Blog
Would you recognise a phishing email?
Billions of emails are sent around the world every day. Most of them are entirely safe, including work correspondence, invoices, newsletters and various notifications. Among them, however, are also emails whose only purpose is to deceive the recipient.
Phishing emails are one of the most widespread cyberattack methods in the world. Their aim is not to break into a computer using complex technical means. Instead, they rely on the user making a mistake. The user opens a harmful link, downloads an attachment or enters their access credentials on a fake website.
In the past, such emails were relatively easy to notice. They often contained grammatical errors, awkward design and suspicious links. Today, however, attackers can use artificial intelligence to produce professionally designed and linguistically correct emails. These look almost identical to a company’s own messages. That is why the appearance of an email matters less than it used to. What matters more is knowing the signs that separate a genuine message from a fraudulent one.
What is phishing?
Phishing is a social engineering attack in which the attacker pretends to be a trusted person or brand in order to obtain confidential information. Social engineering means influencing a person’s behaviour rather than breaking into a system.
What attackers most often try to obtain
-
Usernames and passwords
-
Online banking credentials
-
Payment card details
-
Company system credentials
-
Personal data
-
The opportunity to install malware on a computer
Phishing is not a technical attack. It exploits human psychology. Attackers try to create the feeling that a situation is urgent, dangerous or highly advantageous. The person then makes a decision without checking the facts.
Why are phishing emails still so successful?
Many people believe that only inexperienced users fall for such emails. In reality, the statistics show the opposite. Fraudsters understand human behaviour very well. They use emotions rather than technology.
The five most commonly used psychological techniques
Urgency
-
“Your account will be blocked.”
-
“Act within 24 hours.”
-
“Confirm your identity immediately.”
The less time there is to think, the more likely a person is to click the link.
Fear
The message states that the account is at risk, that a payment has not been made or that access will soon be denied.
Authority
Attackers pretend to be banks, government institutions, delivery companies or IT service providers, because people trust these brands.
Curiosity
-
“Listen to your voice message.”
-
“A document has been sent to you.”
-
“View the attached invoice.”
Gain
-
“Gift card.”
-
“Prize won.”
-
“Discount code.”
This ability to trigger emotions is the main reason why phishing attacks remain so effective.
The most common types of phishing in email
Account security notifications
These are among the most widespread, and they usually claim that:
-
Suspicious login activity has been detected
-
The password will expire soon
-
The account will be blocked
-
Identity confirmation is required
The aim is to make the user enter their password on a fake login page.
Fake invoices
A fake invoice can be a PDF, a Word document, a ZIP archive or an HTML file. Companies receive invoices regularly, which makes this type of attack particularly effective. The attachment may contain harmful code or take the user to a fake login page.
Delivery notifications
Fraudsters exploit people’s habit of shopping online. The message claims that a parcel cannot be delivered, that a small customs or delivery fee must be paid, or that the address needs to be confirmed.
Emails sent in a manager’s name
These are particularly dangerous for companies. The attacker pretends to be the company’s manager or finance director and demands an urgent payment or, for example, that confidential information be sent. Such attacks are also known as Business Email Compromise (BEC), and they cause companies considerable financial losses.
Document sharing notifications
These emails state that you have been given access to a document. After the link is opened, a login page is imitated, and the user is asked to enter their email password.
How to spot a phishing email
Although every attack is different, in most cases the same signs appear.
It urges you to act quickly
If an email creates the impression that action is needed immediately, that is always a reason to be careful.
The sender address does not match the company
The display name may look correct, but the email address itself may be completely different. Always look at the full address, not only the sender’s name.
The link leads to a different website
Before clicking a button or a link, hover your mouse cursor over it. If the address shown does not match the company’s official website, the link should not be clicked.
It asks you to enter a password
Legitimate companies almost never ask you to send a password or to enter one through a link received by email.
Unexpected attachments
If you are not expecting an invoice or a document, do not open the attachment simply because it looks important.
A generic form of address
-
“Thank you, customer!”
-
“Dear user!”
A large proportion of companies use personalisation in their emails.
The message triggers a strong emotional reaction
If an email causes anxiety, fear or urgency, stop before taking any action and check its authenticity carefully.
What to do if you become suspicious
If you are not certain that an email is authentic
-
Do not rush
-
Do not open attachments
-
Do not click links
-
Check the sender address
-
Open the service’s website manually rather than using the link in the email
-
If necessary, contact the company through its official contact channels
Spending one minute checking an email is far safer than dealing with the consequences.
What to do if you did click the link
That does not yet mean you have suffered an attack. If you did not enter any information and did not download anything, the risk may be low.
If you entered a username or password
-
Change the password immediately
-
Turn on two-factor authentication (2FA) if it is not already active
-
Review recent logins to your account
-
Inform your company’s IT specialist or the service provider
The sooner action is taken, the greater the chance of preventing the consequences.
How can companies protect their employees?
Although technical security solutions matter, people remain an essential part of cyber security.
The most effective protective measures
-
Regular cyber security training for employees
-
Phishing simulations
-
Use of multi-factor authentication (MFA)
-
SPF, DKIM and DMARC configuration for email domains
-
Modern email security filters
-
A clearly defined procedure for reporting suspicious emails
Conclusion
Phishing emails are becoming harder and harder to spot. Today they often have professional design, correct language and a well imitated corporate visual identity, so you cannot rely on visual impression alone.
The best way to protect yourself is to maintain critical thinking. If an email urges you to act urgently, asks you to enter access credentials or seems unexpected, spend a few minutes checking it. This habit can protect both your personal data and your company’s information.