Phishing emails use varied themes but mainly urge clicking links

A Large-Scale Empirical Study of Modern Phishing Email Content

Cryptography and Security

Summary

Phishing emails trick people by pretending to be trustworthy sources, and most come through email. This study by the authors looked closely at nearly 3 million real phishing emails to understand what these messages say and how they try to fool victims. They found that while phishing emails cover many topics, most of them ask people to click on a link. The study also shows how attackers use images, PDFs, and calendar invites in different ways to support their tricks, and how phishing tactics have shifted over time.

What this means in practice

Authors

Jaehwan Park, Woonghee Lee, Fujiao Ji, Doowon Kim

Abstract

Phishing remains one of the most pervasive threats to Internet users, and email remains its predominant delivery channel. Email content is the attack surface of phishing: it is what the victim reads and what automated defenses inspect. Yet the composition of modern phishing content is poorly measured. Prior work has characterized dimensions such as theme, call-to-action (CTA), and impersonation, but not at scale, and their associations and temporal changes remain unclear, owing to small or source-specific corpora, bag-of-words topic models, and a focus on text alone. We present a content-focused measurement study of 2.9M distinct real-world phishing emails collected over 13 months (June 2025 - June 2026) in collaboration with the Anti-Phishing Working Group (APWG). We treat each email as a composite artifact comprising message text and its attachments: 272K images, 143K PDFs, and 57K calendar invitations. Using an LLM pipeline validated against human-annotated samples, we analyze these components along three dimensions (theme, CTA, and impersonation), examine the associations among them, and measure longer-term change against a historical dataset. We find that attackers diversify what they use to deceive but converge on how victims should respond: no theme exceeds 21.3% of emails, while a single CTA, URL navigation, accounts for 73.0%. CTA and impersonation choices are conditioned on theme. Attachments play three roles: images supplement the message text, PDFs substitute for it by carrying the pretext, and calendar invitations reinforce it by replicating interaction endpoints into a persistent medium. Over the longer term, the dominant CTA for invoice-themed phishing shifted from URL navigation to offline communication, rising from 6.7% in 2015 to 46.9% in 2025.