How to spot a fake message before you click
Most attacks on companies do not begin with breaking into a system but with a message that persuades someone to click. Seven signs and one rule worth introducing.

It is easier for an attacker to persuade an employee to open the door than to break into a system. That is why most attacks begin with an ordinary message: an email, a text or a message in an app that looks as if it comes from a bank, a courier, a supplier or the director.
Seven signs of a fake message
- Urgency. "The account will be blocked today", "the payment must go through by noon". The pressure is there so you do not have time to think.
- A sender address that is not quite right. One extra letter, a different domain or a private address instead of an official one.
- A link that leads elsewhere. Hover over the link and read the actual address before clicking.
- An unexpected attachment. An invoice you did not order, a notice about a parcel you are not expecting.
- A request for a password or code. Your bank, supplier and IT never ask for a password by message.
- A change of payment account. "From today, pay to a new IBAN" is one of the most expensive forms of fraud.
- An unusual tone. A director who usually writes briefly suddenly writes at length and formally, or the other way round.
One rule worth introducing
Every request involving money, passwords or a change of payment details is verified through a second channel. If the request came by email, call the person on a number you already have, not the one in the message. This rule stops a large share of fraud, with no technology at all.
What if someone has already clicked
- Tell the person responsible for IT immediately. Speed matters more than embarrassment.
- Change the password of that account and of every account that shares it.
- If card or banking details were entered, call the bank.
- Do not delete the message. It will be needed to check who else received it.
The role of management
People report mistakes only if they know they will not be punished. A company where a click on a fake message is reported within five minutes fares much better than one where it is kept quiet. Technical measures such as multi-factor sign-in and mail filtering help, but they do not replace that habit.
We check how exposed your company is to attacks like these as part of our cybersecurity services.




