Most attacks do not start with a hacker in a dark room, but with an e-mail. A parcel that could not be delivered, an invoice that is still open, a bank that wants to block your account. The good news: with half a minute of attention you can spot most of them.
The 30-second check
- Who really sent it? Look at the e-mail address itself, not the name in front of it. A strange domain name means trouble.
- Does it suddenly have to be very quick? Urgency and threats are the favourite tricks. Real companies give you time.
- Where does the link go? Hover over it without clicking and read the address. On your phone, press and hold the link.
- Were you expecting an attachment? Do not open an unexpected document, especially a zip or a file with macros.
- Is the greeting right? "Dear customer" from a company that simply knows your name is suspicious.
- Are you asked for your password or money? Your bank never asks you by e-mail to log in or transfer money.
- Is it too good to be true? A prize you never won is still a prize you never won.
In doubt? Check it safely
Do not click the link. Go to the website you already know yourself, or call the company on a number you look up yourself. It takes a minute and then you are sure.
Clicked anyway?
Do not panic, but be quick. Change your password, turn on two-step verification and tell your colleagues or us. The sooner, the smaller the damage.
Test your own phishing radar in the Lab, or let us train your team with a security check. More tricks, a game and true stories are in Spot the phish.
