Skip to main content

Phishing email example · Tactic: Trust

ESPN phishing email example: fake fantasy football sign-up

This ESPN phishing email announces that fantasy football is back and pushes you to “Sign Up Now.” The tell is the sender, espn@work-survey.com, which is not an ESPN address. Almost the whole message is images, a trick that helps phishing slip past spam filters.

ESPN phishing email example: “Fantasy Football is back!” from espn@work-survey.com, an image-heavy email with Sign Up Now buttons.
A Hook Security phishing simulation template modelled on real ESPN attacks. Links and tracking removed. Numbered markers match the red flags.

The red flags

Subject
Fantasy Football is back!
From
espn@work-survey.com
  1. 1

    The sender domain

    work-survey.com is unrelated to ESPN or Disney.

  2. 2

    An image-only email

    When nearly all the words are inside pictures, filters can’t read them. That is a common evasion technique.

  3. 3

    A sign-up that asks for a login

    Joining a league through an email link that asks for your ESPN or Disney password is how accounts get taken over.

  4. 4

    Arrives at work

    A personal-interest email landing in a work inbox is worth a second look, especially from an unfamiliar sender.

Why this ESPN scam works

Fantasy football season is something millions of people genuinely look forward to, and plenty of offices run a league. An email that says “it’s back” gets opened with excitement, not suspicion.

The email is built from ESPN’s real promotional graphics. Because the content is images rather than text, there is very little for a filter, or a skimming reader, to question.

The tactic: Trust. The message wears a brand or a colleague you already trust, so scrutiny drops. See all six tactics.

Who gets this email

Sports fans, and offices that run a fantasy league, since the email looks like a personal note that arrived at work. Sign-up season each August and September is when these land hardest.

Other versions of this scam

  • A league invite from a “friend” that asks for your password.
  • A streaming or subscription billing problem notice.
  • A betting bonus or promo-code offer that collects card details.

Check it in 30 seconds

  1. Read the sender domain; a sports brand won’t send from an unrelated one.
  2. Join or manage leagues only inside the official app.
  3. Be suspicious of emails that are almost all images.
  4. Don’t reuse a work password for personal accounts.

What happens if someone clicks

The Sign Up Now button in an email like this usually opens a fake login page for the streaming or sports account. Because many people reuse one password across personal accounts and work tools, a stolen fantasy-league login is often tried against email and company systems within hours.

How to report a ESPN phishing email

  1. At work, use your email’s Report Phishing button, or forward the message to your IT or security team, before anything else. They can pull the same email from everyone else’s inbox.
  2. For account concerns, contact ESPN through its support center rather than any link in the email. ESPN support
  3. Forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org. APWG reporting
  4. If you lost money or shared personal details, report it to the FTC. ReportFraud.ftc.gov

Already clicked? Close the page, change the password for any account you entered, sign out of active sessions, and report it anyway. Speed matters far more than blame.

Questions about ESPN phishing emails

Treat them like any other email: check the sender domain first, and open the app or site yourself when an email asks you to sign in or sign up.

Open the ESPN Fantasy app or type espn.com yourself and join from there. League invites from friends can be accepted inside the app without using an email link.

Spam filters read text. Putting the message inside images hides it from filters and makes the email harder to judge at a glance.

It is a phishing simulation template from Hook Security’s library, modelled on real attacks. Links and tracking have been removed from the screenshot.

Give your team a safe first encounter with emails like this.

Hook sends realistic simulations built from real attacks, then a short training moment right after any click. It runs on Autopilot.