How to Spot Phishing Emails
Phishing is when an attacker impersonates a company or trusted individual to trick the recipient into taking a malicious action, such as clicking a link or entering sensitive information on a fake website. They do this by using emotional manipulation, such as creating a sense of urgency or fear, to encourage or even demand immediate action from the victim. This is intended to fluster the recipient so that they don’t carefully examine the email and other inconsistencies are overlooked.
A common tactic in phishing emails is to spoof logos or brands that the attacker knows their target uses or trusts. This can include well-known banks, online retailers or the makers of popular apps. This is called spear phishing. Cybercriminals can also spoof email addresses to make it appear as though the email originated from a familiar domain.
The attacker may also create a false sense of authority and urgency in their email. For example, they might claim to be a high-level executive and use generic greetings to try and get the recipient to bypass standard verification procedures such as wire transfers or sharing confidential information.
A common sign of a phishing attack is poor grammar and misspellings. However, professional companies and organizations typically have a writing and editing staff so these types of mistakes should be a red flag. Similarly, an unusual subject matter is a sign that something may be up. For example, a message about out-of-control IT spending could be a phishing attempt.