6 things your team can do to prevent a phishing attack

A phishing attack aims to trick you into clicking on a link or attachment that can infect your machine with malware or take you to a fake site. The fake sites are designed to look realistic so that you attempt to log in, giving the hackers your login details in the process.

Phishing attacks are becoming increasingly common, and attackers are getting more and more creative with their attempts to gain access to your data and/or money. With so many people now relying on the internet to work, socialise and live their everyday life, the chances of encountering these attacks are higher than ever. Even though we all think we know exactly what to look out for to keep our information safe, people still frequently fall victim.

There are several technical steps that can help stop them from reaching you, but in the case that some get through, here are a few key steps to go through that will help protect you, your friends, and your family from clicking on any dodgy links. 

1) Don’t panic

Phishing often works because the scammers know how to play on our psychology. They create a sense of urgency, telling you to “act now” to avoid any supposed threats to your machine and information. 

But hold fire – there’s no need to rush. You always have enough time to think things through, so go through the steps to ensure everything is legitimate before you make a decision. This is especially essential if you’ve been sent an email containing a link, or asking for any private information or money.

2) Check the source

You need to work out whether the email is genuine and from the person or organisation it says it is. Here are a few tips to help you out:

Scrutinise the sender’s email address – is it the actual domain the organisation uses? Look for lookalikes or spelling mistakes. For example, info@amazon.co.uk or info@amaz0n.co.uk.

Also, most organisations will have their own company accounts and user domain, except for some small operations. No legitimate organisation will send emails from an address that ends @gmail.com (not even Google). 

This is often a huge giveaway but the problem is, in really sophisticated attacks, the scammers can take over a legitimate email so you cannot tell there is a problem from their address. 

If you have ANY doubts, don’t click any links or attachments. Approach the sender directly to confirm, using a different channel – so either by phone, using their app, or going directly to their website and logging on.

3) Spelling, punctuation and grammar

Spelling, punctuation and grammar is a huge giveaway when it comes to phishing attacks. If you’ve received an email from a large organisation, Lloyds bank for example, and the email is riddled with spelling mistakes, it’s very likely a scam.

Check if the style and grammar are what you would expect from the person or organisation who’s sent it, and see if the instructions make logical sense.

4) Inspect the link

Even if you’re sure the email seems legitimate, you should still inspect any link before clicking it if there’s a chance of you jeopardising any sensitive information (like login details) or downloading any files. Some malicious sites can download files without you even consenting or realising it, which is why this is such an important step.

If you hover over a link you can see the actual URL that is going to open if you click on it. Examine it carefully, and see if it lines up with what you’d expect to see.

Look out for subdomains. This is where you get a domain in the form of ‘something dot something dot com’ (or .co.uk etc).

In these cases, the actual domain is ONLY the last something before the dot com.

Soscams.amazon.com’ would be from Amazon

But if the link wasamazon.scams.com’, this would have nothing to do with Amazon.

4) Look for the lock

Any legitimate site address should start with https  (the s is the crucial bit) and should show a padlock in the browser bar where the address is. It is not enough on its own to reassure you – because scammers can set up sites with secure certificates and padlocks – but its absence is enough to instantly tell you not to enter any sensitive information on that site.

6) Get conditioned

The guidance we’ve given you above is solid but the problem is that you only have to get it wrong once and you could be in trouble. Ultimately, the best way to avoid phishing attacks is to get good at spotting them, especially recognising the latest styles and tricks the scammers are using.

Practice makes perfect and our recommendation would be to sign up for simulated phishing attacks.

Having looked at everything available, we offer a service from a global world leader in security awareness training called KnowBe4. We manage the process for you, sending simulated phishing emails to your team in a totally safe way. If your staff click a link they shouldn’t, they receive immediate feedback and training. You can see how many get it wrong and you’ll be able to track how quickly their ability to spot phishing emails and bad links improves.

It costs from under £3 per person per month and the great thing is, you are giving your staff a skill that will help protect them in their personal life too.

What about text messages, social media and phone calls?

It’s not just emails anymore – scammers will approach you through any channel they can and get you to disclose sensitive information. The 5 steps still work. The bottom line – don’t panic and if in any doubt, contact them through a different, official channel to confirm the request.

In summary

Our 5 steps to avoid falling for phishing attacks are:

  1. Don’t panic
  2. Check the source
  3. Spelling, punctuation and grammar
  4. Inspect the link
  5. Look for the lock
  6. Get conditioned

For more help…

Check out our cost-effective staff awareness training, or get in touch with our team using the contact form below.