Phishing is a type of cyberattack that uses email, text messages, phone calls, websites, or other forms of communication to trick individuals into revealing sensitive information, clicking malicious links, opening infected attachments, sending money, or granting unauthorized access to company systems. Attackers often create a sense of urgency, fear, curiosity, or trust to convince users to act without verifying the request. While phishing attempts can be sophisticated and highly targeted, many share common warning signs such as unexpected requests, unusual sender information, suspicious links, and pressure to act immediately. The best defense is to slow down, verify requests through trusted channels, and report anything suspicious to IT or Security.
Examples of Common Phishing:
Email Phishing: An email claiming your Microsoft 365 password is about to expire and asking you to click a link to reset it.
Spear Phishing: An email appearing to come from your manager asking you to review an attached document or approve a request.
Whaling: A message impersonating a company executive requesting an urgent wire transfer or sensitive business information.
Smishing (Text Message Phishing): A text claiming there is a problem with a package delivery and directing you to click a link.
Vishing (Voice Phishing): A caller pretending to be IT Support and requesting your password or MFA code.
Business Email Compromise (BEC): An email from a seemingly trusted executive or vendor requesting gift cards, payment information changes, or urgent financial transactions.
A Real-World Example of Phishing via a Website:
An individual was attempting to access their AdviceWorks account. When they typed in the URL, it was missing a single period causing them to be taken to an exact replica of the actual AW site. Once there, they were prompted to run a security check which ultimately led to a virus being downloaded on their device and access to their AW account being compromised.
Best Practices:
- Verify unexpected requests through a known phone number or trusted contact.
- Check sender email addresses carefully.
- Hover over links before clicking.
- Double check URLs before accessing websites.
- Never share passwords or MFA codes.
- Report suspicious emails, texts, or phone calls to IT.
- When in doubt, stop and ask before acting.
Remember: Legitimate organizations, including your IT department, should never ask for your password. You should also always independently verify any request involving money, credentials, or sensitive information before responding.