Don't Feed The Phish

Fake, spam and suspicious emails are commonly referred to as Phishing email as the sender is trying to ‘hook and reel-in’ you in. Phishing emails are sent to persuade and deceive you into compromising your personal data or your organisation’s security by asking you to reveal passwords, company information, financial information, transfer funds, to visit fake websites, to click on malicious links, to open malicious files and the like.
What Should You Know ?
It used to be so easy to spot a suspicious or spam email, as it would contain spelling mistakes, be written in poor English, not be personally addressed to you, etc.
Suspicious and spam emails have become much more sophisticated and at first (and even second) glance, they may look genuine, as they will include logos, brand names, and slogans of legitimate companies.
Cyber attackers often create emails with attachments containing PDF files, word documents, excel spreadsheet and with embedded links containing malicious and harmful software. Opening the attachment or clicking on the embedded link, will likely result in malicious software being executed to run on your computers. From there on, the cyber attacker will be able to gain control of your computer and can spread the malicious software to other computers on our network.
What Should You Do ?
Simple tips you can use to spot phishing emails include:
- Hovering your cursor over the link, checking the sender's email address carefully;
- Looking out for emails which purport to have a sense of urgency or include threats, these are designed pressure you into acting quickly without checking, so that you do not realise it is a scam;
- Always be suspicious of unexpected emails or those from an unknown sender;
- Ask you to change your account information because there is a discrepancy with your account or you need to verify your account. This tactic is used to scare the end user into clicking on a bad link or going to a bad site and filling in their account information.
- Tell you your account has been hacked. This is to get a similar response as the one above. You are less likely to think an email that announces you have been hacked is a phishing email.
- Ask for a wire transfer or the details of a failed wire transfer for a compelling reason. The email usually claims the “transfer details” are in the attachment, which is likely to be malware! The scammer knows that you will likely be suspicious as you had not made a wire transfer, but they are hoping that your curiosity will make you open the attachment to check.
- Ask you to send you money as a donation, or to redeem a prize. They will either ask you to: give your personal information to send you money, open the attachment to receive the invoice, or click a link to claim your prize. Once you have opened the attachment, it is likely that malware will be downloaded onto your computer.
If you are suspicious of an email or the email is from an unknown or unexpected sender, you should never open the attachments or click on the embedded links. You should move any fake or suspicious emails to your ‘Spam’ or ‘Junk’ folder and report it to your IT Department.
A good practice, is for the IT Department to send a notification to colleagues to advise them, so that they do not fall for the bait, if it transpires that the email was in fact a fake or suspicious email.
If you accidently click on an attachment or embedded link, you should immediately turn off your computer and contact your IT Department or IT Services provider, so that they can run a health-check on your PC and take other appropriate actions.
Report to RCIPS, call 911