Fastcompany iconFastcompanyAug 31, 2026 ~1 min source read

4 devious email scams hitting inboxes right now, and how to spot them

Those recommendations have fallen behind the times. Look for bad grammar, hover over links, and turn on two-factor authentication.

4 devious email scams hitting inboxes right now, and how to spot them

Share this story

Send the public story page.

Useful takeaways from this story.

Look for bad grammar, hover over links, and turn on two-factor authentication.

Thanks to AI and clever architectural work-arounds, today's email scams don't look like scams.

QR code mobile bypass ("Quishing") You open an email claiming your Microsoft 365 password is about to expire, or that an urgent HR document needs a DocuSign signature.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Look for bad grammar, hover over links, and turn on two-factor authentication. Thanks to AI and clever architectural work-arounds, today's email scams don't look like scams. Here's a handful of new tricks flooding inboxes right now, how they work, and how to stay ahead of them.

How it works

  • Instead of a clickable link, there's a crisp graphic with a QR code asking you to scan with your phone's camera to verify your identity.
  • Your work laptop is heavily guarded by corporate firewalls and link-checkers.
  • QR code mobile bypass ("Quishing") You open an email claiming your Microsoft 365 password is about to expire, or that an urgent HR document needs a DocuSign signature.

Details worth keeping

For the last decade, email scams have run rampant on the internet. Those recommendations have fallen behind the times. In many cases, they don't even care if you have 2FA enabled.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app