How to Recognize a Phishing Email
Phishing is an attempt to trick a person into revealing passwords, payment information or other sensitive details. The message may look like it came from a bank, employer, supplier, government office or familiar online service.
Warning signs to check
1. The message creates panic or urgency
Be cautious when an email says your account will be closed immediately, a payment must be made today, or urgent action is required without giving you time to verify the request.
2. The sender address does not match
Read the full email address, not only the display name. Small spelling changes, extra characters or an unrelated domain can indicate impersonation.
3. The message asks for passwords or codes
Legitimate support staff should not ask you to send your password, PIN or one-time verification code by email or messaging application.
4. Links lead somewhere unexpected
On a computer, place the pointer over a link without clicking it. Check whether the destination matches the organization. On a phone, avoid pressing unknown links and verify through the official app or website instead.
5. Attachments were not expected
Unexpected invoices, delivery notices or documents may contain harmful files. Confirm with the sender using a known phone number before opening them.
6. The request is unusual
A message asking an employee to purchase vouchers, transfer money or change supplier bank details should be independently confirmed.
What to do when an email looks suspicious
- Do not click links, open attachments or reply.
- Contact the organization using its official website or a known number.
- Report the message to your supervisor or IT support contact.
- Delete it after reporting.
- If you already entered a password, change it immediately from a trusted device and enable multi-factor authentication.
Simple protection for PNG SMEs
- Train staff to pause and verify unusual requests.
- Use different strong passwords for important accounts.
- Enable multi-factor authentication where available.
- Keep devices and browsers updated.
- Maintain regular backups that are not always connected to the computer.
Concerned about suspicious activity or malware?
Sky DevOps can assist with security checks, malware support and practical cybersecurity guidance.
Explore Security ServicesContact Sky DevOpsHow to Recognize a Phishing Email
Phishing is an attempt to trick a person into revealing passwords, payment information or other sensitive details. The message may look like it came from a bank, employer, supplier, government office or familiar online service.
Warning signs to check
1. The message creates panic or urgency
Be cautious when an email says your account will be closed immediately, a payment must be made today, or urgent action is required without giving you time to verify the request.
2. The sender address does not match
Read the full email address, not only the display name. Small spelling changes, extra characters or an unrelated domain can indicate impersonation.
3. The message asks for passwords or codes
Legitimate support staff should not ask you to send your password, PIN or one-time verification code by email or messaging application.
4. Links lead somewhere unexpected
On a computer, place the pointer over a link without clicking it. Check whether the destination matches the organization. On a phone, avoid pressing unknown links and verify through the official app or website instead.
5. Attachments were not expected
Unexpected invoices, delivery notices or documents may contain harmful files. Confirm with the sender using a known phone number before opening them.
6. The request is unusual
A message asking an employee to purchase vouchers, transfer money or change supplier bank details should be independently confirmed.
What to do when an email looks suspicious
- Do not click links, open attachments or reply.
- Contact the organization using its official website or a known number.
- Report the message to your supervisor or IT support contact.
- Delete it after reporting.
- If you already entered a password, change it immediately from a trusted device and enable multi-factor authentication.
Simple protection for PNG SMEs
- Train staff to pause and verify unusual requests.
- Use different strong passwords for important accounts.
- Enable multi-factor authentication where available.
- Keep devices and browsers updated.
- Maintain regular backups that are not always connected to the computer.
Concerned about suspicious activity or malware?
Sky DevOps can assist with security checks, malware support and practical cybersecurity guidance.
Explore Security ServicesContact Sky DevOps