Hone

Lessons · IT support · spotting phishing

Phishing: the checks, in the order that catches it fastest

A phishing message is one that pretends to be from somebody you trust so that you click, sign in or pay. Check the real sender address, not the display name; hover the link and read where it really goes; look for urgency or a threat; look for a request for a password, a code or a payment. Any one of those is enough to stop and report.

Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.

In beta. This lesson was written for Hone and has not yet been checked by an experienced systems administrator. Practice material, not professional advice. What that means.

What it is for

The call that came in as 'my email is broken' was a user who had already typed their password into a page that looked like the sign-in screen, because the message said their mailbox was full and would be deleted at noon. The technician who asks 'what did the message say' before 'let me reset your password' turns a mailbox ticket into a security incident report in the first minute, which is where it has to be.

How to think about it

Do not click anything while you look. Read the sender's real address, character by character: the domain after the @ is the tell, and character by character is meant literally -- a single swapped letter is the whole attack. Hover the link and read the real destination; it is usually nothing like the text. Count the pressure: deadlines, threats, a boss who 'cannot talk right now'. Ask what it wants: a password, a code, a gift card, a bank change. Then report it to security with the message attached, and tell the user what to do if they already clicked.

Worked example

Display name 'IT Service Desk', real address: it-desk@secure-mail-verify.example
The name is ours. The domain is not. That alone is enough.
Link text 'Sign in to keep your mailbox', hover: a page on a host nobody has heard of
The words say one thing and the address says another. Never the same place.
'Your mailbox will be deleted at 12:00 today'
A deadline is the pressure that makes people skip the checks above.
Reported to security with the original message; user's password reset because it was typed in
Reported, with evidence. And the password is treated as stolen, because it was.

Your turn

Write what you hover over to see where a link really goes, before anything else.

Hover the  and read the real destination

The trap

Trusting the display name, and then trusting the domain. 'From: CEO' is text anybody can type, so the address after the @ is the better check -- but it is not a safe one. A domain that does not enforce DMARC can be forged outright, and the commoner attack needs no forgery at all: the attacker simply registers a domain that LOOKS right. micros0ft.com with a zero, paypa1.com with a one, or company-support.com owned by a stranger all pass every authentication check, because the sender really does own them. Read the domain character by character and ask whether it is the one you know, not whether it looks plausible.

Next in IT support

Every IT support lesson on one page

Practise spotting phishing on HoneA question on it now, a real problem where there is one, and it is remembered for review. Free, no email needed.