2. Spotting phishing emails
Tone, pressure and red flags
Even when the technical details check out, the content and context of a message can give an attack away. These are the behavioural red flags worth committing to memory.
Pressure to act now
Deadlines measured in minutes or hours, threats of account closure, fines, legal action, or missed deliveries. As covered in Section 1, manufactured urgency exists to stop you thinking. Real organisations give you reasonable time and real colleagues can wait for you to verify.
Unusual requests
Any of the following should make you pause, regardless of who appears to have sent the message:
- Requests for your password, MFA code, or other credentials. No legitimate organisation, including your own IT team, will ask you to reveal your password by email or phone
- Requests to buy gift cards or vouchers and send the codes. This is a classic scam with no legitimate business equivalent
- Requests to pay a new account, change bank details, or make an unscheduled payment
- Requests to keep the matter secret or bypass normal process "just this once"
- Requests to move the conversation to WhatsApp, personal email, or SMS
Generic greetings and wrong details
"Dear customer", "Dear user", or a greeting built from your email address rather than your name suggests a bulk campaign. So do references to accounts you do not hold or orders you never placed. That said, remember the flip side from Section 1: a correct name and accurate details prove nothing, because personalisation is cheap.
Too good to be true
Unexpected refunds, prizes, rebates from HMRC, or unclaimed payments waiting for you. The lure of gain works on people just as well as fear does.
It just feels off
Perhaps the sender's tone is slightly wrong for the person you know, the request does not fit their role, or the timing is odd, such as an urgent payment request at 5pm on a Friday. Trust that instinct. The feeling that something is off is often your pattern recognition working faster than your conscious reasoning, and the correct response is always the same: verify through a separate, known channel before acting.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting