Skip to main content
Threat Alerts

Three Real-World Phishing Lures Hitting Inboxes Now and How to Block Them

Recent phishing attacks exploit voicemail notifications, fake SharePoint alerts, and QR code lures. Learn the exact indicators and the defenses that stop them.

Why This Threat Alert Matters Now

Phishing remains the most common entry point for breaches, and the tactics are shifting faster than most security awareness training keeps up with. The 2024 Verizon Data Breach Investigations Report found that 68% of breaches involved a human element, and the majority of those started with a malicious email. But the specific lures that work today are not the same ones from even a year ago. Attackers are borrowing legitimate business tools and workflows, making their messages harder to spot.

We are going to walk through three specific phishing campaigns that have been observed in the wild in recent months. For each, we will show you the telltale signs, the exact technical indicators to check, and the practical controls that will keep these messages out of your inbox or stop them from doing damage if one slips through.

Lure 1: The Voicemail Notification That Is Not from Your Phone System

One of the most effective current lures is a fake voicemail notification. The email appears to come from a unified communications platform like RingCentral, Cisco Webex, or a generic 'Voicemail System'. The subject line is usually something like 'New voicemail from [unknown number]' or 'Transcription of your missed call'.

The body includes a media player icon, a fake phone number, and a prominent 'Play' button. That button does not play audio. It links to a credential-harvesting page that mimics the login portal for Microsoft 365 or Google Workspace. If you enter your password, the attackers capture it and immediately attempt to sign in and establish a session.

We have seen this exact campaign reported by multiple incident responders over the past quarter, and it is effective because it triggers a reflexive action: people want to hear a missed call, especially if they are expecting a callback.

How to Spot This Lure

  • The 'From' address is not from your company's domain and often comes from a free mail provider or a lookalike domain. Check the full address, not just the display name.
  • There is no attachment, but there is a link that goes to a domain that does not match the purported sender's official domain.
  • The message claims urgency ('Your voicemail expires in 24 hours') but there is no voicemail in your actual phone system.

The Practical Block

Set up a mail flow rule in Microsoft 365 or Google Workspace that flags external emails with 'voicemail' in the subject or body and quarantines them. Better yet, configure your email gateway to strip active links from any message that originates outside your organization and contains keywords like 'voicemail', 'missed call', or 'call transcript'. This is a simple transport rule that takes five minutes to implement and will stop a large percentage of these campaigns.

Lure 2: The Fake SharePoint and OneDrive 'You Have New Files' Alert

Attackers are also abusing legitimate file-sharing notifications. They create a fake SharePoint or OneDrive sharing email that looks almost identical to the real thing, including Microsoft logos, 'View in SharePoint' buttons, and even the correct brand colors. The email says someone has shared a document with you, often with a filename that is relevant to your job, like 'Q3_Project_Plan.xlsx' or 'Employee_Handbook_2025.pdf'.

Real Microsoft sharing notifications come from the domain sharepointonline.com or onmicrosoft.com, but these fake ones come from domains like share-pointonline.com or sharepoint-verify.com. The link, when hovered over, reveals a URL that has nothing to do with Microsoft. It leads to a phishing page that requests your credentials to 'view the document'.

In a 2025 report from SlashNext, these file-sharing lures accounted for nearly 30% of all phishing URLs detected in enterprise email traffic in Q1. They work because people are conditioned to expect file-sharing notifications from colleagues, and they are often too busy to scrutinize the sender's domain.

How to Spot This Lure

  • Check the sender domain carefully. Microsoft only sends from microsoft.com, sharepointonline.com, onmicrosoft.com, or notifications.microsoft.com. Any other domain is fake.
  • Hover over the 'View' button. If the URL does not contain sharepoint.com or 1drv.ms, do not click.
  • Real sharing notifications include the name of the person who shared the file and their email address. If that name is not someone you know, treat it as suspicious.

The Practical Block

Enable external sharing notifications to be delivered only for known domains in your tenant. If you do not need to receive sharing links from outside your organization, disable external sharing for sensitive sites. Also, use a browser extension or a security tool that blocks lookalike domains. Many phishing kits are hosted on newly registered domains, so a zero-hour URL reputation service is worth the investment.

Lure 3: QR Code Phishing (Quishing) in PDF Attachments

The third lure is QR code phishing, often called 'quishing'. This one is particularly sneaky because the malicious URL is hidden inside a QR code, so email security filters that scan text URLs often miss it. The email typically contains a PDF attachment that mimics a document from a known vendor, such as a DocuSign request, a delivery notice from FedEx or UPS, or an invoice from a utility company. Inside the PDF, there is a QR code that says 'Scan to view your document' or 'Scan to update your payment information'.

When you scan the QR code with your phone, you are taken to a phishing page that looks like a Microsoft or Google login, or a fake payment portal. Because you are on your phone, the URL is not visible until after you scan, and many mobile browsers do not show the full URL clearly. This has become a top attack vector in 2025, with the Anti-Phishing Working Group reporting a 34% increase in QR-code phishing from the previous year.

How to Spot This Lure

  • Be suspicious of any unexpected email that contains only a PDF with a QR code and minimal text. Legitimate companies usually include a direct link as well.
  • If you receive a QR code from a sender you were not expecting, do not scan it. Instead, visit the company's website directly by typing the known URL into your browser.
  • On your phone, after scanning, check the domain in the browser's address bar. If it is not the official domain of the purported sender, close the page immediately.

The Practical Block

Set your email security gateway to quarantine emails with QR codes in attachments. Several vendors, including Proofpoint and Mimecast, have specific filters for this. If you cannot configure that, a simple rule that flags PDF attachments from external senders for review will help. Also, educate your users to treat QR codes like any other link: if it is unexpected, do not scan.

A Step-by-Step Response When You Suspect a Phishing Email

When you or your team receives a suspicious email, move quickly but methodically. Use this five-step process to contain the risk.

  1. Do not click any links or open any attachments. This is the most critical step. Even previewing an attachment in some mail clients can be risky if it is a malicious file.
  2. Report the email using your organization's reporting tool, such as the 'Report Message' button in Outlook or the Gmail phishing report option. This sends the email to your security team for analysis.
  3. If you clicked a link or entered credentials, immediately change your password and revoke any active sessions. Use the 'Sign out of all sessions' option in your account settings.
  4. Enable multi-factor authentication (MFA) if it is not already active. According to Microsoft, MFA blocks over 99.9% of account compromise attacks. This is the single most effective control.
  5. Notify your IT/security team so they can check for other users who may have received the same email and can hunt for any signs of compromise.

Comparison: Native Defenses vs. Third-Party Email Security

Many organizations rely on the built-in protections of Microsoft 365 or Google Workspace, but these are not sufficient against modern phishing. Here is a quick comparison of what each offers.

Defense LayerNative (Microsoft/Google)Third-Party (Proofpoint, Mimecast, Abnormal)
URL reputationBasic, with blocklists updated periodicallyReal-time analysis of every link, including QR codes
Lookalike domain detectionLimited, often misses typosquatted domainsUses machine learning to flag domains that mimic your company's or known brands
Attachment sandboxingOffered, but may not detonate all file typesDeep sandboxing that executes suspicious attachments in a virtual environment
Phishing simulation and trainingAvailable as an add-on, but basicIntegrated campaigns with advanced reporting
Incident response integrationManual or via APIAutomated email retrieval from all mailboxes

If your organization is small or budget-limited, start with the native tools and add a third-party layer as you can. The cost of a single successful phishing attack — which the IBM Cost of a Data Breach Report puts at $4.45 million on average — far exceeds the subscription cost of a good email security product.

Your Next Move

Do not wait for a real attack to test your defenses. Take these three actions this week:

  • Run a phishing simulation that includes a voicemail lure and a QR code lure. See who clicks and who reports.
  • Implement the mail flow rules described above to quarantine suspicious external emails.
  • Conduct a 15-minute training session on how to check sender domains and hover over links.

Phishing is not going away, but with the right habits and controls, you can make your organization a much harder target. The key is to assume that one of these lures will reach your inbox, and to have the reflexes and technology in place to stop it before it becomes a breach.

Share this article:

Comments (0)

No comments yet. Be the first to comment!