--:--TÂRGU MUREȘ
ROEN
Contact
Security and data1 September 20264 min read

How to spot a phishing email in your company

The concrete signs of a fake message, plus what to do in the first minutes if somebody has already clicked.

Phishing no longer looks like it did ten years ago. Messages with broken grammar and Nigerian princes have been replaced by emails that perfectly imitate an invoice, a bank notification or a message from your own director.

The technique has not changed though: it runs on haste and on authority.

The four signs that show up almost every time

1. Artificial urgency

“Your account will be suspended within 24 hours.” “Payment must be made today.” Haste is the main instrument, because a person in a hurry does not check. Any message that creates time pressure deserves exactly the opposite treatment: slow down.

2. The sender address, read all the way to the end

The displayed name can be anything. The real address is what counts, and the usual trick is one changed letter or a lookalike domain: “.com” becomes “.info”, “rn” instead of “m”. Check the last part, just before the slash — that is where the truth is.

3. The link does not go where it says

Hover over the link without clicking. The real address appears at the bottom of the browser or in a tooltip. On a phone, press and hold. If the text says “your bank” and the address says something else, you have your answer.

4. You are asked for something nobody ever asks by email

No bank, no institution and no serious supplier asks for your password, your card code or the code you received by text through an email. There are no exceptions — so there is no point looking for one.

The version that fools careful people too

The most effective form is not sent to hundreds of people. It is written specifically for your company, after somebody read your website and social pages: the director's name, colleagues' names, a project in progress.

A message from “the director” to accounts, asking for an urgent payment to a new account while the director happens to be away travelling, raises no suspicion through its content. It raises suspicion through procedure — if one exists.

The rule that stops nearly all of it

Any change of bank account is confirmed by phone, on a number you already had. Not the number in the email. No exceptions, whoever asks and however urgent they seem.

It is a one-sentence rule, it takes two minutes to apply, and it is the most effective security measure a small company can adopt.

If somebody has already clicked

  1. Disconnect the computer from the network — pull the cable or turn off wi-fi. Do not shut it down, so the traces survive.
  2. Change the password for the targeted account, from a different device.
  3. Report it immediately, without hunting for someone to blame. Every minute of embarrassment costs more than the mistake did.
  4. If a payment went out, call the bank within the hour. Sometimes it can be stopped.
  5. Check whether any forwarding rule appeared in the mailbox — that is the first thing attackers set up, so they can read replies without you knowing.

What helps more than training

Training helps, but people get tired. Two technical measures do more than any course:

  • Two-step authentication on email and every important account. Even if a password reaches someone, it is of no use to them.
  • An automatic tag on external emails. When the message “from the director” arrives marked “external”, it falls apart on its own.

Both are configured in an afternoon and ask nothing of your users.

Back to the blog

ARTICLES ON THIS SERVICE

GOT A PROJECT?
LET’S BUILD IT.

Tell us briefly what you want to build. You get a first assessment back, not a generic brochure.

START A CONVERSATION