Weโve all seen the obvious phishing emails. Strange spelling, a suspicious email address and an urgent request to click a link immediately... Those are usually fairly easy to spot.
โ
The problem is that phishing emails are getting much better, which means knowing how to spot phishing emails in the workplace is more important than ever.
โ
Todayโs phishing emails can be well written, use convincing branding and appear to come from a company or person you recognise. AI is also helping criminals create more convincing messages, without many of the spelling and grammatical mistakes we traditionally associate with scams.
โ
So, if your advice to employees is still simply โlook out for spelling mistakesโ, it might be time for an update.
โ
Phishing is designed to persuade you to do something you normally wouldnโt. In a business, that might mean :
โ
๐ Clicking a link to a fake Microsoft 365 login page
๐ Opening an unexpected attachment
๐ Entering your email address and password
๐ Changing a supplierโs bank details
๐ Making an urgent payment
๐ Sharing confidential information
โ
The email itself is often only the starting point. The real objective could be gaining access to your Microsoft 365 account, stealing company information or, ultimately, getting hold of money.
โ
Rather than relying entirely on how an email looks, pay attention to what it is actually asking you to do.
โ
Be particularly careful if an email :
โ
๐ Asks you to log into Microsoft 365 or another business system
๐ Requests a payment or change of bank details
๐ Contains an unexpected attachment
๐ Pressures you to act immediately
๐ Asks you to bypass your normal company process
๐ Contains an unexpected QR code
๐ Comes from somebody you know, but the request seems unusual
โ
Urgency is a particular tactic... "Your password expires today", "Your mailbox is full", "A payment needs to be made immediately", "Your account is about to be suspended"... you get the idea. The aim is to get you to react before you stop and question the request.
โ
QR codes are increasingly being used in phishing emails. You might receive an email claiming your Microsoft 365 password is expiring, for example, followed by a QR code you need to scan to keep your account active. You scan it and arrive at what appears to be a Microsoft login page.
โ
Except it isnโt.
โ
The National Cyber Security Centre, NCSC, has warned about QR code phishing, sometimes called โquishingโ. A QR code can hide the destination you are being sent to, making it harder to judge whether a link is genuine.
โ
โ
Check.... and check again. A quick independent check can stop a convincing phishing attempt in its tracks.
โ
๐ If a supplier asks you to change their bank details, call them using a number you already know.
๐ If Microsoft apparently wants you to log in, donโt use the link in the email. Go to Microsoft 365 in the usual way.
๐ If a colleague sends an unusual request, call them or send them a separate Teams message.
โ
A couple of minutes spent checking is considerably easier than dealing with a compromised account.
โ
Tell your IT team and tell them quickly. People need to feel comfortable reporting mistakes. If someone clicks a suspicious link or enters their password into a fake website, waiting to see whether anything happens wastes valuable time.
Your IT team may need to :
โ
โ Reset the password
โ Sign the account out of existing sessions
โ Check recent login activity
โ Scan the device
โ Check whether emails or other company information have been accessed
โ
The sooner they know, the sooner they can act. Staff awareness is important, but your cyber security shouldnโt depend entirely on every employee spotting every phishing email.
โ
Good protection should include measures such as :
โ
โ Multi factor authentication
โ Email security and filtering
โ Appropriate Microsoft 365 security settings
โ Endpoint protection
โ Secure backups
โ Staff cyber security awareness
โ
Even experienced users can be caught out by a convincing phishing email. The NCSC recommends a layered approach rather than relying solely on users to identify suspicious messages. A simple rule for your team... If an email asks you to do something involving money, passwords, sensitive information or a change to your normal process, stop and check.
โ
You donโt need everyone in your business to become a cyber security expert. You do want them to feel confident questioning something that doesnโt seem quite right, and to know who to ask when theyโre unsure.
โ
โ
From Microsoft 365 security and email protection to backups, cyber security and managed IT support, the Espi IT team can help you understand what protection you currently have in place and where there may be gaps. And if youโve received a suspicious email and youโre really not sure whether to click it... donโt! Send it over to us and let us take a look first ๐
โ
๐ง support@espi.net
๐ 01954 213999
โ
โ