Phishing is responsible for over 90% of data breaches (Verizon Data Breach Investigations Report). It is also the most preventable attack vector — knowing what to look for is your primary defence.
The 7 Red Flags of a Phishing Email
🚨 1. Urgency and Threats
“Your account will be closed in 24 hours!” Urgency bypasses critical thinking. Legitimate organisations rarely threaten immediate account closure via unsolicited email. Slow down — that is the attacker’s worst outcome.
📧 2. Suspicious Sender Address
The display name may say “PayPal Support” but the actual email address is [email protected]. Always click or tap the sender name to reveal the full address. A legitimate PayPal email comes from @paypal.com only.
🔗 3. Mismatched or Suspicious Links
Hover over links before clicking (on desktop). The URL that appears should exactly match the company’s real domain. Watch for: paypa1.com (number 1 not letter l), paypal.com.verify.ru, paypal-secure-login.com — all fake.
🔡 4. Generic Greetings
“Dear Customer” or “Dear User” instead of your name suggests a mass-blast phishing campaign. Your bank and most services know your name.
📎 5. Unexpected Attachments
Do not open attachments you were not expecting — especially .exe, .zip, .doc, .xls, or .pdf files from unknown senders. These are primary malware delivery methods.
✏️ 6. Poor Spelling and Grammar
Many phishing emails contain obvious errors. Some errors are deliberate — filtering out alert people and targeting only the most vulnerable recipients.
🔐 7. Requests for Credentials or Sensitive Data
No legitimate company will ask for your password, full Social Security number, or credit card number via email. Ever.
Beyond Email: Other Phishing Variants
- Smishing (SMS) — Fake texts from delivery companies, banks, or the government. “Your package is delayed — click here.”
- Vishing (Voice) — Phone calls from fake tech support, the IRS, or Social Security demanding payment or remote access.
- Spear Phishing — Targeted attacks using your personal details (from LinkedIn or social media) to craft convincing, personalised messages.
- Quishing (QR Codes) — Malicious QR codes in emails or public places that redirect to phishing pages.
If You Clicked a Phishing Link
- Do not enter any information on the page that opened.
- Close the tab immediately.
- Change your password for any account that may be affected.
- Enable MFA on the account if not already active.
- Run a malware scan with Malwarebytes (free version).
- Report it: forward the email to [email protected] and to your email provider.