Every day, phishing attempts try to bypass our defenses by exploiting trust or a sense of urgency. Before clicking or replying, take 30 seconds to analyze the message using these 5 steps.
1. Sender's Address: Inspect the actual domain
- What to look for: Never rely on the display name (e.g., Accounting Department). Click or hover over the name to display the full email address.
- The classic trap: Typosquatting ( e.g.,
[email protected]instead ofpaypal.comor[email protected]).
2. The Tone of the Message: Hunt down urgency and pressure
- What to look for: Does the message require immediate action under penalty of sanction, account blocking, or financial loss?
- The classic trap: "Your account will be suspended in 2 hours" or "Urgent confidential procedure at the request of the CEO".
3. Links: Hover before clicking
- What to look for: Hover your mouse pointer over any button or link without clicking. The actual destination address will appear at the bottom of your screen or in a tooltip.
- The classic trap: The text displays
[https://banque.com](https://banque.com), but the link points to[http://site-pirate.ru/login](http://site-pirate.ru/login).
4. Attachments: Beware of risky formats
- Things to check: Were you expecting this file? Is the extension common (.pdf, .docx) or suspicious (.exe, .zip, .iso, .html, .xlsm)?
- The classic trap: An "Unpaid invoice" in the form of an archive file (.zip) or a Word document asking to activate macros upon opening.
5. The Request: Verify operational consistency
- What to look at: Does the request fall outside of usual procedures? (Change of supplier's bank details, purchase of gift cards, unsolicited password reset).
- The classic trap: Any change to bank details received only by email without prior verbal confirmation.
The right thing to do if in doubt:
- Do not click on any links or open any attachments.
- Do not reply directly to the email.
- Check through another channel (phone call via a known number, Teams/Slack message).
- Notify the IT team or use the report button in your email.