Phishing is how most account compromises happen. Recognizing it is a skill that takes practice; reporting it correctly protects everyone.

What is phishing?

An attempt to trick you into:

  • Sharing credentials (sign-in to a fake page)
  • Installing malware (open an attachment)
  • Wiring money (impersonating your CEO)
  • Disclosing sensitive data (employee info, customer lists)

Sent via email, SMS, voice call, social media. Email is most common.

1. The classic indicators

Red flags in an email:

  • Urgency — "Act now or your account will be closed"
  • Authority — "I'm your CEO and I need this done immediately"
  • Reward — "You've won a prize" or "Refund pending"
  • Threat — "Legal action will be taken if you don't respond"

Pressure tactics override your judgment. Take a breath.

2. Check the sender carefully

The display name can lie:

  • Email "From: HR" but actual address [email protected]
  • "Microsoft Support" from microsoftsupport.gmail.com

Click the sender name to see the actual address. Mismatch = suspicious.

3. Check the links

Don't click. Hover (don't click) to see the actual URL:

  • Link text "office.com/login" but URL goes to office-com.evilsite.com/login
  • Shortened URLs (bit.ly, tinyurl) hide the destination

If you must verify, navigate to the legitimate site yourself by typing the URL.

4. Check the language

Phishing often has:

  • Spelling and grammar mistakes
  • Awkward phrasing ("Kindly do the needful")
  • Inconsistent formatting
  • Generic greetings ("Dear Customer")

Modern phishing is better but still has tells.

5. Unexpected attachments

If you didn't request an attachment, don't open it:

  • Invoices from companies you don't work with
  • "Updated company policy" attachments
  • "Receipt" or "delivery notice" attachments from unknown senders

When in doubt, contact the sender via another channel.

6. Specific types of phishing

  • Spear phishing: targeted at you specifically, often uses public info to look legitimate
  • CEO fraud: impersonates an executive asking for wire transfer
  • Vendor impersonation: looks like a supplier asking to update payment details
  • HR / IT impersonation: "Please update your password at this link"

The targeted ones are the most dangerous because they know your role.

7. SMS phishing (smishing)

Same principles, via text message:

  • "Your delivery is held — click here to release"
  • "Your bank has noticed unusual activity"
  • "Tax refund pending — confirm details"

Banks and authorities never ask you to click a link in SMS.

8. Voice phishing (vishing)

Calls claiming to be:

  • IT support asking for your password (IT never asks)
  • Microsoft / Apple support saying you have a virus (they don't cold call)
  • "Your computer has been hacked" — never call any number they tell you

Hang up. If you're worried, call the company yourself from their official number.

9. How to report

Most organizations have:

  • Report Message add-in in Outlook (button next to Reply)
  • A dedicated phishing inbox (e.g. [email protected])
  • IT helpdesk

Report — don't just delete. Reports help IT block the campaign for everyone.

10. After reporting

If you reported:

  • IT will investigate
  • You may get follow-up questions
  • Don't delete the email until they confirm — they may need it for analysis

If you reported by mistake (it was legitimate), IT will let you know.

What if you clicked?

If you clicked a phishing link or opened an attachment:

  • Don't panic
  • Don't enter credentials (if you haven't)
  • If you entered credentials: change password immediately on the real site
  • Report to IT immediately — speed matters
  • Run antivirus scan

The faster you report, the more IT can contain.

When to ticket

Raise a ticket if:

  • You clicked or opened something suspicious
  • You're getting persistent phishing campaigns targeting you
  • A coworker fell for one and you noticed
  • You suspect your account is compromised

Include the email (forward as attachment to preserve headers), what you did, and when.