{
  "id": 4576710,
  "title": "4 devious email scams hitting inboxes right now, and how to spot them",
  "url": "https://urgent.news/2026/08/31/4-devious-email-scams-hitting-inboxes-right-now-and-how-to-spot-them",
  "topic": "business",
  "section": "Business",
  "published": "2026-08-31T04:30:00.000Z",
  "source": {
    "name": "Fast Company",
    "slug": "fast-company",
    "url": "https://www.fastcompany.com/91598229/new-email-scams"
  },
  "original_language": "en",
  "account": "Email scams have grown increasingly sophisticated over the past decade. Corporate IT departments have long advised users to watch out for poor grammar, hover over links, and enable two-factor authentication. However, these guidelines no longer suffice in the face of modern email scams. Today's scams are more devious than ever, employing tactics that bypass traditional security measures.\n\nThe first new tactic is called \"Quishing,\" short for QR code phishing. Scammers send emails claiming there's an issue with your Microsoft 365 password or an urgent HR document that requires a DocuSign signature. Instead of a clickable link, these emails contain a QR code. If you scan the code with your phone, you bypass your company's security measures and expose yourself to a malicious page on your personal device. If an email asks you to scan a QR code to verify your identity, treat it as a serious threat.\n\nThe second trick is the \"ClickFix\" clipboard trap. This scam uses a psychological technique to exploit your productivity. You receive a notification email with a document attachment. Upon clicking to open the document, a pop-up error appears, claiming a rendering issue. The pop-up then instructs you to press Win + R, paste a verification code into the Windows Run prompt, and press Enter. This is a trap - the scammer has tricked you into copying malicious code onto your clipboard and executing it in your system terminal. Never copy text from a browser into your computer's command terminal when prompted by an email, as browsers don't require system-level commands to display files.\n\nThe third method is \"Adversary-in-the-Middle\" login cloning. Even with two-factor authentication in place, this scam can break through. You receive an email directing you to a login portal that looks identical to your company's login screen. After entering your username, password, and six-digit code from your authenticator app, the fake login page forwards this information to the real site in real time. Once your account is successfully logged in, the scammer grabs the session cookie, gaining instant access as if they were sitting at your keyboard. Always verify the URL address bar before entering any credentials.\n\nLastly, there's the \"Fake (but real) invoice\" scam. One of the most difficult scams to identify is when a legitimate tech company sends a fake invoice. You receive an official invoice notification from QuickBooks, PayPal, or Google Workspace, complete with your name, an order number, and a phone number to call if you suspect fraud. Spam filters typically pass these emails directly to your primary inbox, as they genuinely appear to come from Intuit, Google, or other reputable companies. Attackers create fake business accounts on these platforms and abuse their invoicing tools to send out scam messages. Never call the phone number provided in the invoice. Instead, log in to your account directly through the official website to verify your billing history.",
  "summary": "For the last decade, email scams have run rampant on the internet. And corporate IT departments have handed out the exact same advice like clockwork: Look for bad grammar, hover over links, and turn on two-factor authentication. But those recommendations have fallen behind the times. Thanks to AI and clever architectural work-arounds, today’s email scams don’t look like scams. They don’t contain…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}