Your email security filter blocked 47 phishing attempts last month. Sounds reassuring, right? But here's the problem: attackers know exactly how those filters work, and they've developed new tactics specifically designed to slip through undetected.

Australian small businesses reported losses of $13.1 million to scams in 2024, with phishing remaining the most common entry point. The attacks reaching your inbox today look nothing like the obvious Nigerian prince emails of the past. Running simulated phishing attacks against your own team has become one of the most practical ways to prepare for threats your filters simply cannot catch.

Tactic 1: QR Codes Built From Invisible HTML Tables

Security filters are trained to spot malicious QR code images. Attackers have responded by building QR codes that aren't images at all.

Scammers construct fully functional QR codes from tiny HTML table cells. Each cell is coloured black or white. When your email client displays the message, these cells line up to form a scannable code. To your security software, it looks like a simple table with no links, no images, and nothing suspicious.

The email itself typically contains minimal text: "Scan to verify your account" or "Review this invoice." When staff scan the code with their phone, they land on a convincing fake login page designed to steal their credentials.

This technique works because there's no image file for filters to analyse. The malicious content only becomes visible when rendered by your email program.

Tactic 2: Callback Phishing Through Microsoft Teams

Your team trusts Microsoft Teams. Attackers know this.

A campaign spotted in late 2024 targets users by adding them to Teams groups with alarming names like "URGENT: Payment Required" or "Account Suspension Notice." Inside the group, attackers post fake invoices showing charges for software subscriptions or services the recipient never purchased.

The twist: there's no malicious link to click. Instead, the message includes a phone number to call "if you didn't authorise this charge." Staff who call reach a fake support centre where they're convinced to hand over login credentials, payment details, or remote access to their computer.

Because the attack happens inside a trusted platform and relies on phone calls rather than links, email security testing tools never see it. Research on phishing susceptibility shows that attacks using familiar platforms and urgent language succeed at much higher rates than traditional email phishing.

Tactic 3: Unicode Character Substitution in Links

Look at these two characters: / and ∕

They appear identical. But the first is a standard forward slash. The second is a mathematical division symbol with a completely different character code.

Attackers now substitute these lookalike characters in malicious URLs. A link to "microsoft∕com∕login" (using the mathematical symbol) passes through filters looking for "microsoft/com/login" (using standard slashes). The filter sees an unrecognised domain and lets it through. Your browser, trying to be helpful, often corrects the character or redirects anyway.

This simple substitution defeats filters that rely on matching known malicious domains. The technique also works with letters. The Cyrillic letter "а" looks identical to the Latin "a" but has a different code. A URL using "pаypal.com" with a Cyrillic "a" leads somewhere entirely different from the real PayPal.

Tactic 4: Facebook Infringement Warnings With Fake Pop-ups

Many Australian businesses rely on Facebook for marketing. Attackers exploit this with fake copyright infringement notices that appear to come from Meta.

The email warns that your business page will be suspended within 24 hours unless you verify your identity. Clicking the link opens what looks like a Facebook page with a pop-up login window. The page behind the pop-up is real Facebook. The pop-up itself is a fake overlay controlled by attackers.

Staff see a legitimate Facebook page in the background and assume the login prompt is authentic. They enter their credentials, which go straight to the attackers. Within hours, your business page is compromised, often used to run fraudulent ads charged to your payment method.

Why Simulated Phishing Attacks Prepare Your Team Better Than Training Alone

Reading about these tactics helps. But reading doesn't build the reflexive caution your team needs when a convincing phishing email lands in their inbox at 4:47pm on a Friday.

Simulated phishing attacks create practical experience. Staff who receive a test email and click the link get immediate feedback showing them exactly what they missed. This moment of "I fell for that?" creates stronger learning than any presentation or policy document.

A phishing simulation study at a large hospital found that over 50% of staff clicked on targeted phishing in the first campaign. This underscores the importance of using realistic scenarios that match what real attackers send to identify susceptibility within an organisation.

Building Practical Cyber Security Education Without IT Expertise

Running your own email security testing program sounds technical, but modern platforms handle the complexity for you. You add employee email addresses, choose how often you want tests sent, and the system does the rest.

Good platforms research your organisation to create relevant scenarios. An accounting firm receives fake ATO notices and DocuSign requests. A retail business gets shipping notifications and supplier invoices. The tests match what your staff actually encounter, making the training directly applicable.

When someone fails a test, they receive training explaining what they missed. However, recent research from USF suggests that immediate "just-in-time" training can be counterproductive. Instead, the study recommends providing delayed, inclusive feedback to all employees to ensure stronger long-term retention.

Practical Steps to Protect Your Business

Start with awareness. Share these four tactics with your team so they know what to watch for. QR codes in emails deserve extra suspicion. Unexpected Teams messages demanding urgent action need verification through other channels. Any link deserves a hover-check before clicking.

Implement multi-factor authentication on every account that supports it. Even if credentials are stolen, MFA blocks most account takeovers.

Run regular simulated phishing attacks. Monthly testing keeps awareness fresh and identifies staff who need extra support. Automated platforms make this practical even for businesses without dedicated IT resources.

Create a simple reporting process. Staff who spot suspicious emails should have an easy way to flag them. A shared inbox or quick Slack channel works fine. The goal is making reporting easier than ignoring.

Review your Microsoft Teams settings. Consider restricting external users from adding your staff to groups, or at minimum, train your team to verify any unexpected group invitations through official channels.

These attacks will keep evolving. The specific tactics described here will be replaced by new ones within months. But staff who have developed genuine caution through repeated practice can spot the warning signs regardless of what form the next attack takes.