The New Phishing Attack Doesn’t Look Like Spam — It Looks Like Someone You Know
Most phishing emails still aren’t very convincing. You get a message from some strange address, the grammar is questionable, there’s a link you’re supposed to click immediately, and something about the whole thing feels wrong before you’ve even finished reading it. Those are easy to spot. The more interesting phishing emails are the ones that don’t look like phishing emails at all. We just ran into one.
A client forwarded us an email that appeared to come from someone at Big Orange Planet. It used the person’s name, the correct company logo, the correct social media links, the correct title and a message that, at first glance, sounded completely reasonable. It even referred to an existing client relationship. The client knew enough about how we normally communicate to recognize that something wasn’t quite right, so they forwarded it to us instead of responding. A second client received essentially the same kind of message within the same week. That caught my attention because this isn’t really the old version of phishing anymore. The attacker isn’t necessarily trying to convince you that you’re getting an email from your bank. They’re trying to convince you that you’re getting an email from someone you already know.
The Email Wasn’t Random
The fake message wasn’t particularly complicated. It claimed that some components supporting the client’s website were coming up for renewal, including plugins and the domain. It introduced a deadline, offered to take care of the updates and then asked the recipient to simply reply with one word: Proceed. There was no outrageous claim, no obviously fake logo and no ridiculous promise of millions of dollars. It looked like ordinary business communication.
That’s what makes this kind of attack interesting. The attacker had enough information to understand that Big Orange Planet actually works with the recipient. They weren’t inventing a relationship out of thin air. They were inserting themselves into an existing one. The sender was using a Gmail address rather than the company’s actual business domain, which was one of the clues that gave it away. But everything surrounding that address had clearly been assembled to make the discrepancy easier to overlook. The signature contained the company’s real branding. The links went to legitimate Big Orange Planet social profiles. The website link was legitimate. The person’s actual job title was there.
Nothing about those individual pieces of information was necessarily fake. The identity surrounding the message was fake. And that’s a different problem. The Federal Trade Commission describes this broader category as business impersonation: a scammer creates an email address or message that appears to come from a business people know and uses that familiarity to get them to act.
Phishing Has Always Been About Trust
At its core, phishing has never really been about email. It’s about trust. The attacker wants you to believe that the person on the other side of the message is someone you can safely interact with. Historically, that meant pretending to be a bank, Microsoft, Amazon, the IRS or some other organization that people already recognize. But businesses have another layer of trust that can be even more useful to an attacker: their vendors, clients, employees, accountants, attorneys, contractors and web developers.
Think about how many ordinary emails you receive from those people without questioning them. A web developer saying your domain is coming up for renewal. An accountant saying they need you to review a document. A contractor sending an updated invoice. A client asking you to send something over. None of those requests sound suspicious because they’re normal parts of an existing relationship. That’s precisely why they work. The attacker doesn’t have to create trust from scratch. They just have to borrow somebody else’s trust.
The Research Is Becoming Part of the Attack
This is the part I think businesses need to pay more attention to. A convincing impersonation doesn’t necessarily require breaking into the company being impersonated. A surprising amount of useful information is already sitting in public. Company websites publish names and job titles. LinkedIn publishes relationships between people and companies. Social media publishes branding and profiles. Websites identify vendors and technology. Press releases announce partnerships. Email signatures get forwarded around.
An attacker can potentially learn who owns a company, who manages its website, who works there, what the company looks like, what social profiles belong to it and which vendors or partners are publicly associated with it. Then they can construct a message that fits into that relationship. That’s a very different attack from sending ten thousand random phishing emails and hoping somebody clicks. It’s closer to social engineering at scale.
We’ve seen a related version of the same problem from the other direction. In The $200 Logo Job That Wanted a Full Legal Department, the issue wasn’t necessarily that any individual piece of the communication was impossible. It was that professional-looking information was being assembled into an unusually convincing package. As I wrote there, information isn’t the same thing as evidence. That distinction becomes even more important when somebody is deliberately using real information to construct a false identity.
Artificial intelligence makes this environment more interesting, too. An attacker doesn’t necessarily need to be a particularly good writer to produce a message that sounds professional, conversational and appropriate to the relationship they’re trying to exploit. AI can make that kind of personalization easier and cheaper, even though we don’t know whether AI was involved in these particular emails. The larger point is that the cost of manufacturing professional-looking communication has fallen dramatically. That’s the same broader problem I explored in Information Is Everywhere. Evidence Is Becoming Rare. The internet has become extraordinarily good at producing information that looks credible. That doesn’t necessarily make the underlying claim more credible.
The Most Dangerous Message May Be the Most Boring One
There’s another reason these attacks can work: they’re boring. The fake email we received wasn’t dramatic. It wasn’t threatening. It wasn’t promising anything. It basically said that something needed attention, there was a deadline, the sender could take care of it and the recipient should reply if they wanted the work handled. That’s exactly the kind of email a business owner might receive dozens of times a year. And that’s why security training that teaches people to look only for obviously suspicious messages has a weakness. Real phishing doesn’t always look suspicious. Sometimes it looks like Tuesday afternoon.
One detail in this particular message was especially interesting. The recipient wasn’t immediately asked to enter a password or transfer money. They were simply asked to reply “Proceed.” That seems harmless, but it creates an opening. Once the recipient responds, the attacker has established that the address is active and that the person is willing to engage. The conversation can then evolve into an invoice, a payment request, a fake renewal portal, a request for credentials or something else entirely. The initial message doesn’t necessarily have to complete the fraud. It only has to get the conversation started.
Your Website Can Be Part of Your Security Perimeter
This is where this becomes relevant to what we do at Big Orange Planet. We spend a lot of time talking about websites as marketing tools. They are. But a company’s website also establishes identity. Your domain is part of your identity. Your email addresses are part of your identity. Your branding is part of your identity. Your social profiles are part of your identity. Your website tells people who you are, what you do and who works for you. That information is valuable to legitimate customers. It’s also valuable to somebody trying to impersonate you. That doesn’t mean businesses should hide their employees or stop publishing contact information. That’s not realistic, and it isn’t particularly useful. It does mean that digital identity deserves to be treated as infrastructure, not decoration.
Domain security matters. Email authentication matters. Account security matters. Keeping control of social accounts matters. Knowing which domains actually belong to your company matters. Google specifically recommends email authentication such as SPF, DKIM and DMARC to help protect domains from spoofing and impersonation. And, perhaps most importantly, your employees and clients need to know what your normal communication looks like.
The Best Defense May Be a Second Channel
There is a surprisingly simple defense against this type of attack: when something feels even slightly unusual, verify it somewhere else. Not by replying to the suspicious email. If someone emails you saying your domain needs to be renewed, call the person you normally deal with. If your accountant sends an unexpected payment request, call the accounting office using a phone number you already have. If a vendor suddenly changes payment instructions, verify it through a known channel. If your web developer asks you to authorize something you’ve never seen before, pick up the phone.
The important part is that the second communication doesn’t depend on information contained in the suspicious message. That’s the difference between verification and simply continuing the conversation. The attacker controls the email conversation. They don’t control your phone call to the person you already know. The FTC gives essentially the same advice: when an unexpected message appears to come from a familiar business, don’t use the links or contact information contained in the message. Instead, contact the business through information you already know is legitimate.
I don’t think the answer is to become suspicious of every email. Businesses couldn’t function that way. We work with clients, vendors and partners every day. Most of those communications are completely legitimate, and most of the time you should be able to trust the people you work with. The problem is that an attacker can now make a message look like it belongs inside that trusted relationship. That’s why the question shouldn’t always be, “Does this look like spam?” A better question is, “Is this something this person would normally ask me to do, in this way?” If the answer isn’t immediately obvious, verify it. That’s not paranoia. It’s simply recognizing that the thing being attacked may not be your password. It may be the relationship itself.
The New Phishing Attack Is Personal
The two emails we saw this week were a good reminder of how much information is publicly available about a business and the people connected to it. The attackers didn’t need to convince our clients that Big Orange Planet exists. They didn’t need to invent our branding. They didn’t need to create a believable social profile from scratch. They already had enough information to make the message look like it belonged in an existing business relationship. That’s the evolution worth paying attention to.
The old phishing email said, “I’m your bank.”
The newer version can say, “I’m the person you already work with.”
And that’s a much more interesting problem. Your website, your domain, your email accounts, your social profiles and your employees all contribute to the digital identity of your business. Protecting that identity isn’t just about keeping hackers out. It’s also about making it harder for someone else to walk through the front door wearing your name. Sometimes the first warning sign isn’t a suspicious email. It’s a perfectly normal one.

About Ally Lennon
Ally Lennon is the founder of Big Orange Planet, a Denver web design and SEO company. He builds websites, fixes the ones that aren't working, and has spent more than two decades developing SEO strategies that get businesses found online. He also spends an unreasonable amount of time figuring out what Google, AI and the rest of the internet are going to do next.
Get the Good Stuff
No fluff. Just practical web design ideas, SEO insight, behind-the-scenes projects, & solutions we've tested in the real world.
Never Miss a Good Idea
More Big Orange Knowledge
June 6, 2025
ChatGPT – Prompt Engineering
\"Prompts\" are your inquiries or questions to AI. Effective prompts provide…
June 29, 2026
Why Isn’t My Website Getting More Leads?
Web DesignSEOThe Big Orange Planet Journal
Getting traffic but not enough leads? We look at why website visitors don't…
May 29, 2026
Why Furnished Interior Presentation Matters in Colorado Residential Developments
Discover how AI is revolutionizing web design — from smart automation and…
June 17, 2026
The AI Gold Rush: What AI Can Actually Do for Your Business
SEOAIThe Big Orange Planet Journal
AI is being sold as the answer to almost everything, but the reality is more…
May 31, 2026
What Small Businesses Really Need From a Website
Most small businesses don't need a complicated website. They need one that…
May 28, 2026
Why Most Business Websites Fail (And How to Fix Them)
Most business websites don't fail because of one major mistake. Poor structure,…






