Body

Overview
Phishing is a type of social engineering in which cybercriminals attempt to trick you into providing sensitive information, clicking a malicious link, or opening a harmful attachment.
Phishing messages are often designed to look like they come from a trusted person or organization, such as a bank, technology company, coworker, or IT administrator.
Learning to recognize common warning signs can help you avoid phishing attempts and protect your accounts, personal information, and devices.
Key Information
- Phishing messages may appear to come from someone you know or an organization you trust.
- Cybercriminals often use urgency, fear, curiosity, or tempting offers to encourage you to act quickly.
- Links may lead to a website that looks legitimate but is designed to steal your information.
- Unexpected attachments can contain malicious software.
- An email that looks unusual or out of character should be treated with caution.
- When in doubt, don't click the link or open the attachment. Verify the request through a trusted method instead.
⚠️ Important: Don't let an urgent or threatening message pressure you into clicking a link, opening an attachment, or providing personal information. When in doubt, stop and verify the request before taking action.
What is Phishing
Phishing is an attempt to obtain sensitive information—such as usernames, passwords, financial information, or credit card numbers—by pretending to be a trustworthy person or organization.
Phishing can occur through:
- Email
- Text messages
- Phone calls
- Websites
- Other forms of electronic communication
Cybercriminals commonly impersonate organizations or services that people recognize, such as banks, social media websites, online retailers, or technology providers.
Common Phishing Tactics
Too Good to Be True
Phishing messages may promise something valuable to get your attention.
Examples include:
- You've won a prize.
- You've received a gift card.
- You've been selected for a special offer.
- You are entitled to a refund or payment.
If an offer seems too good to be true, take a moment to verify it before clicking anything.
A Sense of Urgency
Cybercriminals often try to make you act before you have time to think.
Examples include:
- "Your account will be suspended today."
- "Immediate action required."
- "You have only 10 minutes to respond."
- "Your payment information must be updated."
💡 Tip: Don't allow an urgent message to rush you into making a decision. If you think the message may be legitimate, go directly to the organization's website or contact them using a trusted phone number.
Suspicious Links
A link may not lead where you expect it to.
Before clicking a link, hover your mouse over it to view the destination address. Look for:
- A domain that doesn't match the organization.
- Misspelled website names.
- Unusual characters or addresses.
- Links that don't match the context of the message.
For example, a fraudulent website might use a domain that looks similar to a legitimate one but contains a subtle spelling difference.
💡 Tip: If you're unsure about a link, don't click it. Navigate directly to the organization's website by typing the address into your browser or using a trusted bookmark.
Unexpected Attachments
Be cautious with attachments you weren't expecting, especially when they come from someone you don't normally exchange files with.
Ask yourself:
- Was I expecting this file?
- Does the attachment make sense in the context of the message?
- Does the sender normally send me this type of file?
If something doesn't seem right, don't open the attachment until you've verified that it is legitimate.
Unusual Sender
A phishing message may come from:
- Someone you don't recognize.
- A familiar person whose message seems unusual or out of character.
- An organization you don't normally communicate with.
- A suspicious or unfamiliar domain.
Even if you recognize the sender, consider whether the message is consistent with how that person normally communicates.
Red Flags to Look For
When reviewing a suspicious message, consider the following:
Sender
- Do you recognize the sender?
- Is the sender's email address what you expected?
- Does the domain look legitimate?
- Is the message unusual for this person or organization?
- Have you communicated with this sender before?
Recipients
- Were you unexpectedly copied on the message?
- Is the message addressed to an unusual group of people?
- Does the list of recipients make sense?
Subject
- Does the subject match the content of the message?
- Is it a reply to something you never sent?
- Does the subject create an unusual sense of urgency?
Links
- Does the link actually go to the website you expected?
- Is the website address misspelled?
- Does the link use an unfamiliar domain?
Attachments
- Were you expecting the attachment?
- Does the attachment make sense for the message?
- Does the sender normally send you this type of file?
Message Content
- Is the message asking you to provide sensitive information?
- Is it asking you to click a link or open an attachment?
- Is it threatening a negative consequence if you don't act?
- Is it offering something valuable in exchange for taking action?
- Does the message contain unusual grammar, spelling, or formatting?
- Does something about the message simply feel wrong?
📝 Note: Phishing messages are becoming increasingly convincing. Good spelling, professional-looking graphics, or a familiar logo do not necessarily mean a message is legitimate.
How to Protect Yourself
You can reduce your risk of falling for a phishing attempt by developing a few simple habits:
- Stop and think before clicking unexpected links or attachments.
- Hover over links before clicking them.
- Verify unexpected requests for sensitive information.
- Navigate directly to websites instead of using links in suspicious messages.
- Use unique passwords for your accounts.
- Use multi-factor authentication whenever it is available.
- Keep your devices and software updated.
- Be cautious even when a message appears to come from someone you know.
When in Doubt, Verify
If you're unsure whether a message is legitimate, don't interact with it until you can verify the request.
For example, if you receive an unexpected message from a coworker asking you to purchase gift cards, contact the coworker using a known phone number or another trusted communication method.
⭐ Best Practice: When verifying a suspicious request, use contact information you already trust. Don't use the phone number, email address, or link provided in the suspicious message.
What Should I Do If I Receive a Phishing Message?
If you receive a message that you believe may be phishing:
- Don't click links in the message.
- Don't open unexpected attachments.
- Don't provide passwords, financial information, or other sensitive information.
- If possible, report the message using Northwood Tech's designated phishing reporting process.
- Delete the message after it has been reported or verified as malicious.
If you accidentally clicked a link, opened an attachment, or provided your Northwood Tech credentials, contact the IT Service Desk as soon as possible.
Need Additional Assistance?
If you're unsure whether an email or message is a phishing attempt, contact the IT Service Desk for assistance.
When contacting the Service Desk, provide the suspicious message or a screenshot if possible. Do not forward suspicious messages containing sensitive personal information.
Source: https://www.knowbe4.com/hubfs/Social-Engineering-Red-Flags.pdf