Security · Tech Notes
Recognizing and avoiding phishing scams
Phishing scams trick you into clicking links, opening attachments, or sending money. Here is how to recognize them, avoid them, and reduce the risk.
August 28, 2023
Phishing is an online scam that tries to extract information, credentials, or money from you, usually by impersonating someone you trust. Here is how to spot these attempts, avoid falling for them, and cut down on how often they reach you.
What is phishing?
Phishing emails and text messages try to trick you into clicking a link, opening an attachment, or sending proprietary information. Often the return address is the name of a person or company you recognize, which leads you to believe the message is legitimate. But there are many ways to recognize phishing and avoid falling for scams.
If you have any question at all that an email might not be legitimate, forward it to support@macktez.com. If you do this, please send a second email referencing the first one, because sometimes the original forward gets caught in our spam filter. If you accidentally click on an email you think was not legitimate, please let us know, even if you didn't enter any information.
Tips for security
- Exercise your Spidey sense. If a request from someone you know is unexpected or unusual, or if the language in the email is not typical for the person you think sent it, be alert and extra careful. Verify the message with the sender some other way (call, text, or chat).
- Remember that return addresses are easily spoofed. Putting someone else's return address on an email is as easy as writing someone else's return address in the top left corner of an envelope sent through the regular mail.
- Be aware at all times of the links you click in an email. You can hover your mouse over a link to reveal the actual target — if the target is not what you expect, don't click.
- Be particularly wary of any email that links to a website asking you to enter credentials.
- You are most vulnerable when you are doing something new — starting a new job, using a new communication tool, working on a new project with new vendors. Slow down in these situations and stay extra vigilant until you have established a routine.
- If you receive an email asking to change a method of payment (for example, a new wire transfer number), verify the change in person or by phone. Never authorize any electronic payments until you have confirmed the request with the vendor directly.
- Protect your computer by installing security software and keeping it up to date. That way, even if you download malware accidentally, your computer will be protected.
- Set your phones and computers to install updates automatically so you always have the most recent security fixes.
- Do not reuse passwords. If one of your passwords is compromised through a phishing scheme, the attacker will almost certainly try it on any number of other services. (Use a password manager like 1Password to keep track of your passwords.)
- Use strong passwords, at least 12 characters long. Length matters more than complexity, so use phrases if you have trouble remembering passwords.
Ilikebeantacos4lunchis much more secure thanbuRR1t0. (Again, a password manager means you don't even need to remember your long passwords.) - Enable multi-factor authentication (MFA) on every critical service, starting with your email account. MFA means that even if someone knows your password, they still can't log into your account.
- If you suspect a password has been compromised, change it immediately.
Have I been hacked?
Receiving a phishing email does not mean you have been hacked. Even when a suspicious email seems to reveal information you think is private (a message from your direct supervisor, or a link to a service you actually use), it's usually because that information is not in fact private — your company's org chart, for example, can be easily gleaned from your public website or LinkedIn.
If someone else reports that they received a phishing email from you, that also may not indicate a true vulnerability. Adding a fake "from" address to an email is easy to do, and does not necessarily mean the email actually came from your account.
That said, hacks do occur, especially if you use the same password for multiple services and have not enabled MFA. If you suspect your email account has been compromised, change your password right away and let us know. There are clues we can look for within your email account to assess the extent of the hack and take remedial action.
What's really going on?
Phishing is not a particularly sophisticated form of hacking. It doesn't take a lot of computing power or special knowledge of code. It's a modern form of social engineering, where a con artist takes advantage of your trust or inattention.
Phishing can be very broad — someone sends a thousand generic requests from "Dropbox" via email and hopes for a small return. Or it can be targeted (sometimes called "spear phishing") — someone looks up information about your organization, spoofs specific email addresses, and makes specific requests they think will sound more legitimate. In all cases, attackers are hoping to trip you up, then use the information they get to expand their attempts.
What can you do?
There's no way to stop phishing entirely. But there are ways to reduce the practice, minimize the risks, and assist those who are also trying to block phishing on your behalf.
- Enroll in Macktez Domain Management. By configuring, enabling, and monitoring industry-standard email security tools (SPF, DKIM, and DMARC), we can help ensure that outgoing email using your organization's domain is not spoofed, giving recipients greater confidence that messages from you are authentic.
- Sign up for simulated phishing campaigns from Macktez. We can send harmless email to your staff every quarter to train them to recognize phishing.
- Click the "spam" button in your inbox to train your email service to recognize illegitimate emails. Large providers like Google and Microsoft aggregate user feedback to improve their filters so these emails never reach your inbox.