Phishing emails are designed to look like they came from someone you trust — your bank, a colleague, Microsoft, even your own IT team — in order to get you to click a link, open an attachment, or hand over a password. They’re one of the most common ways businesses get compromised, and the good ones are getting harder to spot on sight.
A few signs worth checking before you click anything:
- Check the sender’s actual email address, not just the display name. “Microsoft Support” can be sent from almost any address — hover over or tap the name to see what’s really behind it.
- Be wary of urgency or threats — “your account will be suspended,” “invoice overdue,” “action required within 24 hours.” Real IT and finance teams rarely demand instant action by email.
- Hover over links before clicking to see where they actually go. If the link text says one thing but the address underneath is different or unfamiliar, don’t click it.
- Look out for slightly-off details — a wrong logo, unusual phrasing, a sender domain that’s almost right but not quite (e.g. “micros0ft.com”).
- Be cautious with unexpected attachments, especially .zip, .exe, or macro-enabled Office files, even if they appear to come from someone you know.
If you’re not sure about an email:
- Don’t click, reply, or forward it — contact the supposed sender directly through a separate, known channel to confirm.
- Report it to your IT team so they can check whether others received the same email.
- If you’ve already clicked a link or entered a password, change that password immediately and let IT know — the sooner it’s reported, the easier it is to contain.
This is a sensitive topic in the sense that it touches on security incidents, so if you ever find yourself dealing with a suspected compromise personally, it’s worth looping in your IT/security team straight away rather than troubleshooting alone.





