The Most Common Email Keywords Everyone Should Know to Avoid Phishing Attacks
Phishing emails are by no means new, but as people spend most of their lives online during the ongoing COVID-19 pandemic, the possibilities are increasing. In fact, the number of phishing sites increased by 25% in 2020 compared to 2019.
One way to reduce the likelihood of fraud is to pay close attention to the emails they receive (or at least the ones they intend to open). To determine exactly what to look for, Expel analyzed 10,000 malicious emails and released a report on the most common keywords found in the subject of phishing emails. Here’s what you need to know.
Understanding scam tactics
An Expel report found that scammers use a combination of three strategies to get people to interact with their emails:
- Imitation of legitimate business activities
- Create a sense of urgency
- Encouraging the recipient to take action
“Attackers are trying to trick people into providing them with their credentials. The best way to do this is to legitimize the letter, induce one clear action, and spice it up with emotion — urgency or fear of loss is the most common, ” said Ben Brigida, director of SOC operations at Expel, to TechRepublic. “The actions are as simple as ‘go to this site’ or ‘open this file’, but the attacker wants you to move too fast to stop and ask if it is legal.”
Most common keywords used in subject lines of phishing emails
The full report provides additional details and examples of how and why these keywords are used in the subject lines of phishing emails. For now, here’s a rundown of a few that should be approached with extreme caution:
Check
Examples of real subject lines:
- RE: INVOICE
- Missing Inv ####; From [Official Company Name]
- INV ####
New
Examples of real subject lines:
- New message from ####
- New Scanned Fax Delivery for ####
- New fax transmission from ####
Message
Examples of real subject lines:
- Message from ####
- You have a new message
- Phone message for ####
the necessary
Examples of real subject lines:
- Verification required!
- Action required: expiration notification to [work email address]
- [Action required] Password expired
- Attention required. Support ID: ####
[Empty subject]
According to the report, “Blank subject lines are usually bypassed without automatic security measures — security cannot scan phishing or spam keywords if they are not there.”
File
Examples of real subject lines:
- Do you share a file in Google Drive
- [Name] sent you some files
- File- ####
- [Company name] Sales project files and RFQ
Inquiry
Examples of real subject lines:
- [Company Name] SALES PROJECT FILES AND PRICE REQUEST
- [Company Name] – Request Form W-9
- Your Service Request ####
- Request notification: ####
Action
Examples of real subject lines:
- Action required: expiration notification to [work email address]
- Action Required: [Date]
- Action required: Verification message sent on [Date]
- [Action required] Password expired
Document
Examples of real subject lines:
- File Document ####
- [Name], you have received a new document in the [Company System]
- [Name] shared a document with you
Examination
Examples of a real subject line:
- Verification required!
eFax
Examples of real subject lines:
- eFax with ID: ####
- EFax® message from “[phone number]” – 2 pages, Caller ID: + [phone number]
VM
Examples of real subject lines:
- VM from [phone number] to ext. ### on Tuesday 4 May 2021
- Received VM from **** #### – for <[username]> July 26, 2021
- ‘”” ”1 VMAIL RECEIVED Monday 21 June 2021 03:02:55” ”