WHAT YOU WILL LEARN
Learning objectives
- Separate a message’s claim from evidence
- Verify a request through an independent channel
- Report a suspicious message without spreading it
Start with the request
A logo, familiar display name or polished writing does not establish identity. Ask what the sender wants you to do: sign in, share a code, approve an app, pay an invoice or open a file. Unexpected changes to normal processes deserve extra attention, even when the message comes from a real colleague’s compromised account.
Verify without using the message
Open the service from a saved bookmark or an address you already know. For a payment or account change, call a known contact using your existing directory. Do not use the phone number, QR code or reply address supplied in the suspicious request. Verification should be a separate step, not a reply inside the same conversation.
Report and recover
Use your organisation’s reporting channel. Preserve the original message as instructed instead of forwarding a live attachment to coworkers. If you entered credentials or approved a prompt, report that fact promptly, use a trusted device to secure the account, and follow your response team’s advice. Fast, accurate reporting is more useful than blame.
APPLIED EXAMPLE
Put it in context
An invoice appears to come from a regular supplier but lists a new bank account. Pause the payment and call your existing supplier contact. The changed destination, rather than spelling mistakes, is the important signal.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Assuming perfect grammar means a message is safe
- Using a phone number from the suspicious message
- Deleting evidence before reporting
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Slow down, verify the request independently, and report uncertainty. Phishing is a process problem as well as a message-recognition problem.