← Back to blog
Phishing evolves, but 5 main scam families account for 80% of attacks observed across our analyses. Knowing them is protecting yourself. Here's the top 5 seen on Fiabli mailboxes in 2026, with the visual indicators that give them away.

1. Fake tax refund (IRS, HMRC, etc.)

The scenario: "You're entitled to a refund of $387.42" or "Error in your filing, action required". The email perfectly mimics the agency's design. The link leads to a fake site asking for bank details + card code "for verification".

Indicators: domain like irs-secure.com, hmrc-refund.eu, tax-service.co — official agencies only use their official domains. Any official communication happens via your taxpayer portal, never via email link.

2. Fake parcel tracking (UPS, FedEx, DHL, Royal Mail)

The scenario: "Your parcel is awaiting delivery, customs fee $2.99 to settle". The ridiculous amount lowers your guard. The fake site captures your credit card and then debits hundreds of dollars in recurring charges.

Indicators: domains like parcel-tracking-ups.net, fedex-customs.co. Carriers NEVER ask for fees by email with a payment link. When in doubt, go directly to the official site and enter your tracking number.

3. Fake Amazon, Microsoft, Apple, Google

The scenario: "Your order #4827 has been suspended", "Suspicious login detected", "Confirm your identity". The email mimics perfectly. The link leads to a fake login page that steals your credentials.

Indicators: domain with substituted character (amaz0n.com with zero, microsoft-securïty.com), login request via clicking a link rather than going to the app. Real brands always say "sign in via the app" and NEVER "click here to verify".

4. Sextortion (webcam blackmail)

The scenario: "I hacked your computer, I have compromising images, pay X bitcoins or I'll release them to your contacts". The email sometimes mentions one of your real passwords (recovered from a public data breach).

Indicators: bitcoin demand, threat of release, anxiety-inducing tone. No real hacker would send a threatening email if they had truly compromised your webcam — they would act directly. It's industrial-scale bluffing, to delete without responding. If a password is mentioned, change it immediately on the affected services.

5. CEO fraud / wire fraud

The scenario (target: businesses): An email claims to come from the CEO or CFO, requesting an urgent transfer to a supplier or for a "confidential operation". Often sent end-of-week, when internal verification is harder.

Indicators: slightly modified sender address (e.g., ceo@fiabli-corp.com when the CEO is on fiabli.io), time pressure, instructions not to mention it to other colleagues. Golden rule: any unusual transfer must be verbally verified with the supposed initiator via a known number.

How Fiabli detects these 5 scams

The 5 patterns above share technical signatures that Fiabli automatically checks on every email:

  • Typosquatting and brand spoofing domains
  • Known fraudulent URLs (PhishTank, shared knowledge base)
  • Failed email authentication (SPF, DKIM, DMARC)
  • Linguistic patterns of urgency and pressure
  • Unusual payment or banking information requests

Our AI (Claude Haiku 4.5 + Sonnet 4.6 on ambiguous cases) assigns a risk score to each email in under 2 seconds. Activate protection on your mailbox in 2 minutes.

Ready to protect your mailbox?

Activate Fiabli in 2 minutes. First verdict in under 2 seconds. Free plan forever.

Create a free account

Related articles