Every day, phishing attempts try to bypass our defenses by exploiting trust or a sense of urgency. Before clicking or replying, take 30 seconds to analyze the message using these 5 steps.

1. Sender's Address: Inspect the actual domain

  • What to look for: Never rely on the display name (e.g., Accounting Department). Click or hover over the name to display the full email address.
  • The classic trap: Typosquatting ( e.g., [email protected] instead of paypal.com or [email protected] ).

2. The Tone of the Message: Hunt down urgency and pressure

  • What to look for: Does the message require immediate action under penalty of sanction, account blocking, or financial loss?
  • The classic trap: "Your account will be suspended in 2 hours" or "Urgent confidential procedure at the request of the CEO".

3. Links: Hover before clicking

  • What to look for: Hover your mouse pointer over any button or link without clicking. The actual destination address will appear at the bottom of your screen or in a tooltip.
  • The classic trap: The text displays [https://banque.com](https://banque.com), but the link points to [http://site-pirate.ru/login](http://site-pirate.ru/login).

4. Attachments: Beware of risky formats

  • Things to check: Were you expecting this file? Is the extension common (.pdf, .docx) or suspicious (.exe, .zip, .iso, .html, .xlsm)?
  • The classic trap: An "Unpaid invoice" in the form of an archive file (.zip) or a Word document asking to activate macros upon opening.

5. The Request: Verify operational consistency

  • What to look at: Does the request fall outside of usual procedures? (Change of supplier's bank details, purchase of gift cards, unsolicited password reset).
  • The classic trap: Any change to bank details received only by email without prior verbal confirmation.

The right thing to do if in doubt:

  1. Do not click on any links or open any attachments.
  2. Do not reply directly to the email.
  3. Check through another channel (phone call via a known number, Teams/Slack message).
  4. Notify the IT team or use the report button in your email.

Categories: