Lessons · IT support · spotting phishing
Phishing: the checks, in the order that catches it fastest
A phishing message is one that pretends to be from somebody you trust so that you click, sign in or pay. Check the real sender address, not the display name; hover the link and read where it really goes; look for urgency or a threat; look for a request for a password, a code or a payment. Any one of those is enough to stop and report.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
In beta. This lesson was written for Hone and has not yet been checked by an experienced systems administrator. Practice material, not professional advice. What that means.
What it is for
The call that came in as 'my email is broken' was a user who had already typed their password into a page that looked like the sign-in screen, because the message said their mailbox was full and would be deleted at noon. The technician who asks 'what did the message say' before 'let me reset your password' turns a mailbox ticket into a security incident report in the first minute, which is where it has to be.
How to think about it
Do not click anything while you look. Read the sender's real address, character by character: the domain after the @ is the tell, and character by character is meant literally -- a single swapped letter is the whole attack. Hover the link and read the real destination; it is usually nothing like the text. Count the pressure: deadlines, threats, a boss who 'cannot talk right now'. Ask what it wants: a password, a code, a gift card, a bank change. Then report it to security with the message attached, and tell the user what to do if they already clicked.
Worked example
Display name 'IT Service Desk', real address: it-desk@secure-mail-verify.exampleThe name is ours. The domain is not. That alone is enough.
Link text 'Sign in to keep your mailbox', hover: a page on a host nobody has heard ofThe words say one thing and the address says another. Never the same place.
'Your mailbox will be deleted at 12:00 today'A deadline is the pressure that makes people skip the checks above.
Reported to security with the original message; user's password reset because it was typed inReported, with evidence. And the password is treated as stolen, because it was.
Your turn
Write what you hover over to see where a link really goes, before anything else.
Hover the and read the real destination
Solve one, graded on the server
The trap
Trusting the display name, and then trusting the domain. 'From: CEO' is text anybody can type, so the address after the @ is the better check -- but it is not a safe one. A domain that does not enforce DMARC can be forged outright, and the commoner attack needs no forgery at all: the attacker simply registers a domain that LOOKS right. micros0ft.com with a zero, paypa1.com with a one, or company-support.com owned by a stranger all pass every authentication check, because the sender really does own them. Read the domain character by character and ask whether it is the one you know, not whether it looks plausible.