Phishing Has Changed. Have Your Employees’ Habits Changed With It?
Ryan Greyslak, Senior Director, Secured Managed Services and SOC Services

“Phishing techniques will continue to change, but employees do not need to memorize every new tactic. When a request seems unusual, verify it through a trusted channel before acting. If something goes wrong, report it quickly. “
Key Takeaways
- Phishing is no longer limited to suspicious emails with obvious mistakes. Attacks can begin with text messages, QR codes, collaboration platforms, or phone calls and may lead employees to convincing login pages.
- Employees should evaluate the request itself, not just whether the message looks legitimate. Requests involving money, credentials, MFA, sensitive information, or changes to normal processes deserve extra scrutiny.
- Verify unusual requests through a separate, trusted channel rather than using contact information provided in the message.
- Employees should report suspicious activity quickly, even if they already clicked a link, entered information, or approved an authentication request.
- Ongoing training and realistic phishing simulations can reinforce these habits.
For years, phishing guidance focused on familiar warning signs such as poor grammar, misspelled company names, suspicious links, strange email addresses, and unexpected attachments.
Those signs still matter, but attackers no longer need to rely on poorly written emails. They can create professional-looking messages, imitate familiar business communications, direct users to convincing login pages, or send messages from compromised accounts.
A message can even come from a legitimate account belonging to a coworker, customer, executive, or vendor and still be malicious.
That means employees need to move beyond asking only:
“Does this message look real?”
They also need to ask:
“Does this request make sense?”
Employees do not need to recognize every new phishing technique. What matters more is knowing when a request deserves a second look.
Why Familiar Phishing Red Flags Are Less Reliable
Attackers can use publicly available information about job titles, executives, vendors, office locations, events, and business relationships to make a message more convincing.
Compromised accounts make this even more difficult. An attacker who gains access to a legitimate email or collaboration account can send messages from an identity the employee already trusts. The email address may be correct, the signature may look familiar, and the conversation may even include legitimate message history.
In those situations, traditional phishing indicators may not be present at all.
Employees need to look beyond how a message appears and consider whether the request itself makes sense and follows normal business processes.
An executive requesting an urgent payment, a vendor changing banking information, an IT message asking someone to sign in, or a document notification containing a QR code may all look legitimate.
Even when a message looks legitimate, employees should verify unusual or sensitive requests before acting.
Phishing Does Not Stay in the Inbox
The same social engineering tactics can reach employees through many different channels, including:
- Text messages about an account problem
- QR codes in emails, documents, or printed materials
- Workplace collaboration platforms
- Phone calls from someone claiming to be from IT or another trusted organization
- Fake shared-document notifications
- Messages directing employees to sign-in pages
- Requests that appear to come from customers, vendors, coworkers, or executives
Employees should treat an unexpected QR code with the same caution as an unfamiliar link.
A caller knowing an employee’s name, company, job title, or other personal information is not proof that the request is legitimate. Likewise, a message appearing inside a familiar collaboration platform may still come from a compromised account.
Whether it arrives by email, text, phone, or a collaboration platform, the goal is often to get someone to act before verifying the request.
Phishing Targets More Than Passwords
Phishing attacks do not always stop at stealing a password.
Attackers may try to steal passwords, capture MFA codes, trigger fraudulent login approvals, or convince employees to change authentication settings.
Employees should never approve an MFA request they did not initiate and should question unexpected instructions to reset authentication methods, enroll a new device, change account settings, or take immediate action on an account.
If a message claims that a password, MFA method, passkey, or account setting requires attention, employees should go directly to the service or contact their IT team through the normal support process instead of following instructions in the message.
Strong authentication controls are important, but employees still need to recognize attempts to trick them into bypassing or misusing those controls.
Verify Unusual Requests
Employees do not need to question every routine interaction, but certain requests should automatically trigger additional verification.
These include requests to:
- Send money or change payment information
- Share a password, authentication code, or sensitive information
- Approve an unexpected login or MFA request
- Install software or provide remote access
- Open an unexpected file or sign in through an unfamiliar link
- Change authentication or security settings
- Bypass a normal process because the matter is urgent or confidential
Verify unusual requests through a separate, trusted channel.
If a coworker emails about a financial transaction, call that person using a number you already have.
If a vendor asks to change payment information, follow your organization’s established verification process.
If someone claiming to be from IT contacts you unexpectedly, reach out through your normal IT support channel.
Do not use the phone number, link, email address, or contact information contained in the message you are trying to verify.
Reporting Quickly Matters
Employees may hesitate to report suspicious activity when they are unsure whether something is malicious.
They may also delay after clicking a link, entering information, opening an attachment, or approving an authentication request because they are concerned they made a mistake.
Waiting to report the incident gives an attacker more time to act.
If an employee clicks a suspicious link, scans a QR code, opens an attachment, enters credentials, approves an authentication request, or sends sensitive information, they should report it immediately so the security team can investigate.
No training program will prevent every mistake, but fast reporting can help limit the impact.
Early reporting gives the security team more time to investigate what happened, assess potential exposure, and contain malicious activity.
Organizations can support that behavior by making the reporting process simple and clear. Employees should know exactly where to report a concern without having to search for instructions during a possible incident.
Employees should also understand that reporting something that turns out to be legitimate is still the right behavior.
The goal is to build a culture where employees report suspicious activity quickly rather than hesitate because they are worried they made a mistake.
Phishing Training Has to Change Too
A once-a-year security course can cover the basics, but employees make security decisions throughout the year.
Training should reflect the attacks and situations employees are most likely to encounter.
Phishing simulations can provide useful practice when they reflect realistic scenarios rather than predictable test emails. Simulations should evolve alongside real-world techniques and may include scenarios involving QR codes, credential requests, collaboration tools, unusual financial requests, or impersonation attempts.
Training should also account for different roles.
An employee responsible for payments may face different social engineering attempts than employees in other roles. Attackers may target executives, IT administrators, HR employees, and finance team members differently because of the access or authority each role ha
Organizations should also look beyond click rates when evaluating these programs.
Useful measurements can include:
- Reporting rates and speed
- Recurring mistakes
- Performance by employee group
- Improvement over time
Simulations should help employees build better security habits, not simply catch them making mistakes.
What Employees Need to Remember
Phishing techniques will continue to change, but employees do not need to memorize every new tactic. When a request seems unusual, verify it through a trusted channel before acting. If something goes wrong, report it quickly.
Those habits matter whether the attack begins with an email, text message, QR code, phone call, collaboration platform, or compromised account.
Instead of asking only, “Does this message look legitimate?” employees should also ask, “Does this request make sense, and should I verify it before I act?”
Learn more about CISO Global’s Security Awareness Training and how ongoing training and realistic phishing simulations can help employees recognize and respond to suspicious activity.
Have questions about your organization’s security awareness program? Contact CISO Global to speak with our team.