Email Scams: How to Spot Phishing in 2026
Phishing is now the top threat reported by individuals. Here are the campaigns actually observed, the official figures, and a simple method to decide in under a minute.
Recent figures
- Phishing ranks as the top threat and accounts for 1 in 3 assistance requests, up 70% in 2025 (Cybermalveillance.gouv.fr report published in March 2026).
- Over 500,000 victims assisted in one year, a +20% increase compared to 2024.
- Fraud involving a fake bank advisor, which often follows a phishing email or SMS, rose by 159%; wire-transfer fraud rose by 170%.
- Data leaks (telecom operators, e-commerce sites, delivery companies…) jumped by 107%: that's why fake messages now know your name, your number, sometimes even your latest order.
Source: Cybermalveillance.gouv.fr, 2025 activity and threat report.
How email phishing works
Scammers impersonate an organization you trust: a bank, courier, phone operator, government agency, or even your employer. The logo is copied, the layout reproduced, the tone official. There's only one goal: get you to click, then to enter something.
An important point revealed by 2025 investigations: in most mass campaigns, the payment isn't even actually charged. The form is there to collect your card number and personal details. This data is then used for a second scam, often the "fake bank advisor" call that comes a few days later — the caller already knows your real information and uses it to trick you into approving a transfer.
Another variant: the attachment. An "invoice", a "delivery note", a "resume". Once opened, it installs a program that spies on the device or locks files for ransom. A simple rule that protects against almost everything: never open an attachment you weren't expecting.
Fake emails and texts actually seen in 2025-2026
The stuck package (the classic)
"Your package couldn't be delivered. Pay $1.95 in re-routing fees." The most impersonated brand two years running is Mondial Relay. The amount is deliberately tiny: it feels risk-free and serves to capture your card details.
"Hi, are you home?"
A massive wave in summer 2025. The message contains no link — on purpose. Some apps disable links from unknown numbers, but once you reply, the conversation becomes "legitimate" and subsequent links become clickable. On the other end, it's a bot replying automatically.
The fake fine
Branded like official traffic-fine agencies: "unpaid fine, settle before the penalty increases". Some of these fake pages had a genuine-looking payment module and charged $135 per victim, on top of stealing card details.
The fake toll / fake operator bill
A 2025 trend: fake emails from highway toll operators exploiting barrier-free toll systems. The same pattern appears in West Africa with fake "Canal+ invoice", "Orange account regularization" or "your Wave account will be suspended" emails.
The fake IT department (at work)
"Your mailbox will be deactivated tonight, confirm your password." The goal: take over the work email account to later hijack a supplier payment.
Checking the sender in 20 seconds
- Tap the sender's name to display the full address. Look at what comes after the @: it's the only part that matters.
- Read the domain from right to left. In service.mondialrelay.delivery-tracking.net, the real site is delivery-tracking.net, not Mondial Relay.
- On mobile, press and hold the link without releasing: the real address appears.
- Don't reply and don't call the number given in the email. Look up the official number yourself, on your bill or in the app.
Warning signs in an email
- The full sender address doesn't match the displayed name (e.g. "Orange Customer Service" from a @gmail.com address).
- The domain mimics the real one: mondial-relay-tracking.info, tax-refund-service.net, orange-secure-account.com.
- The message creates urgency with a deadline: "within 24 hours", "before a penalty applies", "final notice".
- You're asked for a tiny amount (a couple of dollars or a few hundred FCFA): the real goal is your card number, not that small sum.
- The displayed link differs from the real one (long-press it on mobile to see the real address).
- An unexpected attachment: .zip, .apk, .html, an "invoice" you weren't expecting.
- You're asked for a password, an SMS code, or your banking details.
- The email calls you "Dear customer" while the real service actually knows your name.
What to do
- Don't click any link: open the app or official website yourself.
- Never open an unexpected attachment, even from a known contact.
- If you entered your password: change it immediately everywhere it was used, and enable two-step verification.
- If you entered your card details: block your card right away by calling the number on the back of it.
- Expect a call from the "bank advisor" in the following days: a bank never asks you to approve a transfer or share a code over the phone.
- Report the email as phishing, then delete it.
Frequently asked questions
The email knows my name and my last order, so it must be real?
No. Assistance requests linked to data leaks more than doubled in 2025: entire customer databases are circulating. Knowing your name proves nothing.
I only clicked, without entering anything. Is that serious?
The risk stays low if you didn't enter or download anything. Close the page, don't go back to it, and watch your accounts for a few days.
They only asked for $2: why all the fuss?
Because that $2 isn't the real target. The real prize is your card data, later reused for a much costlier scam.
Unsure about an email you received?
Paste it into our tool, choose the "Email" channel, and get a verdict in seconds.
Check a suspicious messageUne personne sur deux a déjà reçu ce type de message. Partagez avant qu'elle ne tombe dans le piège.
Envoyer ce guide sur WhatsAppSee also: Instagram Scams · LinkedIn Scams
