Lessons · IT support · spotting phishing
Phishing: the checks, in the order that catches it fastest
A phishing message is one that pretends to be from somebody you trust so that you click, sign in or pay. Check the real sender address, not the display name; hover the link and read where it really goes; look for urgency or a threat; look for a request for a password, a code or a payment. Any one of those is enough to stop and report.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
The call that came in as 'my email is broken' was a user who had already typed their password into a page that looked like the sign-in screen, because the message said their mailbox was full and would be deleted at noon. The technician who asks 'what did the message say' before 'let me reset your password' turns a mailbox ticket into a security incident report in the first minute, which is where it has to be.
How to think about it
Do not click anything while you look. Read the sender's real address, character by character: the domain after the @ is the tell. Hover the link and read the real destination; it is usually nothing like the text. Count the pressure: deadlines, threats, a boss who 'cannot talk right now'. Ask what it wants: a password, a code, a gift card, a bank change. Then report it to security with the message attached, and tell the user what to do if they already clicked.
Worked example
Display name 'IT Service Desk', real address: it-desk@secure-mail-verify.exampleThe name is ours. The domain is not. That alone is enough.
Link text 'Sign in to keep your mailbox', hover: a page on a host nobody has heard ofThe words say one thing and the address says another. Never the same place.
'Your mailbox will be deleted at 12:00 today'A deadline is the pressure that makes people skip the checks above.
Reported to security with the original message; user's password reset because it was typed inReported, with evidence. And the password is treated as stolen, because it was.
Your turn
Write what you hover over to see where a link really goes, before anything else.
Hover the and read the real destination
Solve one, graded on the server
The trap
Trusting the display name. 'From: CEO' is text anybody can type. The address after the @ is the only part the sender cannot fake without owning the domain.