Warning signs include unexpected attachments, especially disk image or archive formats, urgency around bids or agreements, small spelling errors in company names or addresses, and sender domains that closely resemble the real organisation. Another strong indicator is a message that borrows authentic project details, executive names, or logos to create false legitimacy.
What makes a phishing email look targeted rather than generic
A targeted phishing email usually feels unusually specific. It borrows real names, projects, suppliers, signatures, or logos, and often references a current deal, invoice, bid, or internal process. That specificity is meant to reduce doubt, so the most useful indicator is not just “the email is suspicious,” but “the message seems tailored to your organisation and role.”
Look for inconsistencies between the surface realism and the underlying message mechanics. The sender domain may differ by a single letter, use a lookalike subdomain, or route through an address that does not fit normal business communication. The attachment type can also be a clue, especially if the email pushes archive files or disk images that are not normal for the workflow.
Targeted campaigns also try to create pressure. Urgency, secrecy, time-sensitive approvals, and requests to bypass normal checks are common because they push the recipient to act before validating the request. That combination of realism plus pressure is often what separates a run-of-the-mill spam message from a focused phishing attempt.
Signals that matter most during triage
When triaging a suspected targeted phishing email, the strongest signs are the ones that tie directly to social engineering intent. A message that matches a real business context too closely, yet arrives from a slightly wrong sender, should be treated as higher risk than a message that simply contains spelling mistakes. Attackers often trade polish for precision, and the more believable the context, the more dangerous the message can be.
Attachment and link handling are the next practical indicators. Unexpected compressed files, disk images, document containers, or links that redirect through unusual domains are all worth scrutiny. In targeted phishing, the payload is often secondary to the impersonation, so a message can look well written and still be malicious if it is trying to move the user toward credential entry, malware execution, or payment diversion.
For business email compromise patterns, authenticity cues are frequently copied rather than invented. Executive names, logos, and thread continuity can be enough to bypass routine caution, especially when the email asks for an exception to process. That is why the question is not whether the sender sounds professional, but whether the request aligns with known business behaviour and expected routing.
Risk and Threat Considerations
Targeted phishing matters because it is built to defeat pattern recognition. Once an attacker has enough context to mimic a real relationship, the message can bypass informal review and reach the point where a user clicks, responds, opens an attachment, or authorises an action. That creates exposure to credential theft, malware delivery, payment fraud, and broader account compromise.
Failure mechanism: The campaign succeeds when the recipient trusts the impersonated context more than the technical signals, especially where sender lookalikes, urgent language, and realistic business references suppress verification.
Impact: The result can be mailbox compromise, fraudulent transfers, credential reuse across services, or a wider intrusion path that starts with one believable email and extends into identity abuse or internal lateral movement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 14 — Security Awareness and Skills Training | Trains users to spot phishing cues and verify suspicious business requests. |
| 6 — Access Control Management | Phishing often seeks credential theft and unauthorized access through trusted email channels. | |
| Recommendation — Train staff to verify sender, context, and attachment anomalies before acting. Restrict and review account access paths that phishing could abuse. | ||
| NIST CSF 2.0 | PR.AT — Awareness and Training | Supports recognition and reporting of targeted phishing indicators by users and staff. |
| DE.CM — Continuous Monitoring | Monitoring email and identity activity helps detect suspicious sender patterns and abuse. | |
| RS.AN — Analysis | Analysing reported messages helps confirm targeted phishing patterns and campaign scope. | |
| Recommendation — Deliver phishing-focused awareness that emphasizes lookalike domains and urgent request verification. Monitor email and account activity for unusual sender patterns and suspicious attachments. Analyze reported emails for impersonation cues, lookalike domains, and lure themes. | ||
Practitioner Guidance
What to verify: Verify the request through an independent channel whenever the email asks for payment, credential use, document access, or a fast exception. The practical test is whether the same request would still make sense if the sender name, logo, and wording were removed.
Common mistake: Do not rely on spelling quality alone. Many targeted phishing emails are intentionally clean, because the attacker is optimising for business context and timing rather than sloppy mass delivery.
What good looks like: Teams should be able to identify sender-domain drift, unusual attachment formats, and request urgency without needing to open the message or follow the link. The best outcome is fast reporting, not confident manual interpretation in the inbox.
Practitioner takeaway: Treat realism as a risk signal, not a trust signal, because targeted phishing is most effective when it looks like a legitimate internal or partner conversation at the exact moment a busy recipient is least likely to verify it.
Related resources from NHI Mgmt Group
- What are the signs that email security is failing against targeted phishing campaigns?
- What are the signs that a phishing or spear phishing campaign is designed to evade traditional email controls?
- What are the signs that a phishing campaign is using PhaaS infrastructure instead of a simple spoofed email?
- How do teams decide whether a file-sharing notification is part of a phishing campaign?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org