The Email That Almost Got Me
I want to tell you about an email I almost fell for.
It was a Tuesday afternoon last spring. I was working from home—Miles was asleep under my desk, the house was quiet—and I saw an email that looked like it came from a service I used for work. The subject line was something I expected to see: "Action Required: Secure Document Access."
It came from a legitimate domain. It passed every authentication check my email provider had. I clicked the link.
Here's the part I don't tell people often—especially not as a former threat analyst. I only realized it was suspicious because I paused to look at the address bar. The URL wasn't quite right. It was close. Very close.
I almost clicked. And I used to analyze phishing attacks professionally.
If it almost got me, what chance does someone who doesn't look at address bars for a living have?
The Chain: How a Single Leaked Email Opens the Door
This article is about what happens after that email address gets out. I'm going to walk through the full attack chain—from the initial leak to the credential harvesting page.
Step 1: The Leak
An email address gets leaked. It happens all the time. Data breaches, public social media posts, security researchers' investigations, LinkedIn profiles, company websites—there are thousands of ways.
What the attacker needs: just the email address. They don't need a password yet. They don't need anything else.
What the attacker has: a validated address that belongs to a real person. And the domain of that person's email—which tells them who they work for or what service they use .
Step 2: The Reconnaissance
Once the attacker has the email address, they can do a lot with it .
They can:
Look up the person's social media profiles
Identify their employer and role
Find other accounts linked to the same email
Get a sense of their digital habits
Use the email address to request password resets and see which services respond
What the attacker is building: a profile. They don't need to know everything about the person—just enough to craft a message that seems legitimate.
Step 3: The Credential Harvesting Kit
This is where it gets sophisticated. Attackers use reusable phishing kits. These are pre-built systems that do the heavy lifting.
What a modern phishing kit can do:
Automatically customize the login page based on the victim's email domain
Display a victim's own company branding on the fake login page—including using the company's actual logo and colors
Load the legitimate website of the organization as a blurred background to reinforce legitimacy
Harvest credentials and send them to the attacker in real time
One example: in a recent phishing campaign, the attack used a URL that contained the victim's email address. When you clicked the link, the phishing page would :
Extract the domain from your email address
Load the legitimate website of that organization in the background
Display a fake login page that looked like it belonged to your employer
Use your company's actual logo and branding
The victim thought they were logging into their own company's portal.
A more sophisticated version of this attack creates an experience that seems legitimate at every stage. Some phishing kits now route victims through multiple layers—including legitimate services like Google's open redirects—before arriving at the credential harvesting page .
Step 4: The Email Infrastructure
Attackers use legitimate services to send the phishing message—services that pass SPF, DKIM, and DMARC checks .
How this works:
The attacker compromises an email service account (like Amazon SES) or uses stolen credentials
The email gets sent through legitimate infrastructure
The email passes all authentication checks
The email can even be sent from a legitimate domain that the attacker has access to
The result: an email that looks like a legitimate message from a recognized service or contact, with none of the technical red flags that spam filters look for.
"SPF, DKIM, and DMARC answer one question: did this message come from infrastructure the domain owner allows? They say nothing about intent." — Ironscales threat intelligence report
Step 5: The Phishing Message
Now the attacker sends the message—from a legitimate-looking sender, to a known recipient, with a link that goes to a convincing fake login page.

Why it works:
It came from a sender you recognize or trust
It passed the technical checks that filter out most spam
The subject line seems normal or urgent
The link takes you to a page that looks exactly right
The fake page asks you to "verify" or "sign in"
You enter your credentials
The attacker has them
Ways attackers make it convincing:
Using a compromised email account from someone you know
Inserting malicious links into existing email threads with colleagues or partners
Using AI to craft personalized messages that match the victim's context
Creating fake login pages hosted on trusted infrastructure that looks legitimate
Step 6: The Real-Time Takeover
Many modern phishing kits have moved beyond credential theft to something more sophisticated. Some campaigns now involve a human operator on the other end—watching in real time and steering the victim's browser .
What this looks like:
The victim enters their credentials on the fake page
The credentials hit a Telegram bot and land in front of a human operator
The operator reads them and decides what to harvest next
The victim's browser—waiting on a "Please Wait..." spinner—navigates immediately to the next page
The second page often displays a fabricated "Your account or password is incorrect" error, prompting the victim to re-enter the password
The first submission captures the credential. The second confirms it and filters out typos. The operator receives a high-confidence credential before ever attempting real account access.
This is Adversary-in-the-Middle (AiTM). The operator is acting as a live relay between the victim and the real service, capturing MFA codes as they are entered and replaying them against the real account before they expire . Standard MFA does not stop this. The code is real. The timing is real. The interception is invisible.
How to Spot These Emails
Here's what to look for:
1. Check the Sender's Email Address
The display name can be faked. Look at the actual email address. Is it from the domain you expect? Check for subtle differences—an uppercase "i" that looks like a lowercase "l" .
2. Hover Over the Link
Don't click. Hover your mouse over the link (on a computer) or long-press it (on a phone) to see the actual URL. Is it the correct domain? If it's a shortened link, be cautious.
3. Look for Urgency
Attackers create pressure. "Your account will be locked." "Immediate action required." "Your password is about to expire." Slow down.
4. Check the Formatting
Mismatched tone, poor grammar, or an odd format can be red flags. But AI-generated phishing emails can be almost perfect .
5. Verify Through Another Channel
If the email claims to be from a service you use, don't click the link. Type the URL directly into your browser. If it seems to come from someone you know, contact them through another channel to confirm.
6. Consider the Context
The best way to spot an email that looks right: is it actually something you were expecting? If there's any doubt, pause.
What to Do If You Think You've Received a Phishing Email
If You Haven't Clicked Anything
Don't click anything. Hover the link and see the destination. If you're suspicious, delete the email.
Don't reply. Engaging with the attacker just confirms there's a real person behind the address.
Report it to your email provider. Gmail, Outlook, and other providers have built-in reporting tools.
Tell your family or colleagues. If the email is impersonating a known contact, they may have received similar messages.
If You Clicked the Link
Check the URL. If you entered any information on the page, it's likely been captured. Change those passwords immediately.
Change your credentials. Start with the account the email targeted. If you used the same password elsewhere, change those too.
Enable multifactor authentication. If you're not using it on the compromised account, set it up. Even if you are, confirm the settings are still correct.
Monitor your accounts. Watch for unexpected activity or login attempts.
If You Entered Credentials
Change your password for the compromised account and any account using the same password.
Enable or update multifactor authentication—if the attacker captured the code, the account may still be accessible.
Contact the service provider if it's a critical account (banking, email, or password manager).
Monitor your accounts for suspicious activity. If you're in the US, report the incident to the FBI's Internet Crime Complaint Center (IC3).

The Bottom Line
A phishing attack can start with nothing more than a leaked email address. The attack chain is sophisticated: reconnaissance, reusable phishing kits, legitimate email infrastructure, and in some cases, real-time operators steering the victim's browser.
You don't need to understand every detail of how this works. But you do need to slow down before clicking a link—even if it looks legitimate. If it scares you but doesn't help you act, it's not security advice. So here's your action list:
Check the sender's actual email address—not just the display name
Hover over links before clicking to see the URL
Don't enter credentials on a page you reached from an email—type the URL directly into your browser
Enable multifactor authentication on your most important accounts
Next Week: I'll walk through the results of a test I ran in our household—putting smart-home devices on a separate network to see what actually improves privacy and what just adds complexity.
Dave C. — Five minutes now beats five hours later.
No notes on this sheet yet.