What Is Phishing?
Phishing is a type of cyberattack where someone sends a fraudulent message — usually an email — designed to trick you into revealing sensitive information, clicking a malicious link, or downloading harmful software.
These messages are designed to look legitimate. They often impersonate trusted brands, coworkers, or service providers.
The Most Common Tricks
Phishing emails rely on psychological manipulation. Here are the two most common tactics:
1. Urgency or Fear
These emails try to create panic so you act without thinking.
- “Your account has been compromised — click here immediately.”
- “Unusual sign-in detected. Verify your identity now.”
- “Your payment failed. Update your billing info to avoid service interruption.”
2. Excitement or Curiosity
These emails try to lure you in with something appealing or intriguing.
- “You’ve won a $500 gift card!”
- “Someone shared a document with you.”
- “Your package is on its way — track it here.”
Quick Rule of Thumb
If an email makes you feel like you need to act right away — stop and double-check. That urgency is exactly what the attacker is counting on.
Red Flags Anyone Can Notice
You don’t need to be in IT to spot these warning signs:
Misspelled or Unusual Sender Address
The display name might say “Microsoft Support,” but the actual email address could be something like support@micros0ft-security.com. Always check the full sender address, not just the name.
Poor Grammar or Awkward Phrasing
Legitimate companies proofread their communications. If an email has strange sentence structure, odd formatting, or spelling errors, that’s a red flag.
Unfamiliar or Suspicious Links
Before clicking any link, hover over it (don’t click). The actual URL will appear at the bottom of your browser or in a tooltip. If it doesn’t match the expected website — or uses a suspicious domain — don’t click.
Requests for Personal Information
Legitimate companies will never ask for passwords, Social Security numbers, or credit card details via email. If an email asks you to “confirm” or “verify” sensitive info, it’s almost certainly a phish.
Real vs. Fake: A Side-by-Side
Here’s how to tell a legitimate email from a phishing attempt:
Real Email
- Sender address matches official domain
- Professional tone and correct grammar
- Links point to official URLs
- No request for sensitive information
Phishing Email
- Sender uses a lookalike or misspelled domain
- Awkward phrasing, grammar errors
- Links redirect to suspicious sites
- Asks for passwords or personal data
Safe Actions to Take
Never Click Links Directly
If an email asks you to log in or verify something, don’t click the link in the email. Instead, open your browser and navigate to the website directly by typing the URL yourself.
Report as Phishing
Most email clients have a built-in option to report phishing:
- Gmail: Click the three dots next to the reply button and select “Report phishing.”
- Outlook: Select the message, go to the “Report” button in the ribbon, and choose “Report phishing.”
Reporting helps train the email provider’s spam filters and protects others from the same attack.
Notify Your IT Team
If you’re part of an organization, let your IT team know immediately. They can check whether others received the same email, block the sender, and take steps to protect the network.
Slow Down and Verify
Phishing works because it catches people off guard. The best defense is simple: slow down, look at the details, and when in doubt — ask your IT team.
If you’d like help training your team to spot phishing emails or setting up stronger email protection, reach out to IT Launch Solutions.