Phishing (pronounced: fishing) is an attack that attempts to steal your money, or your identity, by getting you to reveal personal information, such as credit card numbers, bank information or passwords, on websites that pretend to be legitimate. Cybercriminals typically pretend to be reputable companies, friends, or acquaintances in a fake message, which contains a link to a phishing website.
Learn to spot phishing
Phishing is a popular form of cybercrime because of how effective it is. Cybercriminals have been successful using emails, text messages, and direct messages on social media or in video games, to get people to respond with their personal information. The best defense is awareness and knowing what to look for.
Here are some ways to recognize a phishing email:
-
Urgent call to action or threats - Be suspicious of emails and Teams messages that claim you must click, call, or open an attachment immediately. Often, they'll claim you have to act now to claim a reward or avoid a penalty. Creating a false sense of urgency is a common trick of phishing attacks and scams. They do that so that you won't think about it too much or consult with a trusted advisor who may warn you.
Tip: Whenever you see a message calling for immediate action take a moment, pause, and look carefully at the message. Are you sure it's real? Slow down and be safe.
-
Pay attention to banners and warnings
- It is common for cybercriminals to claim to be internal/RGU staff. Their name or email address may even match somebody you know, or somebody high-profile within the organisation. The below banner is only shown when the email originates outwith RGU, so may be a sign of phishing where they claim to be internal.
- Be wary of first-time senders marked by the below banner. Again, it is common for cybercriminals to claim to be someone you are familiar with, which would make it unlikely to receive the below indicator.
Tip: Slow down and take extra care at these times. When you get an email or a Teams message from somebody you don't recognize, or that Outlook or Teams identifies as a new sender, take a moment to examine it extra carefully using some of the measures below.
Spelling and bad grammar - Professional companies and organizations usually have an editorial and writing staff to make sure customers get high-quality, professional content. If an email message has obvious spelling or grammatical errors, it might be a scam. These errors are sometimes the result of awkward translation from a foreign language, and sometimes they're deliberate in an attempt to evade filters that try to block these attacks.
Generic greetings - An organization that works with you should know your name and these days it's easy to personalize an email. If the email starts with a generic "Dear sir or madam" that's a warning sign that it might not really be your bank or shopping site.
Mismatched email domains - If the email claims to be from a reputable source, like RGU, Microsoft or your bank, but the email is being sent from another email domain like Gmail.com, or microsoftsupport.ru it's probably a scam. Also be watchful for very subtle misspellings of the legitimate domain name. Like micros0ft.com where the second "o" has been replaced by a 0, or rgua.c.uk, where the 'a' has been moved in front of the '.ac.uk'. These are common tricks of scammers.
-
Suspicious links or unexpected attachments - If you suspect that an email message, or a message in Teams is a scam, don't open any links or attachments that you see. Instead, hover your mouse over, but don't click the link. Look at the address that pops up when you hover over the link. Ask yourself if that address matches the link that was typed in the message. In the following example, resting the mouse over the link reveals the real web address in the box with the yellow background. The string of numbers looks nothing like the company's web address.
Tip: On Android long-press the link to get a properties page that will reveal the true destination of the link. On iOS do what Apple calls a "Light, long-press".
-
Shared documents can be a trap - Don't open or log in to suspicious shared documents. Before entering your password to open a shared document, do a quick check to be sure it is safe. Some emails directing you to shared documents that require login are simply trying to steal your password and this has become increasingly common.
Stop and think. Are you expecting the document and does it make sense to receive this in the context of your role? It is highly unusual to receive a shared document without prior discussion or email.
Below is a real life example of malicious file sharing.
Beware of flattery. Other universities have for example, received personalised emails complimenting their research and asking them to look at a shared document related to it. If it looks suspicious, don't log in.
Cybercriminals can also tempt you to visit fake websites with other methods, such as text messages, phone calls, even messages on Microsoft Teams or other chat platforms. If you're feeling threatened or being pressured, contact the IT Service Desk, who will be happy to provide advice. Sophisticated cybercriminals set up call centers to automatically dial or text numbers for potential targets. These messages will often include prompts to get you to enter a PIN number or some other type of personal information.