
What is Phishing?
Phishing has been around for almost as long as the internet and is an unnervingly common way for cyber criminals to obtain sensitive data from private individuals and organizations. The basic strategy is to send out an email (often a mass email) that contains a malicious attachment or hyperlink. The attachment is malware, and the hyperlink directs people to a website that is camouflaged as something legitimate and familiar. The cyber criminals hope that the individual receiving the email will either download the attachment (exposing their computer to the malware) or provide sensitive information on the fake website after clicking on the link.
Phishing attacks can be scary; here are a few ways you can protect yourself:
- Watch for Links and Attachments:
The primary purpose of a phishing attack is to get you to download an attachment, and/or click on a link. If an email includes an attachment and/or a link, use extreme caution— they may be malicious and include malware that could infect your computer.
If you notice a suspicious email that includes a link, hover your mouse over the text of the hyperlink to reveal the full URL. This should help you determine if it is a legitimate link or a link to something malicious.
- Look for Red Flags:
One of the easiest ways to identify a potential phishing email is to look for the "red flags" that are common among many of these attacks.
-
- Typos: Spellcheck is one feature that many cyber-criminals are unfamiliar with. Most (if not all) phishing attacks include typos such as poor grammar and structure, as well as a confusing text layout.
- Unfamiliar Email Address: A simple way to check if an email is coming from a legitimate source is to look at the email address of the sender. For example, if the email references your recent purchase on Amazon and the sender's address is
AmazonSupport1234@Gmail.com, this email obviously did not come from Amazon.
-
- Asking for Personal Information: A website, bank or organization should never ask you to confirm confidential personal or organizational information in an email. Always treat such requests with extreme suspicion, as the email is most likely phishing for your personal or company data.
- Contact the Sender:
Coordinated phishing campaigns can be difficult to detect. Often, these emails have less typos, they reference something you and/or your organization may be a part of, and they originate from what appears to be a reputable source. If you have any doubts about the message, it's recommended that you send an email directly to the person or their customer service department or contact the person or company directly by phone to verify that they sent the email.
