The short answer: phishing is a message pretending to come from someone you trust (Interweb, your bank, a supplier, your boss) to get you to click a link, open an attachment or hand over a password. The signs are almost always the same: urgency, a link that does not go where it says, and a request the genuine sender never makes. If you clicked, what matters is what you did next.
The signs that keep repeating
| Sign |
What usually lies behind it |
| Urgency and a threat |
“Your account will be suspended today.” The hurry is there so you click before you think. |
| A disguised link |
The text says one thing, the real address is another. Hover over it without clicking (on a phone, press and hold) and read the end of the address, after the first “/”. |
| Asks for a password or a code |
No serious service asks for your password or a verification code by message. |
| An unexpected attachment |
.zip and .exe files, or documents asking you to “enable macros”, are the classic carrier of malicious programs. |
| A sender that does not add up |
The display name says “Bank X”, the address is a string of letters. The name can be anything; the address is harder to fake. |
| Changes payment details |
“We have changed account, pay into this one.” The costliest trick of all. Always confirm through another channel. |
For our own messages, telling a genuine one from a fake has an article of its own, with the addresses we write from and the technical checks that prove it: how to tell whether an e-mail really came from us.
Clicked or opened? Do this, in this order
| 1 |
You typed nothing, you only opened the page. Close the tab. Merely opening a page is usually harmless, but do not click again or download anything it offered.
|
|
| 2 |
You typed a password. Go to that service from another device, typing the address yourself, and change the password now. Then change it anywhere else you reused it (see a strong password and a password manager).
|
|
| 3 |
You typed a verification code. Treat the account as taken. End all open sessions, change the password, and check that no e-mail forwarding rules or unknown devices were added.
|
|
| 4 |
You downloaded or opened an attachment. Take the device off the internet, run an antivirus scan, and do not use that computer to sign in to important accounts until it is clean. If you have lost control of the site, read how to tell if your site has been compromised.
|
|
| 5 |
You gave card details. Contact your bank at once and have the card blocked.
|
|
|
Changing the password from the same computer or phone that opened the attachment is pointless if that device has a program copying what you type. Make the change from a clean device.
|
|
If the message claimed to be from Interweb, do not reply and do not click: forward it to us through the contact page and, if you wish, report it as described in reporting abuse. With two-step verification switched on (see how to enable it), a stolen password alone no longer opens your account.
|
|
Received a strange message in the name of Interweb? Send us a copy and we will tell you whether it is ours.
Open a support ticket
|
RECOMMENDED PRODUCT Professional e-mail on your domain Mailboxes in your company name, no adverts, with spam filtering. from $6.59/mo (3-year plan, with coupon) See plans |