Email Phishing Attacks: When the Email Looks Normal but the Request Is Wrong

A supplier sends an invoice that looks familiar.
The company name is correct. The invoice format is familiar. The amount is consistent with previous work.
Near the bottom is one change:
Please use our new bank account for future payments.
There may be no suspicious attachment, no badly written message and no obvious warning banner.
The important question is no longer simply whether the email looks like phishing. It is whether the business action being requested should be allowed to happen on the strength of an email alone.
That distinction changes how businesses should think about an email phishing attack.
The Email Is Often Only the Delivery Method
Phishing is usually discussed as an email problem.
Look at the sender. Check the link. Be careful with attachments.
Those checks still matter, but they focus heavily on the message itself. The outcome the sender wants is usually something beyond the inbox.
A message may be trying to get someone to:
redirect a payment
enter account credentials
disclose internal information
approve a request
grant or change system access
change an existing business instruction
In each case, the email is only the mechanism used to start the action. This means an email does not necessarily need to look obviously malicious to create risk. It only needs to make the requested action appear legitimate enough to continue.
Some Phishing Does Not Need to Break Anything
Consider the payment example.
If an employee accepts new bank details and updates them in the company's normal payment process, the accounting system may behave exactly as designed.
The employee is authorised. The payment workflow works. The transaction is processed normally.
The failure happened earlier: the business instruction itself was not genuine.
Many cybersecurity controls are designed to detect something technically abnormal — malicious files, suspicious links, unusual login activity or harmful software. But a fraudulent business instruction can lead an authorised employee to perform a technically legitimate action.
The problem is no longer simply:
"Did the security system block the email?"
It becomes:
"What evidence does the business require before this type of instruction is accepted?"
Familiarity Can Be Part of the Risk
An attack does not need to construct an entirely new scenario to be convincing. It can simply use a business relationship that already exists.
A supplier normally sends invoices. A manager normally requests documents. IT normally sends account-related instructions. A cloud platform normally asks users to sign in. None of that needs to be faked — only one detail inside it does.
That is what makes this different from a request that looks out of place. The context around it is real. The business relationship is real. Only the specific instruction inside it has changed, and the surrounding context is exactly what makes that change easy to miss.
Put the Control Around the Action, Not Only the Message
This leads to a different way of designing phishing protection.
Instead of expecting employees to correctly classify every questionable email, businesses can identify a small number of actions where an email is never sufficient authority on its own.
For example:
A change to supplier bank details may require confirmation through an established contact method.
A request involving credentials can direct employees to access the relevant service independently rather than through the message.
Release of sensitive information may require an existing approval process regardless of who asks for it.
An unusual access change may need confirmation from the responsible system or business owner.
The control is attached to the action, not to whether the employee thinks the email looks suspicious. Two employees may judge the same email differently. The business process does not have to.
This Also Changes the Role of Security Awareness
Employees still need to recognise common phishing indicators. But awareness training becomes more useful when it moves past a single question — can you spot a suspicious email — and adds a second, more practical one: which requests require a different process before you act.
That gives employees something more reliable than intuition. They do not need to determine with certainty whether every message is genuine or fraudulent. For certain high-impact actions, they simply know that the email itself is not enough.
Design the Rule Before the Email Arrives
Businesses do not need employees to treat every email as suspicious.
They need to decide in advance which actions require independent verification.
A change to payment details, a request for credentials, the release of sensitive information or an unexpected access change can all have one thing in common: the rule for handling them should already exist before the email arrives.
That removes an important decision from the moment itself. The employee no longer has to decide whether the email is convincing enough to trust. The business has already decided that certain actions require additional evidence.
That is the broader lesson behind an email phishing attack: sometimes the inbox is only where the instruction begins. The real control belongs at the point where the business decides whether to act on it.
For a broader view of how identity, endpoints, networks, backup and other controls fit together, read our Business Cybersecurity Guide.




