info@poslovnaspajalica.hr

How to spot a fake message before you click

Security

Most attacks on companies do not begin with breaking into a system but with a message that persuades someone to click. Seven signs and one rule worth introducing.

How to spot a fake message before you click

It is easier for an attacker to persuade an employee to open the door than to break into a system. That is why most attacks begin with an ordinary message: an email, a text or a message in an app that looks as if it comes from a bank, a courier, a supplier or the director.

Seven signs of a fake message

  • Urgency. "The account will be blocked today", "the payment must go through by noon". The pressure is there so you do not have time to think.
  • A sender address that is not quite right. One extra letter, a different domain or a private address instead of an official one.
  • A link that leads elsewhere. Hover over the link and read the actual address before clicking.
  • An unexpected attachment. An invoice you did not order, a notice about a parcel you are not expecting.
  • A request for a password or code. Your bank, supplier and IT never ask for a password by message.
  • A change of payment account. "From today, pay to a new IBAN" is one of the most expensive forms of fraud.
  • An unusual tone. A director who usually writes briefly suddenly writes at length and formally, or the other way round.

One rule worth introducing

Every request involving money, passwords or a change of payment details is verified through a second channel. If the request came by email, call the person on a number you already have, not the one in the message. This rule stops a large share of fraud, with no technology at all.

What if someone has already clicked

  • Tell the person responsible for IT immediately. Speed matters more than embarrassment.
  • Change the password of that account and of every account that shares it.
  • If card or banking details were entered, call the bank.
  • Do not delete the message. It will be needed to check who else received it.

The role of management

People report mistakes only if they know they will not be punished. A company where a click on a fake message is reported within five minutes fares much better than one where it is kept quiet. Technical measures such as multi-factor sign-in and mail filtering help, but they do not replace that habit.

We check how exposed your company is to attacks like these as part of our cybersecurity services.