Phishing Awareness
Practice identifying suspicious messages and choosing a safe response before a scam captures your information.
Spot the Warning Signs
theoryLearn how phishing messages use urgency and impersonation to make unsafe actions feel normal.
Slow down when a message creates pressure
Phishing messages imitate a trusted person or service and ask you to act quickly. The message may claim that your account will be closed, a payment failed, or an urgent document needs your review.
Look for several signals together:
- The sender address uses a lookalike domain or an unexpected account.
- The message creates urgency or asks you to keep the request secret.
- The greeting, spelling, or tone does not match the supposed sender.
- A link or attachment asks for a password, payment, or personal information.
One unusual detail is worth checking. Several unusual details are a reason to stop and verify the request independently.
Knowledge Check
An unexpected account message lands in your inbox. Which mix of details should make you stop and verify it?
Inspect the Link Safely
theoryPractice checking where a link leads without opening the destination.
Read the real destination before trusting it
A link’s visible text can be different from its real destination. On a computer, hover over the link to preview the address. On a phone, press and hold when the application provides a preview. Do not sign in just to find out whether a link is safe.
Read the domain from right to left. In accounts.example.com, the important registered domain is example.com. A name such as example.com.attacker.test belongs to attacker.test, not example.com.
When a message might be legitimate, open the service using a bookmark or a manually typed address instead of the message link.
Knowledge Check
You receive a password-reset link you did not request. What is the safest way to check whether it is real?
Verify and Report
theoryChoose a safe next step after recognizing a suspicious message.
Verify through a channel you already trust
Do not reply to a suspicious message, call a number included in it, or use its links to verify the request. Instead, contact the person or organization through a known phone number, official application, or bookmarked website.
Report the message using your mail provider’s phishing control or your organization’s security process, then delete it. If you already entered information, change the affected password from the trusted service, enable MFA, and tell the organization quickly.
Knowledge Check
Once you have identified a suspicious message, what should happen next?
Handle a Suspicious Request
theoryApply the warning signs to a realistic message before deciding what to do.
Combine clues before you act
Imagine that a message appears to come from your manager. It asks you to buy gift cards immediately, says they are needed for a confidential project, and tells you to reply with the codes. The sender address uses a slightly different domain from your organisation.
This request has several independent warning signs: an unusual payment request, secrecy, urgency, and a lookalike address. Do not continue the conversation or send anything. Verify the request using a known phone number or an established workplace channel.
Knowledge Check
A manager appears to request gift cards through a lookalike address. What is the safest response?
Build a Safe Habit
theoryTurn phishing detection into a repeatable decision process.
Pause, verify, and report
Use a simple three-step routine whenever a message asks for credentials, money, confidential information, or an unexpected download:
- Pause. Do not click, reply, open the attachment, or share information.
- Verify. Contact the supposed sender or service through a trusted channel you found independently.
- Report. Use the organisation’s reporting process, then remove the message.
If you already clicked or entered information, tell the organisation quickly. Change the affected password from the official site, revoke unfamiliar sessions, and enable MFA.
Knowledge Check
Before doing anything else, what is the right first move when an unexpected message asks for sensitive information?
Complete the Phishing Response
theoryWork through a realistic message that combines impersonation, urgency, and a malicious attachment.
Choose the complete response, not just one safe action
You receive an email that appears to come from your payroll provider. It says your direct-deposit details will be suspended in one hour, includes a spreadsheet attachment, and asks you to reply with a one-time verification code. The sender domain has one extra character compared with the provider’s real domain.
Treat the message as phishing. Do not open the attachment, reply, or share the code. Report it through your organisation’s process, then contact payroll through a known channel to confirm whether any action is needed. If you opened the file or shared information, tell the security team immediately so they can help protect your account.
Knowledge Check
The payroll message combines urgency, a lookalike domain, and an attachment. Which response handles the whole situation safely?