Blog guideEducational content, not a workshop description

Cybersecurity and continuity

How to spot phishing emails before giving away access or money

A phishing email can copy a supplier’s name, continue a real conversation and arrive without obvious mistakes. Appearance alone is therefore a weak test. Useful verification separates the message from the requested action: confirm identity, context, destination and authorization through an independent channel before opening a file, signing in or moving money.

An employee carefully verifies a suspicious email in an office

Four habits that reduce phishing risk

  • Urgency, an unexpected change and a sensitive request matter more than spelling quality.
  • Verify payments, credentials and data through a known contact, never a number or link supplied by the questionable message.
  • Visible link text can conceal a different destination; open the service from a bookmark or type its known address.
  • When someone interacted with the message, prompt reporting helps contain accounts, devices and payments while preserving evidence.

1. Start with the request, not the design

Ask what the sender wants the employee to do. Common lures ask a person to open a document, enter credentials, share a code, change banking details, make a purchase or allow remote access. A correct logo and familiar signature do not prove origin because those elements are easy to copy. The strongest warning is often that the requested action does not match the company’s normal process.

Look for a change in context. An expected invoice may arrive from a different domain; a regular supplier may announce a new account without the agreed confirmation; a purported executive may demand secrecy and speed. CISA identifies urgent or emotional language, requests for personal or financial information, shortened links and incorrect addresses as signs that deserve verification.

  • Unexpected requests for a password, MFA code or banking data.
  • A changed beneficiary, delivery point or established procedure.
  • Pressure to act without consulting another person.
  • An attachment unrelated to the recipient’s work or conversation.
  • Sender, reply address and signature that do not align.

A message can be malicious even when it comes from a genuinely compromised account. If the action is sensitive or bypasses procedure, verify it even when the sender initially looks right.

2. Inspect the destination without using it

On a computer, hover over a link without clicking and compare the displayed destination with the expected domain. On a phone, avoid a long press if it might open the address; use safe features in the mail client or give the message to support. Read the domain carefully. Familiar words placed in a path, subdomain or long string do not make an unrelated domain official.

Do not use the email button to “check” the account. Open a new tab, use a managed bookmark or type the service’s known address. A genuine alert will often also appear inside the account. The FTC recommends contacting a company through a phone number or website the person knows is real rather than through information in a suspicious message.

  • Compare the complete sender address, not only its display name.
  • Look for substitutions, inserted characters and unexpected domain endings.
  • Treat executable, compressed or content-enabling attachments cautiously.
  • Do not enter credentials after following a questionable link.
  • Check the account through a separate, known route.

3. Confirm identity and authority through another route

Independent verification does not mean replying to the same email. Call a number from a contract, internal directory or official website; begin a new message to a saved address; or speak directly with the responsible person. For payments, account changes and data disclosures, use a dual-control procedure that states who requests, who confirms and who authorizes.

Ask an operational question that is not contained in the questionable message. If the purported requester is traveling or unavailable, that inconvenience does not cancel the control: the transaction can wait or escalate. Improvised exceptions are exactly what attackers exploit. The objective is not to prove that the email “looks fake,” but to establish separately that the action is legitimate.

  • Use contact details obtained before the message arrived.
  • Require a second approval for payments and beneficiary changes.
  • Never share authentication codes with someone who calls or writes.
  • Record who confirmed, through which channel and what was approved.

When a supplier requests new banking details, stop the payment until the established validation is complete. Replying in the thread or calling the number in that same email does not create an independent channel.

4. Report the message and preserve useful context

Use the mail service’s phishing-report function or the company support channel. Where possible, retain the original message with its headers, attachments and receipt time; a screenshot omits technical information. Do not forward a dangerous attachment to coworkers to ask whether it looks real. The responsible team can inspect it through controlled procedures and tools.

Reporting should not be a punishment. A sound process makes it easy to warn others, block a domain or file and locate similar messages before more recipients act. After reporting, follow the administrator’s direction for quarantine or deletion. For suspected fraud, the organization can also use reporting channels appropriate to its jurisdiction and the providers involved.

  • State whether the message, link or attachment was opened.
  • Say whether credentials, data or codes were entered.
  • Preserve the time, recipients, subject and related conversation.
  • Do not edit or download the suspicious file again.
  • Escalate immediately if a transfer or payment instruction changed.

5. If someone clicked, respond to what actually happened

A click without data entry does not prove compromise, but it should be reported so redirects, downloads and logs can be assessed. If a password was entered, change it through a trusted device and route, terminate active sessions where the service permits, and inspect recovery methods and mailbox rules. If the employee approved an MFA prompt or surrendered a code, treat the account as potentially accessed.

If a file ran or software was installed, disconnect the device from networks when support directs and avoid further work until it has been evaluated. For a payment or financial disclosure, contact the institution immediately through known channels; speed may preserve response options but cannot guarantee recovery. Document each action and preserve evidence so the response can cover related accounts, devices and business processes.

  • Notify security or support without waiting for symptoms.
  • Change exposed credentials from a trusted session.
  • Revoke sessions, tokens and access where appropriate.
  • Inspect forwarding rules, recovery methods and recent activity.
  • Escalate payments, personal data and remote access to the proper owners.

Frequently asked questions

Questions that should be settled before acting

Can a well-written email still be phishing?

Yes. Attackers can copy real messages, use writing tools or control a legitimate account. Evaluate the requested action, domain, context and procedure, then verify through another channel when risk is present.

Can I reply to the sender to confirm?

That is not independent verification. If the account or conversation is compromised, the reply reaches the attacker. Use a number, directory, application or address you already knew and start a separate conversation.

What should I do if I already entered my password?

Report it immediately. From a trusted route, change the password, revoke sessions when possible, review MFA, recovery and activity, and change any reused credential. Follow the organization’s incident response process.

Sources and further reading