People love using technology to communicate, and among all the options at our fingertips, email remains the most popular. Over half the world’s 600 billion daily digital interactions happen via email. With that kind of volume, it’s no surprise cybercriminals use phishing as the #1 attack method year after year.


Phishing has remained a persistent threat

While security tools and best practices have improved, phishing has remained a persistent threat for nearly 30 years. There’s no magic bullet to stop it, and the protections we rely on often feel a step behind. Email filtering requires constant tuning. Too strict, and important messages are blocked. Too relaxed, and you’re buried in spam. As soon as that balance is achieved, attackers change their tactics and sneak through.


The 2025 shift: account-compromised phishing

One of the most alarming shifts in 2025 is the rise of a new style of phishing attack known as account-compromised phishing. In the past, attackers who hacked an email account typically searched for sensitive information or tried to impersonate the user for financial gain. Today, the strategy has changed dramatically. Once an email account is compromised, the inbox itself becomes a weapon. The goal is no longer stealing data; it’s to use the inbox to compromise more victims.

This approach works because it exploits trust at scale. After compromising someone’s Microsoft 365 or Google Workspace account, bad actors create documents containing links to legitimate-looking login pages. They then share those files with the victim’s contact list. Suddenly, hundreds of people receive what appears to be a trusted message from a familiar source. It isn’t a strange message from an odd email address; it’s a shared file from Fred in Accounting. When recipients click the link and “log in”, their account becomes compromised too. The attack spreads like a viral video: each newly infected account blasts out the same malicious message to their contact list.


The objective is simple

The objective is simple: spread the message and collect as many usernames, passwords, and Multi-Factor Authentication tokens as possible. Modern attacker toolkits now include sophisticated software that sits between victims and popular login pages, allowing criminals to intercept credentials and even bypass Multi-Factor Authentication in real time. These large-scale credential harvesting campaigns are often run by Initial Access Brokers, criminal middlemen who steal logins and sell them in bulk on the dark web. From there, ransomware groups, fraud rings, and other cybercriminals purchase access to carry out the next wave of attacks.


The red flags to watch for

Account-compromise phishing attacks are designed to look completely normal. Spotting them often comes down to slowing down and paying attention to small details that feel “off”. Before opening or interacting with shared files, watch for these common red flags:

  • The message feels out of context
    You weren’t expecting a shared file, or it doesn’t match the type of work you usually do with that person.
  • The subject line is vague or generic
    Messages with subjects like “Shared Document”, “Urgent Request”, “Please Review” are designed to trigger quick clicks without explanation.
  • The link doesn’t look quite right
    Hover over the link (without clicking). If the web address looks strange, unfamiliar, or doesn’t clearly match Microsoft or Google, pause.
  • The timing seems unusual
    Emails sent late at night, early in the morning, or on weekends deserve extra scrutiny.
  • The login page feels wrong
    If clicking a shared file asks you to log in again when you’re already logged in, or prompts you for Multi-Factor Authentication in an unusual way, stop immediately.

Our awareness matters now more than ever

Phishing has survived for decades because it targets something deeply human: our trust and the need to communicate. As attackers shift toward account-compromise phishing, the messages we receive will look more familiar and less suspicious. Our awareness matters now more than ever. Slowing down, questioning unexpected requests, and verifying shared files through a second channel can stop these attacks before they spread. In a world where one compromised inbox can impact hundreds of people, a moment of caution can make all the difference.

Need a second set of eyes? Kalmer Solutions helps teams reduce phishing risk with practical protections like stronger email security, Multi-Factor Authentication hardening, and user training that actually sticks. If you want to pressure-test what you have in place and close the gaps before an attacker finds them, contact Kalmer Solutions.