The warning signs
- Urgency or pressure: “your account will be closed today”, “pay this invoice before 5pm”
- A sender name you know, but an email address that doesn't match
- Unexpected attachments, shared files, or voicemail notifications
- Requests to change bank details, buy gift cards, or approve a payment
- Sign-in pages reached from an email link instead of the address you normally type
- A message that's slightly off from someone you know: unusual tone, odd greeting, wrong signature
The most expensive scams often contain no link at all. An email that appears to come from your boss or a vendor, asking to change where a payment goes, is a common example. Always confirm by phone using a number you already have.
Before you click
- Hover over links to see where they actually go
- Open your accounts by typing the address or using a bookmark, not from the email
- Verify any request involving money, passwords, or sensitive data through a separate, known contact
- When in doubt, forward it to whoever handles your IT
If you clicked or entered a password
- Don't panic, and don't try to cover it up. Speed matters more than blame.
- Change the password for that account from a different, trusted device
- Make sure multi-factor authentication is on, and sign out other sessions
- Tell your IT support immediately so they can check for forwarding rules, new sign-ins, and other changes attackers make
- If you opened an attachment, disconnect the computer from the network and wait for IT
- If money moved, call your bank right away
How to make phishing less dangerous
- Multi-factor authentication on every account, so a stolen password alone isn't enough
- Email filtering that flags external senders and lookalike domains
- Alerts for new forwarding rules and sign-ins from unusual places
- Short, regular reminders for staff with real examples
- A written rule that payment changes are always confirmed by phone