In this article, you will learn how to quickly recognise a phishing email, which signs deserve extra attention, and what to do if you have doubts.
Phishing emails try to deceive you so that you, for example, click on a harmful link, open a file, enter your password, or make a payment.
Recognising phishing in 30 seconds
Before clicking on a link or opening an attachment, check at least these points:
-
Check the sender’s real email address.
Don’t just look at the displayed name. A message may, for example, show "Microsoft" or the name of your director, while the real email address comes from a completely different domain. -
Watch out for unexpected urgency.
Messages such as "your account will be blocked today", "pay immediately" or "confirm within 30 minutes" often try to pressure you. -
Check where a link actually leads.
On a computer, hover your mouse over the link without clicking. Check if the domain matches the organisation that claims to send the message. -
Be careful with unexpected attachments.
Do not open unexpected invoices, shared documents, ZIP files, or other attachments without first verifying whether you actually expected them. -
Are you unexpectedly asked for your password?
Never just enter your Microsoft 365 password or other login details after being directed via email to a website.
1. Check the sender
One of the most important checks is the full email address of the sender.
An attacker can easily make the displayed name look like a known person or organisation.
Displayed name:
Microsoft 365
Real email address:
security-microsoft365@example-random-domain.com
Pay special attention to the part after the @ symbol.
Also watch out for domain names that look very similar to the real domain but are subtly altered.
2. Watch out for pressure, panic, or an exceptional reward
Phishing messages often try to make you act quickly before you have time to think.
Examples:
- "Your Microsoft 365 account will be deactivated today."
- "Your mailbox is full. Click here to keep it immediately."
- "Urgently open this invoice."
- "Make this payment today."
- "You have won a prize. Confirm here."
- "A document has been shared with you. Sign in to view it."
3. Check links before clicking
The text of a link may show something different from the website the link actually leads to.
On a computer, you can usually hover your mouse over the link without clicking. The real web address then appears at the bottom or next to the browser.
Pay special attention to the domain name.
https://microsoft-login.example-random-domain.com
The words "Microsoft" or "Office 365" in a URL do not automatically mean the website belongs to Microsoft.
4. Be careful with attachments
Do not open an unexpected attachment just like that, even if the message seems to come from a customer, supplier, or colleague.
Especially unexpected files such as invoices, documents, ZIP files, or other downloads deserve extra checking.
5. Asked to enter your password?
A commonly used phishing technique is an email with a button to a fake Microsoft 365, bank, Dropbox, SharePoint, or other login page.
You enter your username and password and then, for example, receive an error message. At that moment, your details may already have reached the attacker.
6. Watch out for unexpected MFA requests
Do you receive a login request via Microsoft Authenticator while you are not trying to sign in yourself?
Do not approve this request.
An unexpected MFA request may mean someone knows your password and is trying to access your account.
Decline the request and contact your IT administrator immediately if in doubt.
7. A known sender can still be suspicious
Phishing does not only come from unknown addresses.
An attacker may have gained access to the mailbox of a supplier, customer, or colleague. This means a phishing message can effectively be sent from that person’s real email address.
Be extra careful when a known person suddenly asks for something unusual, for example:
- an unexpected payment;
- a change of bank account number;
- the purchase of gift cards;
- a password or verification code;
- urgently opening a document;
- changing payment details of a supplier.
Received a suspicious email: what do you do?
- Do not click on links.
- Do not open suspicious attachments.
- Do not reply to the email.
- Do not provide passwords, MFA codes, payment details, or other sensitive information.
- If possible, report the message as phishing in Outlook.
- Delete the message after reporting or checking it.
In Outlook, you can select a suspicious message and then choose:
Have you already clicked the link?
Clicking on a link does not automatically mean your account has been hacked, but be extra cautious.
If you then entered your password, an MFA code, bank details, or other sensitive information, contact your IT administrator as soon as possible.
The sooner it is checked and acted upon, the smaller the chance that an attacker can perform further actions with your account.
Not sure if an email is trustworthy?
If you still have doubts after the above checks, do not click anywhere and have the message checked first.
Are you unsure whether a message is legitimate? Contact our service desk via:
support@flexamit.com
Preferably include the suspicious message or clearly indicate which message it concerns. Meanwhile, do not click on links or open attachments.
In brief
- Check the sender’s real email address.
- Do not be rushed by urgent language.
- Check links before clicking.
- Do not open unexpected attachments.
- Never just enter your password or MFA code.
- Verify unusual requests via a second channel.
- When in doubt: do not click and ask for help.
Comments
0 comments
Please sign in to leave a comment.