Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response What are the signs that a phishing campaign…
Threats, Abuse & Incident Response

What are the signs that a phishing campaign is targeting your organisation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Threats, Abuse & Incident Response

Common signs include unexpected requests for credentials, urgent language, spoofed sender addresses, suspicious links, and messages that pressure staff to bypass normal process. Smishing and spear phishing often use personal detail or apparent authority to increase trust. A spike in unusual login attempts, anomalous email patterns, or repeated requests for sensitive data can also indicate active targeting.

How phishing campaigns usually reveal themselves before they succeed

Phishing is often noisy before it is effective. The earliest evidence is usually behavioural rather than technical: staff receive unexpected credential prompts, messages that create urgency, or requests that try to move them off approved process. The strongest warning signs are often clusters, such as multiple users receiving similar lures, repeated sender spoofing, or a rise in suspicious logins after the messages land.

Look for indicators that the attacker is trying to shape behaviour, not just deliver a message. Examples include requests that ask someone to “confirm” access, reset a password, approve a payment, or review a document immediately. In mature environments, those social cues are often visible alongside delivery anomalies such as domain lookalikes, reply-to mismatches, or links that redirect through unfamiliar infrastructure.

What separates ordinary spam from an active targeting pattern

Spam can be broad and opportunistic, but phishing campaign usually show an intent to harvest credentials, tokens, or money. That intent often appears in message repetition, role-specific wording, and payloads that are tuned to a department, executive function, or current business event. When attackers know your org structure, their messages tend to become more credible and more operationally specific.

Technical telemetry helps distinguish nuisance mail from a campaign in progress. Watch for sudden spikes in login failures, password reset traffic, mailbox-rule changes, and access attempts from unusual geographies or user agents after message delivery. A single suspicious email may be incidental; a coordinated pattern across inboxes, identities, and authentication logs is much more consistent with active targeting.

Campaigns also leave weak signals in the email layer itself. Reused template language, inconsistent branding, malformed headers, or sender infrastructure that changes only slightly between messages can indicate a coordinated phishing run rather than isolated spam. For teams with sufficient telemetry, correlating email events with identity events is usually more useful than reviewing either source alone.

Risk and Threat Considerations

Phishing becomes materially more dangerous when it is aimed at high-value roles, shared mailboxes, or accounts that can approve payments, reset credentials, or access sensitive systems. Once a victim engages, the next step is often account takeover, session theft, or secondary abuse of trust through internal forwarding, mailbox rules, or impersonation.

Failure mechanism: The campaign succeeds when a user trusts a spoofed sender, follows a malicious link, or enters credentials into a fake login flow, allowing the attacker to capture authentication material or establish access before defenders intervene.

Impact: The result can be credential compromise, unauthorized access, lateral movement through email or SSO-linked services, fraud, data exposure, or a broader incident if the phish reaches privileged or business-critical accounts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM — Security Continuous MonitoringDetects anomalous email and login activity consistent with active phishing.
PR.AC — Identity Management, Authentication and Access ControlPhishing targets credentials and access paths, making authentication control central.
Recommendation — Correlate email alerts with identity telemetry to surface campaign activity early. Strengthen authentication and review access events that follow suspicious messages.
CIS Controls v88 — Audit Log ManagementPhishing campaigns are confirmed through correlated login and mailbox evidence.
9 — Email and Web Browser ProtectionsDirectly addresses malicious email delivery, links, and spoofed sender abuse.
Recommendation — Centralise and review email, auth, and mailbox logs for coordinated abuse. Apply email and browser protections to block spoofing, payloads, and risky links.
NIST SP 800-635 — Digital Identity GuidelinesPhishing often exploits weak or non-phishing-resistant authentication flows.
Recommendation — Prefer phishing-resistant authenticators for accounts that would be high-value targets.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ExposurePhishing often aims to steal credentials, tokens, and other secret material.
NHI-03 — Identity and Access GovernanceCampaigns become dangerous when they can reach high-privilege or poorly governed accounts.
Recommendation — Reduce exposed secrets and rotate any credentials obtained through suspicious messages. Review privileged access paths and tighten governance on accounts likely to be targeted.
MITRE ATT&CKT1566 — PhishingCaptures the delivery and social-engineering techniques used in phishing campaigns.
T1110 — Brute ForceRepeated login attempts after phishing are a common sign of credential abuse.
T1078 — Valid AccountsSuccessful phishing often leads to abuse of stolen credentials or sessions.
Recommendation — Map observed lure patterns to phishing techniques and refine detections around them. Alert on spikes in failed logins that follow suspicious message activity. Investigate unexpected successful logins as potential valid-account abuse after phishing.

Practitioner Guidance

What to prioritise: Treat phishing as a combined email, identity, and user-behaviour problem. If you only inspect the email content, you will miss the signal that matters most: whether the message is producing authentication anomalies, mailbox abuse, or repeated attempts against the same role or service.

What to verify: Confirm whether the suspicious message triggered any of the following within a short window: failed logins, MFA prompts, forwarding-rule creation, new OAuth consent, password resets, or access from unfamiliar networks. That verification tells you whether the campaign is merely present or already operational.

What good looks like: Security teams can quickly connect reported lures to identity telemetry, preserve the original message and header evidence, and identify whether the campaign is broad spray-and-pray or targeted at specific staff. In practice, that shortens containment time and improves triage priority.

Practitioner takeaway: The most useful phishing signal is rarely the email alone, it is the combination of deceptive content plus downstream identity activity that shows the attacker is trying to turn attention into access.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org