Phishing is how most account compromises happen. Recognizing it is a skill that takes practice; reporting it correctly protects everyone.
What is phishing?
An attempt to trick you into:
- Sharing credentials (sign-in to a fake page)
- Installing malware (open an attachment)
- Wiring money (impersonating your CEO)
- Disclosing sensitive data (employee info, customer lists)
Sent via email, SMS, voice call, social media. Email is most common.
1. The classic indicators
Red flags in an email:
- Urgency — "Act now or your account will be closed"
- Authority — "I'm your CEO and I need this done immediately"
- Reward — "You've won a prize" or "Refund pending"
- Threat — "Legal action will be taken if you don't respond"
Pressure tactics override your judgment. Take a breath.
2. Check the sender carefully
The display name can lie:
- Email "From: HR" but actual address
[email protected] - "Microsoft Support" from
microsoftsupport.gmail.com
Click the sender name to see the actual address. Mismatch = suspicious.
3. Check the links
Don't click. Hover (don't click) to see the actual URL:
- Link text "office.com/login" but URL goes to
office-com.evilsite.com/login - Shortened URLs (bit.ly, tinyurl) hide the destination
If you must verify, navigate to the legitimate site yourself by typing the URL.
4. Check the language
Phishing often has:
- Spelling and grammar mistakes
- Awkward phrasing ("Kindly do the needful")
- Inconsistent formatting
- Generic greetings ("Dear Customer")
Modern phishing is better but still has tells.
5. Unexpected attachments
If you didn't request an attachment, don't open it:
- Invoices from companies you don't work with
- "Updated company policy" attachments
- "Receipt" or "delivery notice" attachments from unknown senders
When in doubt, contact the sender via another channel.
6. Specific types of phishing
- Spear phishing: targeted at you specifically, often uses public info to look legitimate
- CEO fraud: impersonates an executive asking for wire transfer
- Vendor impersonation: looks like a supplier asking to update payment details
- HR / IT impersonation: "Please update your password at this link"
The targeted ones are the most dangerous because they know your role.
7. SMS phishing (smishing)
Same principles, via text message:
- "Your delivery is held — click here to release"
- "Your bank has noticed unusual activity"
- "Tax refund pending — confirm details"
Banks and authorities never ask you to click a link in SMS.
8. Voice phishing (vishing)
Calls claiming to be:
- IT support asking for your password (IT never asks)
- Microsoft / Apple support saying you have a virus (they don't cold call)
- "Your computer has been hacked" — never call any number they tell you
Hang up. If you're worried, call the company yourself from their official number.
9. How to report
Most organizations have:
- Report Message add-in in Outlook (button next to Reply)
- A dedicated phishing inbox (e.g.
[email protected]) - IT helpdesk
Report — don't just delete. Reports help IT block the campaign for everyone.
10. After reporting
If you reported:
- IT will investigate
- You may get follow-up questions
- Don't delete the email until they confirm — they may need it for analysis
If you reported by mistake (it was legitimate), IT will let you know.
What if you clicked?
If you clicked a phishing link or opened an attachment:
- Don't panic
- Don't enter credentials (if you haven't)
- If you entered credentials: change password immediately on the real site
- Report to IT immediately — speed matters
- Run antivirus scan
The faster you report, the more IT can contain.
When to ticket
Raise a ticket if:
- You clicked or opened something suspicious
- You're getting persistent phishing campaigns targeting you
- A coworker fell for one and you noticed
- You suspect your account is compromised
Include the email (forward as attachment to preserve headers), what you did, and when.