Hone

Lessons · IT support · spotting phishing

Phishing: the checks, in the order that catches it fastest

A phishing message is one that pretends to be from somebody you trust so that you click, sign in or pay. Check the real sender address, not the display name; hover the link and read where it really goes; look for urgency or a threat; look for a request for a password, a code or a payment. Any one of those is enough to stop and report.

Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.

What it is for

The call that came in as 'my email is broken' was a user who had already typed their password into a page that looked like the sign-in screen, because the message said their mailbox was full and would be deleted at noon. The technician who asks 'what did the message say' before 'let me reset your password' turns a mailbox ticket into a security incident report in the first minute, which is where it has to be.

How to think about it

Do not click anything while you look. Read the sender's real address, character by character: the domain after the @ is the tell. Hover the link and read the real destination; it is usually nothing like the text. Count the pressure: deadlines, threats, a boss who 'cannot talk right now'. Ask what it wants: a password, a code, a gift card, a bank change. Then report it to security with the message attached, and tell the user what to do if they already clicked.

Worked example

Display name 'IT Service Desk', real address: it-desk@secure-mail-verify.example
The name is ours. The domain is not. That alone is enough.
Link text 'Sign in to keep your mailbox', hover: a page on a host nobody has heard of
The words say one thing and the address says another. Never the same place.
'Your mailbox will be deleted at 12:00 today'
A deadline is the pressure that makes people skip the checks above.
Reported to security with the original message; user's password reset because it was typed in
Reported, with evidence. And the password is treated as stolen, because it was.

Your turn

Write what you hover over to see where a link really goes, before anything else.

Hover the  and read the real destination

The trap

Trusting the display name. 'From: CEO' is text anybody can type. The address after the @ is the only part the sender cannot fake without owning the domain.

Practise spotting phishing on HoneA question on it now, a coding challenge where there is one, and it is remembered for review. Free, no email needed.