Spot the phish
A second of doubt is cheaper than a week of repairs
Phishing stopped being that e-mail full of spelling mistakes a long time ago. It comes as a calendar invitation, a call from 'the bank', a chat message from 'the helpdesk' or a video call with your 'director'. Learn the tricks, practise with copied messages and read what happened to those who did fall for it.
The tricks
Four buttons fraudsters press
Hurry
"Within 24 hours, or else..." People in a hurry check nothing. That's why fraudsters always rush you.
Authority
The bank, the tax office, the director, the helpdesk. A title or a logo is easy to copy, and so are a voice and a face.
Curiosity
A parcel, a shared document, a refund, a photo of you. You just want to take a quick look.
Helpfulness
A colleague in trouble, a customer who wants to pay quickly, 'the helpdesk' improving your security. Your kindness is used against you.
Practise
Phish or not? The big round
Six messages a round, a different mix every time. They are made up, but every fake copies a real attack. After you answer you see what to look out for, and for every fake what happened in real life.
From: Delivery Service
Your parcel could not be delivered. Pay 1.95 euros shipping within 24 hours via track-parcel.example, or it goes back to the sender.
Show the answer
Phishing. A small amount makes it look harmless, but they're after your card details. Couriers don't ask for money through a link in a text.
How you can tell:
- A parcel and you don't know who it's from.
- Hurry: within 24 hours.
- Paying through a link to an unknown site.
You ordered business cards last week.
From: Triangle Print <[email protected]>
Invoice 2026-0412 for your business cards
Attached is the invoice for last week's business cards. You can pay in your own banking app; the account number is on the invoice, the same as always.
Show the answer
Real. You expected this invoice, the sender checks out and you don't have to click anything. Still unsure? Call the printer on the number you already had.
Why it checks out:
- You were expecting this invoice.
- The sender is the printer you already knew.
- The same account number as always, and you pay in your own app.
From: Management <[email protected]>
Confidential: must happen today
I'm in negotiations all day and can't call. We're buying a company and it has to stay secret until the announcement. Transfer 186,000 euros to the notary today; I'll send the details shortly. Don't discuss this with anyone, not even the accountant.
Show the answer
Phishing. Classic CEO fraud. Agree that every unusual payment is confirmed through a second channel, even when the director is the one in a hurry.
How you can tell:
- Secrecy: 'don't discuss this with anyone'.
- Hurry and a large amount.
- The director is 'unreachable', so you can't check.
- A sender address that's not quite right.
Real story: A secret takeover in Dubai, paid in six instalments
From: Safe Bank <[email protected]>
Your account will be blocked
We noticed unusual activity. Confirm your details within 2 hours using the button below, or we will block your account.
Show the answer
Phishing. A bank doesn't ask you to confirm your details through a button in an e-mail. In doubt? Open your banking app yourself.
How you can tell:
- A threat: or we block your account.
- Hurry: within 2 hours.
- Confirming your details through a button in an e-mail.
You're just logging in to a web shop.
From: WebShop
Your login code is 482913. Do not share this code with anyone. Not trying to log in? Then ignore this message.
Show the answer
Real. But if someone then calls you for that code, that's the scam: never share it.
Why it checks out:
- You asked for the code yourself.
- There's no link and nothing is asked of you.
From: Unknown number
Hi mum, this is my new number, my phone is broken. Could you transfer 480 euros? I'll pay you back tomorrow. I can't call, my microphone isn't working.
Show the answer
Phishing. The well-known 'hi mum' scam. Call your child on the old number, or ask a question only your child can answer.
How you can tell:
- A new number and money trouble.
- Calling 'isn't possible'.
- Pressure to pay today.
From: Tax Refund <[email protected]>
You are owed a 312.40 euro refund
After a recalculation you are getting money back. Enter your bank details and your DigiD login within 48 hours to receive the amount.
Show the answer
Phishing. No government service asks for your DigiD login by e-mail. Check Mijn Belastingdienst yourself via the site you type in.
How you can tell:
- Money back you weren't expecting.
- A request for your login and bank details.
- A sender that isn't the government.
Real story: A fake MijnOverheid e-mail, and the text code with it
You just clicked 'forgot password' in your bookkeeping app.
From: Books App <[email protected]>
Set your new password
You asked for a new password. Use the link below within 30 minutes. Wasn't you? Then you don't need to do anything.
Show the answer
Real. Do check that the link goes to the same domain as the app.
Why it checks out:
- You asked for it yourself, a minute ago.
- The sender is the service you use.
- No threat: 'if it wasn't you, you don't need to do anything'.
From: IT helpdesk <[email protected]>
Your mailbox is 99% full
Soon you will no longer receive e-mail. Log in on this page now to request extra space for free.
Show the answer
Phishing. Your login page never comes from an e-mail. You get more space in your own mail app or through your own IT partner.
How you can tell:
- A vague 'helpdesk' you don't know.
- Logging in through a link in the e-mail.
- A threat: no more e-mail.
Real story: A phishing e-mail in October, a university down at Christmas
You're a member of the volleyball club.
From: Triangle Volleyball Club <[email protected]>
Saturday's programme
Hi! On Saturday we play at home at 2 pm. Coming to watch? You can unsubscribe from this newsletter at the bottom of this e-mail.
Show the answer
Real. Exactly what you expected from your club. Nothing wrong here.
Why it checks out:
- A sender you know.
- No request for money, details or a login.
You ordered printer paper yesterday.
From: Paper Shop <[email protected]>
Your order is on its way
Good news: order 10482 has been shipped. You can follow its status in your account on our website.
Show the answer
Real. And if you want to see the status, open the shop's site yourself.
Why it checks out:
- You really ordered something from this shop.
- You don't have to pay or fill in anything.
Organiser: Billing Team <[email protected]>
Invitation: discussion of outstanding invoice Q3
- When
- Thu 10:00 - 10:30
- Location
- Read the document first: docs-share.example/q3
You have been invited to a meeting about an outstanding invoice. Please read the shared document beforehand. This event is already in your calendar.
Show the answer
Phishing. Calendar invitations slip past spam filters more often and appear in your calendar by themselves. Don't open documents from an invitation sent by someone you don't know.
How you can tell:
- It was already in your calendar without you accepting anything: that's how invitations work, fake ones too.
- You don't know the organiser.
- The 'location' is a link to a document on an unknown site.
- An outstanding invoice makes you curious and a little worried.
Real story: Fake invitations that turned up in your calendar by themselves
Since this morning your mailbox has been flooded with spam: hundreds of newsletters.
From: IT Helpdesk (External)
Hi, we can see a lot of spam coming in for you and we're fixing it now. I'll call you on Teams in a minute. Then start Quick Assist on your computer and type in the code I give you.
Show the answer
Phishing. With remote help the 'helpdesk' gets full control of your computer. A real helpdesk doesn't ask for that out of the blue; call your own IT partner yourself.
How you can tell:
- '(External)': the message comes from outside your organisation.
- You didn't ask for help.
- You're asked to start remote help and type in their code.
- The flood of spam just before is part of the trick.
Real story: First hundreds of spam e-mails, then 'the helpdesk' calls
Your phone keeps showing sign-in requests: 'Is this you?' Ten times already, while you aren't signing in.
From: IT department (unknown number)
Hi, this is IT. We've got a fault in the sign-in system, that's why you're getting all those notifications. Press Approve once and they'll stop.
Show the answer
Phishing. This is called MFA fatigue: the attacker already has your password and bombards you with requests until you approve one. Never approve anything you didn't start, change your password and report it.
How you can tell:
- You didn't sign in, so every request comes from someone else.
- 'IT' gets in touch from an unknown number.
- Approving 'to make it stop' lets the attacker in.
Real story: Prompt after prompt, until someone pressed Approve
After an e-mail about a 'secret transaction' you're in a video call with the finance director and two colleagues. You recognise their faces and voices.
In the call: The finance director and two colleagues
Good to have you here. As in the e-mail: these payments have to go out today, in a few parts, to the accounts we'll send you. Keep it within this group.
Show the answer
Phishing. A video with familiar faces feels like proof, but that can be faked too. Agree on a check that happens outside the call.
How you can tell:
- It started with an e-mail about a secret transaction.
- Secrecy and hurry, even though you see familiar faces.
- Large amounts split into several payments to new accounts.
- Faces and voices can be faked. Call back yourself on a known number.
You've been ordering from North Wholesale for years. Kees replies in an existing thread.
From: Kees, North Wholesale <[email protected]>
Re: invoice 2291
Hi! Small change: we've moved to another bank, so our account number has changed. Could you pay invoice 2291 to the new number in the attachment? Cheers, Kees
Show the answer
Phishing. Invoice fraud works precisely because it seems to come from a real account. Call Kees on the number you already had before you change anything.
How you can tell:
- A changed account number, by e-mail only.
- The address and tone can be genuine: then Kees' mailbox has been taken over.
- There's no confirmation other than this e-mail.
Caller: 'The fraud team' of your bank, with your bank's number on screen
Good afternoon, this is the fraud team. We're seeing suspicious payments on your account. To protect your money, we'll move it to a safe account for now. You'll get a code in a moment; could you read it out to me?
Show the answer
Phishing. This is bank helpdesk fraud. Hang up and call your bank yourself, on the number on your card or in your app.
How you can tell:
- The number on your screen can be faked.
- A 'safe account' to move your money to.
- Reading out a code to someone who called you.
From: DigiD
Your DigiD expires in 2 days. Renew it for free via digid-renew.example to keep access to your tax return.
Show the answer
Phishing. In doubt about your DigiD? Go to digid.nl yourself. Don't click links in a text about your DigiD.
How you can tell:
- A link to a site that isn't digid.nl.
- Hurry: in 2 days.
- Fear of not being able to file your tax return.
Seen at: A sticker on the parking meter
NEW: pay for parking faster with your phone. Scan the QR code and enter your card details.
Show the answer
Phishing. A QR code is just a link, except you can't see where it goes. Pay at the machine itself or through the parking app you already have.
How you can tell:
- A sticker on or next to the machine, not printed into it.
- A QR code that leads to an unknown site.
- Entering your card details on that site.
On Monday you agreed to go through the figures on Tuesday.
Organiser: Sanne, your colleague <[email protected]>
Weekly figures meeting
- When
- Tue 10:00 - 10:45
- Location
- Meeting room 2
As we discussed on Monday. Could you bring the September figures?
Show the answer
Real. Exactly what you expected, from someone you know, without having to click anything.
Why it checks out:
- You agreed on it together.
- No link, no attachment, no hurry.
- An ordinary meeting room as the location.
You've just set up your banking app on your new phone.
From: Your bank
Your banking app has just been activated on a new device. Wasn't you? Call us on the number on the back of your bank card.
Show the answer
Real. A good notification sends you to a number you already have, not to a link.
Why it checks out:
- It confirms something you just did yourself.
- No link: you call yourself, on a number you already have.
You work in customer service. Your phone rings: 'a colleague from IT'.
Caller: 'Robin from IT'
Hi, it's Robin from IT. We've got an outage in the customer system and I need to reset your session. Could you log in via the link I'm sending you now? You'll get a verification code, and I need that to finish the reset.
Show the answer
Phishing. That's how a big hack at a Dutch telecoms provider started in 2026. Real IT never asks for your code. Hang up and call the service desk back on the internal number.
How you can tell:
- IT calls you, though you didn't ask for anything.
- Logging in via a link the caller sends.
- The caller wants your verification code.
- Smooth, friendly and full of IT jargon: that's what makes it sound real.
Your provider had a big data breach last month. It was all over the news.
Caller: 'Your provider', with a friendly voice
Good afternoon, I'm calling on behalf of your provider about the data breach. You're entitled to compensation. To arrange it I'll send you a text code; could you read it out to me?
Show the answer
Phishing. After a big data breach at a telecoms provider, fraudsters called customers about 'compensation'. With the code read out to them they took over accounts or activated an eSIM. Hang up and check your provider's app yourself.
How you can tell:
- They're calling about something that was in the news.
- Compensation you didn't ask for.
- Reading out a text code to someone who called you.
From: Provider
Your SIM card expires in 48 hours due to new legislation. Switch to an eSIM for free via sim-switch.example to stay reachable.
Show the answer
Phishing. In 2025 and 2026 messages like this went round in the name of Dutch providers. Anyone who followed the steps handed their SIM card to criminals, who then used it to send scam texts in bulk. A SIM card doesn't just expire; check your provider's app.
How you can tell:
- Hurry: in 48 hours.
- 'New legislation' as the reason.
- A link to a site that isn't your provider's.
Real story: 'Your SIM card is expiring', and your number belongs to someone else
Last week you got a friendly WhatsApp message from someone at a well-known organisation. Now an invitation follows.
Organiser: Linda, Digital Business Foundation <[email protected]>
Teams meeting: working together
- When
- Fri 15:00 - 15:30
- Location
- Microsoft Teams. To join, enter code 7KQ-4MZ on Microsoft's sign-in page.
Lovely to chat! Here's the invitation. Teams asks for a code when you join; it's above. See you Friday!
Show the answer
Phishing. That code signs the attacker in to your account, two-step verification included. Never enter a code because an invitation or chat asks you to.
How you can tell:
- Friendly contact over chat first, then an invitation.
- You have to enter a code to 'join'. An ordinary Teams meeting doesn't ask for that.
- The sign-in page really is Microsoft's. That's exactly why it works.
Real story: A Teams invitation with a code, on the real Microsoft site
You booked a hotel for a trade fair, 12 to 14 November. A message arrives through the booking platform.
From: Hotel Southpark (via the booking platform)
Dear guest, we were unable to confirm the payment for your stay from 12 to 14 November. Please confirm your card within 24 hours via booking-confirm.example, or your reservation will be cancelled.
Show the answer
Phishing. Criminals hijacked hotel accounts on booking platforms and messaged guests with their real booking details. Check in the app, or call the hotel on the number from its own website.
How you can tell:
- Your real dates are right: the hotel's account may have been hijacked.
- Hurry: within 24 hours, or you lose the room.
- Re-entering your card details via a link.
Real story: The hotel's account hijacked, the guests scammed
You're selling your old office chair online. A buyer messages you.
From: Buyer (unknown number)
Hi! I'll take the chair. I pay from my business account, which works with a QR code. Just scan it with your banking app to accept the money, and I'll pick the chair up tomorrow.
Show the answer
Phishing. Someone sending you money only needs your account number. With this trick, fraudsters linked their own phone to the seller's bank account.
How you can tell:
- You never need to scan anything to receive money.
- A QR code in your banking app can link a new device to your account.
- An excuse ('business account') for an odd way of paying.
You look after the IT at the office. Your phone rings.
Caller: 'Eva from Finance' (unknown number)
Hi, it's Eva from Finance. I can't log in any more and I've got a deadline in ten minutes. Could you reset my password and set up my authenticator again? I haven't got my staff number to hand, sorry!
Show the answer
Phishing. That's how attackers got into large companies: not by hacking, but by calling the helpdesk. Call back on the number you already have for Eva, or check with her manager, before you reset anything.
How you can tell:
- Hurry and a bit of panic: you want to help.
- An unknown number, and no way to check who it is.
- A new password and a new authenticator: then the whole account belongs to the caller.
You've been with this provider for years and pay by direct debit.
From: Your provider <[email protected]>
Your October bill is ready
Your October bill is ready in the app and in your account. The amount will be collected by direct debit as usual. You don't need to do anything.
Show the answer
Real. If you want to see the bill, open your provider's app yourself.
Why it checks out:
- You get a bill every month.
- No link to click and no request for details.
- You can check it yourself in the app.
This morning you asked Joris for a client's quote.
From: Joris (your colleague)
Here's the quote you asked for. It's in our shared Quotes folder, version 3. I'm back in the office tomorrow if you have questions.
Show the answer
Real. You expected it, it's from someone you know and you open the file where it belongs.
Why it checks out:
- You asked for it yourself.
- No '(External)' label: it's from your own colleague.
- The file is in a folder you already know.
Every round deals new messages from 30. All made up, but every phish copies the trick of a real attack.
The check
How to check a message in thirty seconds
- Was I expecting this? An invoice, a parcel or an invitation you weren't expecting is suspicious.
- Who is the sender really? Look at the address, the number or the domain, not just the name.
- Is there rush or a threat? Then it's time to slow down.
- What am I asked to do? Click, log in, pay, pass on a code or install something? Extra care.
- Check it another way. Call yourself, on a number you look up, or open the app yourself.
In doubt? Then do nothing and check. A real bank, supplier or colleague is fine with that.
How it feels
Tuesday, 16:12
Based on a real case; names and details changed.
- Mila (accounts)
Joost, the wholesaler has a new account number. It came by e-mail this morning, with a neat letter attached.
- Joost (owner)
OK. Does it say why?
- Mila (accounts)
'New payment route as instructed by management.' A Spanish bank, bit odd. But it's from Petra's usual address there.
- Mila (accounts):
They've already asked twice whether I've updated it. Very polite, mind.
- Joost (owner)
Go ahead and change it, then that's sorted.
- Joost (owner):
Mila, the wholesaler just rang. They haven't received a thing from us since December.
- Mila (accounts)
But I've paid everything! To the new number.
- Joost (owner)
That number wasn't theirs. Petra's mailbox had been hacked, and our confirmation was tucked away in a hidden folder there. She never saw it.
- Mila (accounts)
So that money's gone? And we have to pay again?
- Joost (owner)
Looks like it. New rule: account number changed? Call first, on the number we already had.
It really happened
They fell for it, and this is what it cost
Click for the summary. Below it you'll always find the link to the full story.
Questions
And if you did click?
I clicked a link but didn't fill anything in.
Close the page. Keep an eye on your device for the next few days and make sure your updates and virus scanner are up to date. In doubt? Send us a message.
I entered my password.
Change it straight away, and everywhere else you use the same password. Turn on two-step verification and check whether new rules appeared in your mailbox that forward e-mail.
I transferred money or gave my bank details.
Call your bank straight away, on the number on your bank card or in your banking app. The sooner, the better. Then report it to the police. Also read first aid after a hack.
Can you train my team?
Yes. In a practical session we practise with examples like the ones above, tuned to your e-mail, your bank and your customers.
Press play
A sharp team, without a dull course
A short, practical phishing training with real examples. After that nobody clicks just like that. Or first read in the Evo-log how to spot phishing in 30 seconds.