Common signs include unexpected requests for credentials, urgent language, spoofed sender addresses, suspicious links, and messages that pressure staff to bypass normal process. Smishing and spear phishing often use personal detail or apparent authority to increase trust. A spike in unusual login attempts, anomalous email patterns, or repeated requests for sensitive data can also indicate active targeting.
How phishing campaigns usually reveal themselves before they succeed
Phishing is often noisy before it is effective. The earliest evidence is usually behavioural rather than technical: staff receive unexpected credential prompts, messages that create urgency, or requests that try to move them off approved process. The strongest warning signs are often clusters, such as multiple users receiving similar lures, repeated sender spoofing, or a rise in suspicious logins after the messages land.
Look for indicators that the attacker is trying to shape behaviour, not just deliver a message. Examples include requests that ask someone to “confirm” access, reset a password, approve a payment, or review a document immediately. In mature environments, those social cues are often visible alongside delivery anomalies such as domain lookalikes, reply-to mismatches, or links that redirect through unfamiliar infrastructure.
What separates ordinary spam from an active targeting pattern
Spam can be broad and opportunistic, but phishing campaign usually show an intent to harvest credentials, tokens, or money. That intent often appears in message repetition, role-specific wording, and payloads that are tuned to a department, executive function, or current business event. When attackers know your org structure, their messages tend to become more credible and more operationally specific.
Technical telemetry helps distinguish nuisance mail from a campaign in progress. Watch for sudden spikes in login failures, password reset traffic, mailbox-rule changes, and access attempts from unusual geographies or user agents after message delivery. A single suspicious email may be incidental; a coordinated pattern across inboxes, identities, and authentication logs is much more consistent with active targeting.
Campaigns also leave weak signals in the email layer itself. Reused template language, inconsistent branding, malformed headers, or sender infrastructure that changes only slightly between messages can indicate a coordinated phishing run rather than isolated spam. For teams with sufficient telemetry, correlating email events with identity events is usually more useful than reviewing either source alone.
Risk and Threat Considerations
Phishing becomes materially more dangerous when it is aimed at high-value roles, shared mailboxes, or accounts that can approve payments, reset credentials, or access sensitive systems. Once a victim engages, the next step is often account takeover, session theft, or secondary abuse of trust through internal forwarding, mailbox rules, or impersonation.
Failure mechanism: The campaign succeeds when a user trusts a spoofed sender, follows a malicious link, or enters credentials into a fake login flow, allowing the attacker to capture authentication material or establish access before defenders intervene.
Impact: The result can be credential compromise, unauthorized access, lateral movement through email or SSO-linked services, fraud, data exposure, or a broader incident if the phish reaches privileged or business-critical accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Detects anomalous email and login activity consistent with active phishing. |
| PR.AC — Identity Management, Authentication and Access Control | Phishing targets credentials and access paths, making authentication control central. | |
| Recommendation — Correlate email alerts with identity telemetry to surface campaign activity early. Strengthen authentication and review access events that follow suspicious messages. | ||
| CIS Controls v8 | 8 — Audit Log Management | Phishing campaigns are confirmed through correlated login and mailbox evidence. |
| 9 — Email and Web Browser Protections | Directly addresses malicious email delivery, links, and spoofed sender abuse. | |
| Recommendation — Centralise and review email, auth, and mailbox logs for coordinated abuse. Apply email and browser protections to block spoofing, payloads, and risky links. | ||
| NIST SP 800-63 | 5 — Digital Identity Guidelines | Phishing often exploits weak or non-phishing-resistant authentication flows. |
| Recommendation — Prefer phishing-resistant authenticators for accounts that would be high-value targets. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Exposure | Phishing often aims to steal credentials, tokens, and other secret material. |
| NHI-03 — Identity and Access Governance | Campaigns become dangerous when they can reach high-privilege or poorly governed accounts. | |
| Recommendation — Reduce exposed secrets and rotate any credentials obtained through suspicious messages. Review privileged access paths and tighten governance on accounts likely to be targeted. | ||
| MITRE ATT&CK | T1566 — Phishing | Captures the delivery and social-engineering techniques used in phishing campaigns. |
| T1110 — Brute Force | Repeated login attempts after phishing are a common sign of credential abuse. | |
| T1078 — Valid Accounts | Successful phishing often leads to abuse of stolen credentials or sessions. | |
| Recommendation — Map observed lure patterns to phishing techniques and refine detections around them. Alert on spikes in failed logins that follow suspicious message activity. Investigate unexpected successful logins as potential valid-account abuse after phishing. | ||
Practitioner Guidance
What to prioritise: Treat phishing as a combined email, identity, and user-behaviour problem. If you only inspect the email content, you will miss the signal that matters most: whether the message is producing authentication anomalies, mailbox abuse, or repeated attempts against the same role or service.
What to verify: Confirm whether the suspicious message triggered any of the following within a short window: failed logins, MFA prompts, forwarding-rule creation, new OAuth consent, password resets, or access from unfamiliar networks. That verification tells you whether the campaign is merely present or already operational.
What good looks like: Security teams can quickly connect reported lures to identity telemetry, preserve the original message and header evidence, and identify whether the campaign is broad spray-and-pray or targeted at specific staff. In practice, that shortens containment time and improves triage priority.
Practitioner takeaway: The most useful phishing signal is rarely the email alone, it is the combination of deceptive content plus downstream identity activity that shows the attacker is trying to turn attention into access.
Related resources from NHI Mgmt Group
- What are the signs that a stealer campaign is targeting creators rather than general consumers?
- What are the signs that a phishing campaign is using an ISO or LNK delivery chain?
- What are the signs that a cryptocurrency phishing campaign is targeting a wallet or exchange?
- What are the signs that an AI impersonation campaign is targeting your organisation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org