Almost everyone has been taught the same rule: check who sent it. Look at the sender's address, and if it isn't right, don't click.
That rule made sense when phishing arrived from strangers with clumsy lookalike addresses. It does not cover what is actually landing in inboxes now. The two live phishing campaigns our team pulled apart this summer — the Paperless Post invitation kit, and the credential harvester dressed as a Meta notification — both had the same opening move. The message came from a real account belonging to a real person, because the attackers had already taken that account over.
The sender being real is not evidence. Verify the request, not the person.
Why the sender check stopped working
A compromised account is the most valuable delivery vehicle a phishing operation can get, and there is nothing subtle about why.
The message passes every technical check, because it isn't spoofed — the mail genuinely originated from that account. The display name is right. The address is right. It may arrive in an existing thread. Spam filters have less to work with, and so do you.
More importantly, it arrives pre-trusted. You are not evaluating a message from an unknown company. You are reading something from a colleague, a contractor, a family member. The part of your attention that would normally do the checking has already stood down.
Account takeover also compounds. One compromised inbox produces the contact list, the writing style, the ongoing conversations, and the credibility to compromise the next several — which is why these campaigns spread through a company or a friend group rather than arriving at random.
The three shapes it takes
The unexpected thing to open. An invitation, a shared document, a delivery notice, a photo album. It comes from someone plausible and asks you to sign in to view it. The sign-in page is the attack; the invitation never existed.
The hijacked reply. The attacker replies inside a real thread you have been part of for weeks, matching the tone and referencing details only a participant would know — because they have been reading it. Nothing about the context is fake except the newest message.
The changed ask. The relationship is genuine and the conversation is genuine, and then the request quietly shifts: new bank details for an invoice you were expecting, a gift card errand, an urgent transfer, a password. This is the shape that costs the most money, and the one people most often talk themselves into.
The habit that replaces the sender check
One rule covers all three. Confirm on a different channel than the one it arrived on, every time.
- Arrived by email? Call or text on a number you already had.
- Arrived by text? Call.
- Colleague at work? Message them somewhere else, or walk over.
Never use a phone number, link, or address supplied inside the message. If the message is fake, so is the contact detail in it. That is not a hypothetical — supplying a helpful number to call is a standard feature of these kits.
The cost of this habit is about ten seconds. The cost of skipping it is a wire transfer you cannot recall or an email account you spend a weekend getting back.
Tells that survive a compromised account
The sender is genuine, so stop looking there. These do not go away:
- The ask changed. Payment details, account numbers, or delivery instructions that are different from what was agreed. Treat any change to where money goes as unverified until confirmed by voice.
- Urgency arrives with secrecy. Do it now, don't loop anyone in, I'm about to get on a flight. Real colleagues and real family are rarely both rushed and private about money.
- A sign-in prompt with no reason to exist. An invitation, a shared file, or a delivery notice has no business asking for your email password. When a page asks you to sign in with Google or Microsoft to view something unrelated, that is the attack, whoever sent it.
- The reply goes somewhere else. Hit reply and check where it is actually addressed before you type. Attackers redirect replies to a lookalike address so the real owner never sees the conversation.
- It is slightly off. Odd timing, a greeting they never use, a request outside their role. You know this person's normal. Trust the mismatch enough to check.
And when the message contains a link, the domain is still the final word. The registered domain sits immediately left of the first single slash, and you read it right to left — google.com.secure-login.xyz is not Google, no matter how the page looks or who sent it.
If it was your account that sent it
You may find out because someone tells you. Move quickly, and in this order.
- Change the password now, on the real site, reached by typing the address yourself rather than clicking anything.
- Sign out of every other session. Your account's security page lists active devices and lets you revoke them. A password change alone does not always evict someone already signed in.
- Turn on two-factor authentication, using an authenticator app or a hardware key rather than SMS.
- Check your forwarding rules and filters. Attackers add rules that copy your incoming mail elsewhere, or that auto-archive replies so you never notice the conversation happening in your name. Remove anything you did not create.
- Tell your contacts directly. They received something from you and had every reason to trust it. A short, plain message is enough.
If a file downloaded and you opened it, treat the device itself as compromised rather than just the account, and get help from someone who can check it properly.
Summary
- A genuine sender is not a safe message. Compromised accounts are now a primary delivery method for phishing.
- Verify the request, not the person — on a different channel, using contact details you already had.
- Any change to payment details is unverified until confirmed by voice.
- A sign-in prompt on an invitation, file, or delivery notice is the attack, regardless of who sent it.
- If it was your account, change the password, revoke sessions, enable two-factor, and check your forwarding rules.
Not sure about a message sitting in your inbox right now, even one from someone you know? Paste it into a free Quick Check with Carmen and you will have a read on it in seconds.