat it like a live grenade. 2. “ClickFix” clipboard trap This one hits you with a psychological trick right when you’re trying to be productive.
Comments
No comments yet. Start the discussion.