New email scams leverage AI and bypass traditional security measures
Email scams have evolved significantly, utilizing AI and new tactics to trick users. Traditional advice like checking for grammar errors and using two-factor authentication is becoming insufficient.

Increasingly sophisticated email scams are flooding inboxes by leveraging artificial intelligence and circumventing traditional security measures. The advice historically provided by corporate IT departments, such as looking for grammar errors and hovering over links, is no longer adequate.
New scam tactics, like the use of QR codes for mobile-based phishing ("Quishing"), are designed to appear as legitimate requests. Users might be prompted to scan a QR code with their phone to verify identity or account status, which bypasses workstation protections and directs them to a malicious site via their mobile browser.
Another emerging threat is the "ClickFix" clipboard trap. In this scam, a user's browser is frozen with an error message that instructs them to enter a command into the Windows Run prompt. This command copies malicious code to the clipboard and executes it within the operating system, bypassing browser security mechanisms.
Two-factor authentication (2FA) is also no longer a foolproof defense against "Adversary-in-the-Middle" attacks. These attacks involve creating a fake login page that mimics a legitimate one. Even if a user enters their correct credentials and 2FA code, the attacker intercepts the session cookie, gaining full access to the account.
Even seemingly legitimate invoices from established service providers like QuickBooks or Google Workspace can be part of a scam. Attackers abuse these platforms' invoicing tools to send fraudulent messages with malicious links or fake support numbers. To verify invoice authenticity, always log in directly to the service provider's official website to check account history.