Phishing continues to be one of the biggest threats to email users worldwide, with Gmail and Outlook platforms consistently at the center of attacks. Despite continued security enhancements from Google and Microsoft, cybercriminals are constantly evolving their techniques, creating increasingly convincing messages targeting both consumers and businesses.

Modern phishing attacks are no longer limited to obvious spam emails with poorly written content and suspicious links. Instead, they leverage artificial intelligence, stolen logos, fake login pages, and social engineering to trick even experienced users.
Fake account security alerts
One of the most common scams involves emails that appear to be security alerts from Google or Microsoft. Users receive messages that report suspicious activity, a login attempt, or a possible breach of their account.
See also: Internet Explorer: Still running malware
The email usually includes a button like “Secure Your Account” or “Verify Login Activity,” which leads to a fake login page that looks almost identical to the genuine Gmail or Outlook login page. Once the user enters their details, they are sent directly to the attackers.
Experts note that these types of attacks increase significantly after major data leaks or cyberattacks that make headlines, as users are already in a state of anxiety.
Scams with supposedly shared files and OneDrive links
Another particularly popular Outlook phishing method relies on fake OneDrive or SharePoint. The victim receives a message that appears to come from a colleague, accounting, or HR department, informing them that an important document has been shared.
The link leads to a page that asks to reconnect to a corporate Microsoft 365 account. In many cases, attackers use real cloud services to make emails more easily pass security filters.
Similarly, Gmail is experiencing an increase in attacks via fake Google Docs invitations, where users are tricked into granting access rights to malicious third-party applications.

Business Email Compromise and Corporate Fraud
Business Email Compromise, also known as BEC, is one of the most dangerous forms of phishing for businesses today. Perpetrators gain access to real corporate email accounts and then monitor internal conversations for weeks or even months.
See also: Nx Console 18.95.0: Infected version steals developer codes
When they detect financial transactions or communication between executives, they intervene by sending fake payment instructions or money transfer. Because the emails come from real accounts, they are extremely difficult to detect.
BEC attacks have cost billions of dollars worldwide and are considered a top threat to organizations that rely on cloud email services.
AI and phishing: The new generation of attacks
Artificial intelligence is rapidly changing the phishing landscape. Attackers are now using AI tools to create personalized emails without spelling errors, mimic the style of real executives, and automatically translate messages into multiple languages.
This means that traditional signs that helped identify phishing emails are becoming less and less obvious. In addition, new forms of attacks are emerging that combine phishing emails with deepfake voice calls or fake confirmation.
The Gmail and Outlook platforms are investing significantly in AI-based detection systems, however the battle is evolving into a constant struggle for technological superiority between defenders and attackers.
How can users be protected?
Cybersecurity experts recommend enabling multi-factor authentication on all email accounts, as well as using password managersto create strong and unique passwords.
See also: INTERPOL: Operation Ramz disrupts cybercrime networks

At the same time, users should never click on links in emails that cause panic or pressure for immediate action. Confirming the sender address and checking the domain before any connection remains critical security practices.
Businesses, for their part, need to invest more in staff training, as the human factor continues to be the weakest point in the security chain.
Phishing is no longer a simple nuisance of spam emails. It has evolved into a multi-layered cybercrime industry that targets personal data, financial accounts , and corporate networks. As attacks become more convincing and automated, awareness and digital vigilance remain the most important weapons of protection for every Gmail and Outlook user.
