Home » Business Email Etiquette Articles » Nefarious Business Email Tactics

Nefarious Business Email Tactics

Phishing, spoofing and scams -- how to be aware of nefarious business email tactics.

What You Don’t Know Can Hurt Your Business

Spammers have always had to be creative to get the information they want to exploit. You’ve probably heard of phishing and spoofing. Emails that look like a company or business you use or are familiar with are all in an attempt to trick you.

Supposed confirmations from services or stores you frequent, such as Costco, Amazon, and Apple, all with fake links for fake purchases you didn’t make. Emails claiming you subscribed to anti-virus or accounting services that look pretty darned close to the authentic notifications.

Do not click on those links!

Below are just a handful to keep an eye out for and avoid falling victim to. Then, if they land in your inbox, you’ll know right out of the gate to just hit DELETE!

The one that made me chuckle at how creative some scammers can be is the…

Amazon Subscription Hoax

Who doesn’t have an Amazon account? Who would panic if they had to live without Amazon?

Your Prime benefits are on hold due to a billing issue!

Hello,
We’re unable to charge your payment method for your subscription and any applicable taxes for your next month of Prime. Your Prime benefits are currently on hold.

If you don’t update your payment method in the next 6 days, your membership may be canceled. To restore access to your benefits, please update your payment information.

Prime Membership Notification is in the from field. Prime logo and Amazon TOS are included in the header and footer, respectively. If, of course, you move your cursor over the From field and the clickable Update Information button, and you see it’s a scam.

I bet they get some takers.

The Google Doc Invitation

You may have experienced this latest trickery — an invitation to view a Google Doc. A very legitimate looking email invites you to login at a very impressive fake Google login page and to view the doc.

What caught my eye was the email was addressed similar to hh*@********or.com. That was enough for me to hit delete right then and there. Google jumped on this one and supposedly had it shutdown within an hour. But how many logins did the preptrators get in the interim?

So, with similar requests, always give it a once-over to ensure you recognize the email address in the From field that made the request.

The Unpaid Invoice Trick

yea , we finally did it.
here is the bank confirmation:
bofa_card_statement_support.doc
now f*** off and try not to contact me again or else.

On Jul 6, 2026 at 3:25 AM, em***@*********ny.com wrote:
did you send the money? i need the proof

The above uses profanity and a threatening tone to get you riled up enough that you hopefully won’t stop to think before you click on the attachment. The Subject and the supposed previous email from you reflect your company’s email address to make it appear more authentic.

Remember, faking the use of your email address is the easy part. All they have to do is type it, and don’t worry, it doesn’t mean they’ve accessed your email system. Displaying your address in the To or From fields is just a matter of email software settings. So don’t panic.

The Fancy Company Overcharge Trick

Who the f*** are you and why is there a charge from xxxxxxxxxxxx.com on my card? Here you can view my statement, get back to me asap.

bofa_card_statement_XXXXXX.doc

Thank you
David Smith

If you do any e-commerce, this will catch your attention. The goal is to get you to think, “Did I incorrectly charge a customer?”

In this example, I’ve received numerous versions where the Subject: field notes different legitimate big-name consulting companies to add to the effect. In one case, the company’s website changed its homepage to state, “…we apologize, the emails were not from us. We were hacked.”

Once again, using profanity and noting your business website domain to get you to click on the attachment is common. Don’t fall for that trap.

The Legal Threat Trick

WTF is this?
I got it in my mail today.
subpoena_from_support.doc

my lawyer will call you tomorrow.

Yours,
Christopher Stephenson
Phone: XXX-XXX-XXXX
Fax: XXX-XXX-XXXX

Subpoena!? Attorney?! Click on that “doc” to see what this is about! Don’t.

What surprised me about the above is that the phone numbers seemed to belong to real people with different names. I feel sorry for them…

The We Can’t Deliver Your Package Trick

Dear Customer,

Your parcel was successfully delivered February 15 to the UPS hub, but our courier cound not contact you. Please check the attachment for complete details!

Yours faithfully,
Seth Jones,
UPS Senior Delivery Manager

Most businesses get UPS deliveries regularly. If you expect a package, you can click the attachment to open it. UPS doesn’t send notices like this; just hit delete. Instead, log in to your UPS account to check your shipments.

You Have an eFax Trick

You received a new eFax from 222-555-1212

Do folks still use faxes? I used eFax back in the day and wasn’t aware enough folks still used it to warrant a phishing email.

Everything in the email looked legit—all the eFax links, when moused over, showed eFax.com. The trick here is the eFax download link. When you hover over the link, the first part shows eFax.com, but if you move your mouse to the end of the link, you can see the phishing site you’d be taken to!

The Business Complaint Trick

Subject: ID 8d6ba737-775e8bdc-f95f16f3-1b460259 – CompanyName Complaint

This message has been generated in response to the company complaint submitted to CompanyName. (CC01) The complaint for the above company was accepted on 07/01/2026.

Please check attached documents for more information. The submission number is id: 8d6ba737-775e8bdc-f95f16f3-1b460259. Please quote this number in any communications with CompanyName.

Of course, as a legitimate business, you’ll jump if you think a complaint is lodged against you. You want to know what’s in the complaint, and you click the link before thinking it through. In this case, mousing over the company’s link showed a .uk domain.

I do not do business outside the USA, so I knew this was a fake. But if you do business globally, you may accidentally click a phishing link. Don’t.

Crypto Purchases

PayPal

2026-07-29

Thank you for your payment to
UID337735 BTC Trade Desk LLC

Here are the details about your automatic payment for 1 Week Dai…
Transaction ID 11L43090EH4027426S
Payment Source PayPal / Bank Card
Recipient UID337735 BTC Trade Desk LLC
Total Amount Paid $235.29 USD
Profile ID I-3T8SYIBAP7T70Y
Next Payment Due Next Week same day
Next Payment Amount $235.29 USD

To change or cancel your automatic payment, please contact the Service Team at: +18056704725

PayPal

Help & Contact | Security | Apps

PayPal is committed to preventing fraudulent emails. Emails from PayPal will always contain your full name or email. Learn to identify phishing

Please don’t reply to this email. To get in touch with us, Help & Contact.

PayPal Customer Service can be reached at +18056704725.

PayPal, Inc. NMLS ID #: 910457

Not sure why you received this email? Learn more

Copyright © 1999-2026 PayPal, Inc. All rights reserved. PayPal is located at 15780 Via Sonata San Lorenzo Ca 94580 United States.

PayPal RT001423:en_US(en-US):1.2.1:c9c0783293d3a

This one goes out of its way to look and sound legit — no need to click on links or to call the “service team” — just hit delete.

Compromised Contacts

Another worth mentioning is an email from a known contact, with all their contacts in the To field, including yours. The content is a single statement about a site or link for you to visit. You can safely assume they have a virus on their computer that is now sending out these emails to everyone they know.

In that case, as a courtesy, let them know they’ve been compromised, ask them to update their virus software, and then have them scan their system ASAP.

Don’t Trust ANYTHING

The above are just a few examples of some of the trickery I have seen recently. Spammers will keep trying to make their emails look legitimate by mimicking sites you visit or by playing on your emotions. Don’t fall for these traps!

As a one-woman show, it’s easy for me to know that some of these emails just don’t apply to my business. But imagine if a larger company with tons of folks using company email addresses had one of these land in their inbox.

If you are unsure and want to check the attachment, scan it with your antivirus software first. Also, making your IT department aware may also help them protect the network from similar communications in the future and identify whoever is responsible.

Your best approach is not to trust any email you don’t expect, that sounds too good to be true, that does not include a recognizable sender, or that has an unusual communication style. And refrain from clicking on any attachments or links in these emails.

Do me a favor and share this post with others and those in your organization so we can help raise awareness. The more online users know about these tactics, the less effective they will be!

Business Email Etiquette eBook

Share the knowledge!

Similar Posts