FREEBeginner · 8 minute read

Recognize a phishing attempt

Learn a repeatable way to assess a suspicious message without opening its links or trusting its urgency.

WHAT YOU WILL LEARN

Learning objectives

  • Separate a message’s claim from evidence
  • Verify a request through an independent channel
  • Report a suspicious message without spreading it
01

Start with the request

A logo, familiar display name or polished writing does not establish identity. Ask what the sender wants you to do: sign in, share a code, approve an app, pay an invoice or open a file. Unexpected changes to normal processes deserve extra attention, even when the message comes from a real colleague’s compromised account.

02

Verify without using the message

Open the service from a saved bookmark or an address you already know. For a payment or account change, call a known contact using your existing directory. Do not use the phone number, QR code or reply address supplied in the suspicious request. Verification should be a separate step, not a reply inside the same conversation.

03

Report and recover

Use your organisation’s reporting channel. Preserve the original message as instructed instead of forwarding a live attachment to coworkers. If you entered credentials or approved a prompt, report that fact promptly, use a trusted device to secure the account, and follow your response team’s advice. Fast, accurate reporting is more useful than blame.

APPLIED EXAMPLE

Put it in context

An invoice appears to come from a regular supplier but lists a new bank account. Pause the payment and call your existing supplier contact. The changed destination, rather than spelling mistakes, is the important signal.

Illustrative scenario for learning, not a claim about a verified customer incident.

Common mistakes

  • Assuming perfect grammar means a message is safe
  • Using a phone number from the suspicious message
  • Deleting evidence before reporting

Your practical checklist

Checklist ticks are temporary and are not recorded as account progress.

MINI RECAP

Slow down, verify the request independently, and report uncertainty. Phishing is a process problem as well as a message-recognition problem.

Put your understanding to the test.

Further authoritative reading ↗