A scammer’s best friend is a sense of urgency. If they can get you to do something before raising suspicion, it doesn’t really matter whether you eventually uncover the scam — it’s already too late to stop it.
The danger can be in something as simple as clicking a link inside an email. And that email might look like it’s from your bank, your boss, an old coworker or a company like Amazon or Zoom. This tactic is called phishing, and it can be done by impersonating anyone familiar to you.
If you’re distractedly checking your email, you could inadvertently click a scammer’s link in just a few seconds. Then, as the Federal Trade Commission explains, you’re opening yourself up to ransomware (which locks you out of your computer’s data until you pay the scammer), password theft, identity theft and more.
The scammer can then use your email to propagate itself to everyone in your contact list.
Given the risk, computer security company KnowBe4 tracks the most common subject lines used to perpetrate these phishing expeditions and releases that information each quarter. Here are some of the most common bait subject lines that scammers have recently used to get people to click links in emails:
- ACTION: Complete Request Form Below
- Guest feedback report
- Your Signature is Missing
- Microsoft: Large Numbers of files were recently deleted
- Amazon: You are a view-only recipient for [[company_name]]
- Zoom: You were mentioned in a meeting transcript
- Contract Submittal
- Email Account Concern
- Password Expiration Notice
- IT: Company Policy Update: AI Tools
IT notifications and account issues are some of the most reported recent phishing attempts, according to KnowBe4.
So if you see any of these subject lines in your inbox, don’t click the links inside the message. If you think the email might be legitimate, go to the website in question — whether it is your bank or a retailer — to check the status of your account directly.
KnowBe4 also warns that phishing emails containing QR codes (quick response codes) are on the rise. QR codes are two-dimensional barcodes that can be scanned with a smartphone camera — and can be easily spoofed by bad actors and cybercriminals.
Stu Sjouwerman, CEO of KnowBe4, says:
“The prevalence of HR and IT-themed phishing attempts, coupled with emerging techniques like QR code integration, presents a complex threat landscape. These tactics are particularly deceptive as they leverage the perceived legitimacy of trusted sources, often prompting hasty actions before verification.”
Aside from being vigilant about your inbox, the FTC lays out some valuable ways to protect yourself, including using security software and ensuring it updates automatically.
Another important step is enabling multifactor authentication (sometimes called two-factor authentication or 2FA) so that scammers need more than just your password to get at your stuff.

Add a Comment