AI has accelerated the number of fraud emails we are all receiving these days.  You might be getting more scam emails because your email address may have appeared in a data breach, mailing list, public directory, website, professional database, or previously compromised account. Once an address is known to scammers, it can circulate among multiple criminal mailing lists.

The important point is that receiving these emails does not necessarily mean your computer or email account has been hacked. It may simply mean your address is known to spammers. Because today’s scammers don’t need to know much about you. They can send 100,000 messages and only need a tiny percentage of recipients to respond.

AI has not only increased the number of these campaigns, but it has also made these campaigns more convincing. Messages can now be written in professional language, imitate familiar brands, and be customized for particular industries. 

Here Are Some Examples

  1. The “DocuSign” message: This is the most concerning of the three—not because of the DocuSign branding, but because of where the link actually goes. The visible message says: “VIEW SECURE FILE” suggesting that the document is being shared through a secure network. But the actual link is an Microsoft OAuth authorization URL, with parameters that ultimately include: uri=https://honeywell.com. That’s a major red flag. The scammer is trying to make you think you’re going to a document. Instead, you’re being directed into an authentication/authorization flow.

Never authenticate through a link in an unexpected document-sharing email. If you really think someone sent you a DocuSign document, open your browser independently and go to the legitimate service yourself—or contact the supposed sender using a phone number or email address you already know.

  1. A Bitcoin “purchase”: This one uses a different psychological trick: “You just purchased Bitcoin for $238.39.” The goal isn’t necessarily to convince you that you bought Bitcoin. The goal may be to get you to panic and call the phone number. Once you call, the scammer has you exactly where they want you. They may claim they need to “secure” your account, reverse the transaction, verify your identity, or connect to your computer.

Don’t call the number. If you’re concerned that a transaction actually occurred, independently open PayPal, your bank, or your credit-card account and check.

  1. The “weekly $681.70” billing agreement: This is another variation of the same psychological attack. It tells you that you’ve authorized a recurring charge of $681.70 every week and gives you a “security” number to call. Again, the phone number is the trap. The scammer wants you to think: “I need to stop this immediately!”  That emotional urgency overrides your normal skepticism, which is what it wants you to do.

The Rule I: Never solve an email problem from inside the email. That’s probably the single most useful rule. If an email says:
“Your bank account has been compromised.” Don’t click the link. 
If it says: “Your Microsoft password is expiring.” Don’t click the link.
If it says: “You purchased Bitcoin.” Don’t call the number. 
If it says: “Your DocuSign document requires immediate attention.” Don’t open the document through the email.

Instead, go directly to the institution’s website or app yourself. That one habit eliminates an enormous percentage of phishing attacks.

Five Questions Before You Click: I would teach yourself—and anyone in your organization—to stop for five seconds and ask:

  1. Was I expecting this? If not, suspicion goes up immediately.
  2. Is the sender actually who they claim to be? Don’t judge by the display name. Look at the actual email address.
  3. What happens if I click? Hover over the link without clicking and inspect the destination. Be particularly suspicious of strange domains, redirects, shortened links, and authentication URLs.
  4. Is the email trying to make me emotional? Urgency, fear, curiosity, embarrassment, greed and panic are the scammer’s favorite tools.
  5. Can I verify this another way? Open the app yourself. Type the website yourself. Call the organization using a number from its official website or your existing records.

A Few Things You Should Do Now
Tighten your email defenses rather than simply deleting messages one at a time.

  • Turn on MFA for your email account, Microsoft account, Google account, banking, PayPal, and other important services. Ideally use an authenticator app or passkey rather than relying exclusively on text messages.
  • Check your account’s recent sign-ins. If you see unfamiliar successful logins, that’s different from merely receiving spam and deserves immediate attention.
  • Don’t reply to suspicious emails. Even replying “unsubscribe” can confirm that a human actively monitors the address.
  • Report phishing rather than simply deleting it. Your email provider will have a “Report phishing” or similar option.
  • Never use the phone number supplied in an unexpected financial-security email. Find the organization’s legitimate contact information independently.
  • Don’t let the volume scare you. A flood of fraudulent messages does not by itself mean that someone has access to your account. It often means your email address has entered the broader spam/phishing ecosystem.

The distinction is important: Receiving a phishing email ≠ being hacked.