Not all AI platforms handle data the same way. Some consumer-focused AI tools may use user interactions to improve future AI models, while enterprise-focused platforms typically provide stronger controls around how business information is stored, processed, and protected.Understanding the difference...
The Email You Almost Trusted: Phishing From Known Contacts
Overview
Hackers now compromise trusted email accounts and use past conversations to craft convincing follow-up messages. Even emails from colleagues or vendors you've worked with for years can be malicious. Never click unexpected links or attachments — call the sender directly using a known number to verify before you act.
The old advice was simple: don't open emails from strangers. That guidance made sense for a long time. But phishing attacks have evolved well beyond Nigerian princes and suspicious lottery winnings. The most dangerous emails landing in inboxes today don't come from strangers at all — they come from people you know.

How Do Hackers Use Compromised Email Accounts to Trick You?
When a hacker gains access to someone's email account, their first move isn't always to send a suspicious blast. Often, they read. They review past conversations, study the tone of previous messages, identify ongoing projects, and look for anything they can use to craft a follow-up that fits naturally into an existing thread.
Then they send an email that looks like a continuation of a real conversation. Same name. Same email address. Same casual writing style. Maybe even a reference to a project you've both been working on.
This technique — sometimes called Business Email Compromise (BEC) — is highly effective precisely because it bypasses our instincts. We're trained to look out for strangers. We're not trained to be suspicious of someone we've worked with for two years.
To navigate these digital threats, a helpful principle to adopt is "Trust, but verify." This phrase, originally an old Russian proverb ("Doveryai, no proveryai"), is most famously associated with U.S. President Ronald Reagan. He frequently used it during nuclear disarmament negotiations with Soviet General Secretary Mikhail Gorbachev in the 1980s. Reagan learned the saying from American historian and Russian scholar Suzanne Massie, who suggested it as a way to connect with Soviet leadership. The timeless wisdom behind the phrase applies just as well to cybersecurity: even when things seem trustworthy, it's essential to verify before acting.

How Many Americans Are Already Affected?
The scale of this problem is significant. According to the Identity Theft Resource Center's 2023 Data Breach Report, over 353 million Americans were impacted by data breaches in 2023 alone. Each breach creates a potential pool of compromised credentials — email addresses, passwords, and account access — that cybercriminals can use to launch exactly these kinds of targeted attacks.
That number isn't abstract. It means that someone in your contact list — a vendor, a client, a former colleague — may already be compromised without knowing it.
What Are the Red Flags in Emails From People You Trust?
Because these emails look convincing, you need to know what subtle warning signs to watch for:
- Unexpected links or attachments — Did you ask for this file? Were you expecting this link? If not, pause.
- Unusual urgency — Phrases like "please action this immediately" or "time-sensitive request" are designed to short-circuit your judgment.
- Slightly off phrasing — If something feels grammatically awkward or unlike how that person normally writes, trust that instinct.
- Requests for credentials or sensitive information — Legitimate colleagues and vendors rarely need you to log in somewhere or share a password via email.
- A link that doesn't match the expected domain — Hover before you click. If the URL looks unfamiliar or slightly misspelled, don't proceed.
None of these signals alone confirms an attack, but any one of them warrants a pause.
What Should You Do When Something Feels Off?
Stop. Close the email. Do not click anything.
Then pick up the phone and call the sender directly — using a phone number you already have on file, not one provided in the email. A quick 30-second call can confirm whether the message was real or whether their account has been compromised.
This step matters more than it might seem. If the account is compromised, your call may be the first alert the sender receives. You're not just protecting yourself — you're potentially helping them.
What Should You Do If a Link Asks for Your Username and Password?
Close the browser immediately and report it to IT.
This is a hard line. A credential-harvesting page is one of the most common phishing payloads — it looks like a normal login screen (Microsoft 365, your company portal, a vendor site), but every keystroke goes directly to a hacker.
If you've already entered credentials before realizing something was wrong, report it to IT right away. The faster a compromised account is flagged, the faster access can be revoked.
No legitimate system will ask you to log in through an emailed link without warning. Go directly to the resource — type the URL yourself, use your saved bookmark, or search for the official site.
Why You Should Go Directly to Resources — Not Through Email Links
Whenever you need to access a platform, a portal, or a document, navigate there directly. Following email links to login pages is a habit worth breaking entirely. Even when an email is legitimate, it trains a behavior that attackers count on. Breaking that habit removes one of the most reliable tools in a phisher's toolkit.
When in Doubt, Verify — Every Time
Cybersecurity doesn't require technical expertise. It requires habits. The most effective defense against phishing from trusted contacts is a simple, repeatable one: when something feels off, verify before you act.
Call the sender. Go directly to the resource. Report anything suspicious to IT — even if you're not sure. A brief moment of caution is far less costly than a compromised account or a data breach.
If you receive an email that feels unusual, even slightly, treat that instinct as worth acting on. Don't dismiss it because the name looks familiar. Remember: "Trust, but verify."
Frequently Asked Questions
Can someone's email be compromised without them knowing?
Yes. Hackers often gain access to an email account and monitor it quietly before sending anything. The account owner may have no idea their account has been accessed until someone reports a suspicious email.
How do I verify a suspicious email without clicking anything in it?
Contact the sender through a separate channel — call them using a phone number from your records, or reach out via a different platform. Do not reply to the suspicious email or use any contact information it contains.
What should I do if I accidentally clicked a suspicious link?
Disconnect from the network if possible, and report it to your IT team immediately. Do not attempt to undo it yourself. The faster IT is notified, the faster they can assess and limit any potential damage.
Are phishing emails from known contacts more dangerous than those from strangers?
In practice, yes. Emails from familiar contacts are more likely to be opened, trusted, and acted on. Hackers know this, which is why compromising a trusted account is a high-value move.
What makes a credential-harvesting page different from a real login page?
Often, very little — that's the danger. The page may look identical to a real Microsoft or Google login. The only reliable way to avoid it is to never follow email links to login pages. Navigate directly to the site instead.
Who should I contact if I think my own email has been compromised?
Report it to your IT team immediately. They can review account activity, revoke unauthorized access, and reset credentials before further damage occurs.
Microsoft Copilot can be a powerful productivity tool, but it is not a replacement for employees, expertise, judgment, or accountability. Understanding what Copilot does well (and where human involvement remains essential) is key to getting meaningful business value from AI.At its core, Microsoft Co...


