How to Spot a Phishing Email: Tips to Detect a Fake Email
Anyone can be a victim of phishing, these tips will help you recognise whether an email is accurate
Email is an effective gateway for hackers and cybercriminals, with especially for social engineering attacks such as phishing.
A 2017 study from Keepnet Labs showed that a staggering 48.2 percent of phishing messages were opened by the target across all campaigns, up from 30 percent in 2016.
Security issues like malware and ransomware are frequently delivered via email - and so it takes just one unrecognised successful breach to affect the safety of an organisation.
According to Keepnet Labs, phishing attacks tend to be successful as they target basic human natural responses. This is due to the fact that the emails are disguised to look like those sent by popular brands & organisations, however there are ways to spot when something isn’t right.
Here are some tips for detecting a phishing email.
1. Incorrect spelling & grammar
The structure of an email is often the first way to spot whether it is a phishing email or not. The writing style is likely to appear different to how it is usually written from the original sender, even in the slightest way.
Organisations and brand marketers tend to take their communication very seriously, and often have emails proof-read before being sent out so it is highly unlikely the email came from the original source if an email is packed with spelling and grammar mistakes.
2. Strange URLs
A phishing email is likely to include some links to direct you to a site asking for login details, where would-be attackers can then steal account details.
This is often overlooked as the URLs appear to be valid or even similar to the link you are used to logging into but if checking emails from a PC, you can hover your mouse over the link where you can see the actual hyperlink – if it looks unfamiliar, then it's not safe to click.
The domain name may also be different to the organisation or brand it claims to be from, so check the sender address and look back at how domain addresses usually appear in previous, legitimate emails you have received from that organisation.
3. Personal information
If the email begins with ‘Dear Customer’ as opposed to being addressed by your name, it is unlikely that it came from the organisation itself. If it is an organisation that has your personal details on file, then they are more likely to address the email to you.
Also, a bank would never ask for your personal information via email. It would also never ask you to submit your account details in such way. This is a clear way to spot a phishing email.
4. Requests urgent action
Emails that claim "urgent action" is required are very frequent phishing scams as the fraudster is likely to be tricking the user to click links to access personal data.
If you receive an email stating this, with a threat that your account may be closed or blocked, for instance, it is best to give the organisation a direct call before taking any action. Usually, if it is coming from them they will either write a letter or call you themselves.
5. Alarming content
Often, phishing emails are written in an alarming manner to trick the person into clicking links out of excitement or fear.
They are likely to say you have won a prize or some sort of discount, sometimes they might even say there’s been fraud on your account – all of which can cause panicked responses from people. Instead of clicking the link, just go the company’s website and log in directly, any of the information (if accurate) is likely to be on there.
It is better to confirm from the supposed sender before taking actions which require sharing your personal details.
6. What to do if you’ve been a victim?
As phishing emails are often very difficult to spot, it is likely that many people and organisations have been a victim, perhaps without even realising it.
However, there are actions that can be taken to avoid further fraud. If you know you have been a victim, or suspect you might be from an email you have received then it is a good idea to report it as a crime.
This type of issue can be reported as suspicious communications via an online form on the Action Fraudwebsite. There is also more information on what to do in the case of phishing scams on the government website.
- Information Security Risk Consultant, HMG, Public sector
A Public Sector Information Security Risk Consultant is needed for a long term project in the Yorkshire area. This is a Security consultancy role so travel to other client site locations across the country will be expected. The Public Sector Information Security Risk Consultant MUST have current security clearance and ideally have a breath of information and technology security experience. Broad knowledge across IT transformation, Cloud is also key. Public Sector Information Security Risk Consultant should be versed in working within the public sector HMG environments and be experienced in conducting security risk assessments on sizable IT systems. Broad experience across GRC, ISO27001, NIST is key. Career progression, personal development and excellent training provided. All details kept in the strictest of confidence Salary: £55,000 Location: Yorkshire Ref: GM7720 (Cyber Security Jobs, Information Security Jobs, IT Security Jobs, Cyber Security Jobs in Yorkshire)
- Greenfield opportunity SOC / Threat Hunting Services Lead
- £85,000+ Base
Exclusive Greenfield opportunity to DCL Search & Selection. We are looking for an experienced SOC / Threat Hunting Services Lead to build a NEW Security Operation Centre (SOC) / Threat hunting service within an existing security consultancy. This is a brand new service offering for the client. The successful SOC / Threat Hunting Services Lead must, therefore, have previous experience in building a SOC / Threat hunting (IR) service from the beginning. Everything including, but not limited to; selection of the systems, platforms, kitting out the physical office space. Customisation, setting the policies, playbooks, go to market collateral, recruitment (through DCL obviously) establish processes, management of the team, service delivery, refinement, development etc. Essentially the end to end creation of the capability and then the day to day management and expansion of the service. An in-depth technical background is essential, experience across SOC SIEM/ Threat Hunting (IR) tools, processes, techniques, operational etc The goal is to create, spin up and deliver a SOC/threat hunting (IR) offering to clients ASAP in 2020. Investment and board sign off approved. Apply today for more information or contact me directly on Chris.Holt@dclsearch.com or 07884666351. Candidates must be UK based and commutable to Bracknell. Sponsorship can not be provided to Non-EU Candidates. Ref CH7713 £85,000+ Base
- IT Managed Services Account Director
- Up to £80,000 + Double OTE
IT Managed Services Account Director We are currently working with a growing multi managed service provider who specialises in Cloud & Connectivity services who are currently looking for an IT Managed Services Account Director in London. The IT Managed Services Account Director will be responsible for selling (Increase revenue, develop pipeline etc.) into our client’s current enterprise customers selling public cloud solutions. The IT Managed Services Account Director should have Current experience selling public cloud solutions (preferably Microsoft Azure) into enterprise customers. Currently working for an IT managed services business Commutable to London, Home working is available (Non-EU candidates are not able to be sponsored). Consistent tenure in current and previous positions. Ref BD7703 Salary: Up to £80,000 + Double OTE (Cloud Jobs, Cloud Computing Jobs, Cloud Sales Jobs, Azure Jobs)
- Service Delivery Lead (Data Centre)
- Up to £60,000 Base
A State of the Art Data Centre business are looking for a Service Delivery Lead-in Wiltshire. The Service Delivery Lead will be responsible for maintaining and improving current services to our client's customers. The Service Delivery Lead will also be responsible for a service desk team (reviews, hiring, training etc.) Other responsibilities include: Acting as a senior point of escalation for any customer incidents making sure these are raised quickly and efficiently Root cause analysis Maintain and improve ITIL disciplines Experience required ITIL v3 Certified Current experience within a Data Centre / Data Center Environment Current experience within a Senior Service Desk role. Candidates must be UK based. Sponsorship is not available for Non-EU candidates. Ref BD7701 Up to £60,000 Base (Data Centre Jobs, Data Center Jobs, Service Delivery Jobs)