Warning signs include unusual login prompts, unexpected file-sharing requests, urgent payment changes, strange inbox forwarding rules, and users reporting that messages feel plausible but slightly off. In ransomware cases, a malicious attachment or link often precedes broader file encryption. Security teams should treat repeated user confusion and multiple similar reports as early indicators of active abuse.
How to recognize the first signs that a phishing campaign is working
The earliest success signal is usually not a confirmed compromise, but a pattern shift: users start behaving differently because the message has created urgency, confusion, or trust. Look for repeated login prompts, unexpected document-sharing or payment-change requests, and replies that show the attacker has persuaded someone to take an action they would normally question.
A useful way to read the signal is to separate noise from momentum. One odd email may be harmless, but several people reporting the same message, the same sender theme, or the same “slightly off” urgency is often the moment a campaign begins to move from delivery to engagement.
When the campaign is active, the attacker’s next step often leaves a visible trail in identity and email behaviour. Security teams should watch for mailbox forwarding rules, unusual MFA prompts, authentication fatigue, and access attempts that follow the initial lure. For controls around phishing-resistant authentication and user sign-in protection, the NIST SP 800-63 Digital Identity Guidelines remain a useful reference point.
What “success” looks like before the obvious compromise
Phishing success rarely starts with ransomware or a public breach. It usually starts with partial trust: a user clicks, enters credentials, approves a prompt, opens a file, or follows an instruction that creates a new foothold. That is why early warning signs include small behavioral anomalies, not just dramatic security events.
In business email compromise and impersonation cases, the campaign often shows up as a change in communication patterns, for example a finance request that bypasses normal review, a supplier message that asks to update bank details, or a conversation that becomes unusually time-sensitive. If the attacker has gained mailbox access, forwarding and inbox rule changes are especially important because they indicate the campaign has moved from persuasion to persistence.
Attackers also rely on social proof. Multiple users asking whether a message is legitimate, or reporting that it “looks real but not quite right,” is a strong operational signal that the campaign is landing. That feedback loop matters because it tells defenders the lure is convincing enough to continue, adapt, and target additional recipients.
The same pattern often appears in brand impersonation and credential theft incidents. NHIMG’s Workforce Identity Security Guide is useful here because it ties the warning signs to the control failures that let a phishing attempt progress from inbox to account takeover. NHIMG’s Identity Provider and SSO Security Guide is also relevant when the first visible symptom is suspicious sign-in activity rather than a confirmed message click.
What defenders should watch when the campaign is moving into abuse
Once a phishing attempt is succeeding, the observable signs usually cluster around access, email control, and user confusion. A good triage question is whether the message is merely being seen, or whether it is now changing identity state, mailbox state, or payment workflow state. The second case is materially more serious because it means the attacker has influenced an actual business process.
For mailbox abuse, hunt for new forwarding rules, deleted sent items, unusual out-of-office replies, and access from unfamiliar locations or devices. For payment or procurement fraud, look for abrupt beneficiary changes, altered approval paths, and urgency framed as secrecy. For ransomware precursors, a malicious attachment or link may precede broader file encryption, so repeated reports about the same lure should be treated as early incident activity, not just awareness noise.
At the team level, the most useful operational signal is convergence: user reports, authentication alerts, and email-control changes all pointing to the same campaign. That is the point where investigation should shift from message analysis to impact analysis, because the real question is no longer “Is this phishing?” but “Has the attacker already gained a usable foothold?”
NHIMG’s Marks and Spencer cyberattack 2025 is a good example of how impersonation can move from a social engineering event into wider operational disruption. For a broader incident pattern, the MailChimp Breach shows how social engineering can expose credentials and downstream assets after the initial human mistake.
Risk and Threat Considerations
Phishing becomes materially dangerous once it stops being a simple message problem and starts creating account, mailbox, or payment-path changes. The main risk is that an attacker can turn a convincing lure into a foothold before the organization realizes the campaign is active, especially when multiple users are engaged and the message theme feels credible.
Failure mechanism: The attacker exploits urgency, authority, or familiarity to induce a login, approval, file open, or payment change, then uses that action to gain persistence, access, or fraudulent influence.
Impact: Early success can lead to credential theft, mailbox control, invoice diversion, data access, or ransomware staging, with the visible signs often arriving before the full compromise is confirmed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IA-5 — Authenticator Management | Phishing succeeds when attackers steal or reuse login credentials and tokens. |
| Recommendation — Harden authenticator handling and rotate credentials after suspected phishing. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Early phishing success is often visible in sign-in, forwarding, and access anomalies. |
| Recommendation — Review authentication and mailbox audit trails for suspicious post-lure activity. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | The subject centers on email-borne lures and malicious links or attachments. |
| Recommendation — Block malicious links and attachments and strengthen email filtering controls. | ||
| MITRE ATT&CK | T1566 — Phishing | The question asks how to spot an active phishing or social engineering campaign. |
| Recommendation — Map observed lure behavior to phishing techniques and investigate related access paths. | ||
| OWASP ASVS | V6 — Authentication | Phishing often succeeds by defeating authentication through credential capture or prompt abuse. |
| Recommendation — Strengthen authentication flows to resist credential theft and replay. | ||
Practitioner Guidance
What to prioritise: Treat repeated user reports, unusual sign-in prompts, and mailbox-rule changes as an active campaign, not isolated hygiene issues. Correlate those signals quickly, because the first responder error is usually assuming the messages are only “suspected phishing” when the attacker has already obtained a usable interaction.
What to verify: Confirm whether any account has accepted a prompt, clicked a lure, created a forwarding rule, or changed payment details. If the suspected campaign touches finance, executive mailboxes, or help-desk reset paths, escalate faster than you would for a generic spam wave.
Practitioner takeaway: The key judgment is whether the campaign is still merely delivering messages or has already altered user behavior and access state; once the latter starts, the response should shift from mailbox review to compromise containment.
Related resources from NHI Mgmt Group
- Why do phishing and social engineering still succeed against mature IAM programmes?
- What happens when phishing and social engineering succeed against crypto users?
- What are the signs that a social engineering campaign is actively progressing inside an organisation?
- What are the signs that an AI-assisted social engineering campaign is becoming dangerous?