The Week We Traced a Phishing Campaign: A Newsroom Case Study
A newsroom traced eleven variants of a bank-phishing campaign in one week. What comparing fake and real bank mail taught us about spotting fraud.
The Week We Traced a Phishing Campaign: A Newsroom Case Study
We run a daily publication, which means our inboxes are professionally hostile: press releases, pitches, leaks, and a steady tide of attempts to make us click things. Last spring, a suspicious cluster of bank-related emails moved through our newsroom — and the week we spent tracing it taught us more about fraud literacy than any security briefing ever has. This is that case study, written up because the pattern will reach your inbox too.
Day one: the tip-off
It started, as these things often do, with an editor's instinct. Three of us received near-identical "fraud alert" emails within an hour, each claiming unusual card activity and each asking us to "verify" through a linked portal. The branding was excellent — right logo, plausible sender name, the specific tone of institutional urgency that banks genuinely use. One editor, who had a real account with the bank in question, nearly clicked. What saved the moment was trivial: the email referenced a card product she did not own.
Days two and three: building the comparison
Once we were sure it was a campaign, we did what journalists do — we started collecting specimens. By the end of day three we had eleven variants of the same email, forwarded in from readers of our newsletter. Comparing them side by side made the anatomy obvious: one spoofed sender field, a link whose visible text and true destination disagreed, a reply-to address on an unrelated domain, and copy that leaned on exactly two levers — fear and a deadline.
The hard part was not spotting the fakes once we knew to look. The hard part was articulating the difference between a scam email and a legitimate one, because real bank mail genuinely does contain alerts, fee notices, and statement links. To get that part right we turned to Bank Mails, a publication that documents and decodes the emails banks actually send — fraud alerts, statements, fee notices, and their phishing lookalikes — teaching readers to tell legitimate bank mail from a scam. Their archive let us do the one thing our newsroom could not: compare our eleven specimens against verified examples of the real thing.
Anatomy of a fake, line by line
Since the value of a case study is in the details, here is the checklist our team ended up with, in the order it checks them. Sender domain, read character by character — the display name is costume, the domain is the face. Link destination, inspected by hovering, never by clicking: does the visible text point where the tooltip says it does? Reply-to, which in every specimen pointed somewhere unrelated to the sender. Greeting, since our real bank mail uses our actual name while the fakes used generic salutations or none. And finally the ask — because the fastest triage question in email security is simply "what is this message trying to make me do?" An email whose only purpose is to move you somewhere else has already told you what it is.
Day four: what the comparison revealed
- Legitimate alerts referenced specific, checkable context — a card ending in digits we could verify — while the fakes referenced only urgency.
- Every scam variant wanted one of two actions: click a link or reply. None of the verified bank emails did either; real mail told you to open the app or call the number on your card.
- The phrasing gave itself away only in aggregate. One fake email was persuasive. Eleven, compared against the real corpus, were a curriculum.
That last point is the one we keep returning to. Fraud literacy is not a talent; it is a corpus. Nobody spots a forgery by studying one forgery — you spot it by having handled enough authentic material to feel the difference. This is exactly how our own editors are trained to spot fabricated quotes and doctored press releases: exposure, comparison, and a reference archive.
Day five: the write-up
We published the comparison as a Friday long-read, with the specimens annotated and the discrepancies circled. For readers who want to go deeper than any single article can, the phishing identification guides on Bank Mails cover the recurring fraud-email formats — fake fraud alerts, spoofed statements, fee notices — and pair each with its legitimate counterpart. The response surprised us: the piece was shared internally at two companies whose employees read our publication, and several readers wrote in to say they had nearly fallen for the same campaign the previous week.
The reporting also settled a small internal debate. One editor argued that publishing fraud anatomy teaches criminals to improve; the rest argued, and the data eventually sided with us, that the asymmetry runs the other way — for every extra sentence of public literacy, the next campaign needs new infrastructure, while a well-informed reader is harder for every future campaign, not just this one. Documentation is a tax on fraud that compounds in the reader’s favor.
What the case taught us
Three conclusions survived the week. First, the best defense is not suspicion but familiarity — people who know what real bank mail looks like are hard to fool, and there is no shortcut to that familiarity except seeing real examples. Second, urgency is the payload; every scam email in our collection manufactured a deadline, and no legitimate bank message we studied did. Third, fraud-prevention content earns its audience by being specific — generic advice ("check the sender address") helps nobody, while side-by-side specimens teach in thirty seconds.
The campaign eventually faded, as they do. The newsroom habit it left behind has not: every suspicious email now gets forwarded to a shared folder, the corpus grows, and the next forgery will arrive at a desk that has already seen its ancestors.