I got some training at work on how to catch malicious emails. Here are some notes I took.
- Phishing emails are fake emails created to trick a reader into revealing security information.
- Can’t tell what emails criminals use
- They use catchy subject lines
- Using your name doesn’t mean they know you
- Only click on links you know are safe
- At the bottom of emails it should be easy to verify if a worker with that name works at that phone number
- Large organizations generally don’t use public emails services like Gmail and yahoo thus this can identify a possible trap
- Be aware of emails that offer money
- Look for types or misspellings as professional organizations don’t usually make these types of mistakes
- Be careful of emails that ask for acct numbers or want to verify info through a link.
- Be aware of links and see if the logic of the name matches
- Giving you a deadline to respond is a frequently used ploy
- Problems in email used to scare you
- Don’t fill out forms in emails
- When you look at a link, hover your mouse over the link to see if link is displaying the path correctly.
- Scammers use legal sounds statements to sound legit such as a law or case number.
- Always confirm web address and phone number through other means than the email sent to you.. Hover your mouse over your contact info to confirm accurate info
- Avoid attachments. Before opening one, confirm it’s from a known source first
- Confirm phones numbers as scammers have fake call centers
- Email trick people by offering to give a prize
- Malicious attachments often attached to fake emails.
Have something to add? Please do so in the comment section of this blog. Thanks.