Detect and Prevent Phishing

Detection - Signs of a phishing attempt

It can be hard to detect a phishing mail but there are some warning signs to keep a look-out for:

  • The mail seems to friendly for the purpose.
  • Request for personal information.
  • The sense of an emergency.
  • Spelling and grammar errors.
  • Unsolicited content or advice.
  • Attachments. 
  • Inconsistencies in email addresses, links, etc.
  • Unusual requests.
  • The message says you are the winner of something.


Actions to help prevent or delay a phishing attack

Only respond to known senders

If you get an unsolicited message in your mailbox/chat/phone etc. from a sender you don´t know or expect a message from, be cautious. Everytime you respond to an potential phishing mail you increase the risk for falling for a phishing attack because you have showed that you are willing to interact and that the mail/phone number/account are active. This can prompt them to continue trying to scam you in the future and risk of giving personal information becomes bigger. 


To prevent phishing, only respond to people you know and trust.

Always report suspicious mails to your email provider

When getting a suspicious message make sure to report it as soon as possible to your message service provider. If the message were sent to a work related account make sure to inform your company's security function. When reporting you help the provider/company to stay on top of potential phishing threats.

DO NOT JAILBREAK!

Jailbreaking is something many people, especially younger people, do. Jailbreaking is when you remove software restrictions on a device to unlock additional features or install third-party applications.


The problem with this is that at the same time you remove restrictions to do something yourself, you also leave your device vulnerable to security threats.

Firewalls and Antivirus (Malware Protection)

An easy way to help you block out any outsider is to use a firewall. Even if it do not block phishing mails it provides an layer of protection for your information.


If you accidentally click a phishing link your antivirus software help you stop the virus before it can infect your device.

Never share personal information

Never share personal information to someone you don´t know! And if needed always make sure to control through phone or in person with the receiver to make sure i really are them on the other end. 


Please note that legitim financial institutions will not ask for your personal information over mail, they will not ask through phone either if you aren´t the one contacting them. 

Keep things up to date

By keeping your devices and operating systems up to date you will gain a higher protection from phishing. Most updates include some security patches that help you to keep your device safe.


Many people forget to keep their applications up to date which is just as important as an updated device. Updates in, for example, the browser help the user by blocking pop-ups etc. So if you happen to click a link in a phishing mail the browser will hopefully block it.

Strong passwords and two-factor authentication

A password can be seen as the last defence for your personal information.


If you accidentally click on a phishing link the password can help you keep the bad guys out.


If you want to know more about passwords and MFA check out Security Dragon - Password

Stay Informed

The methods used by scammers always changes, the latest is AI. To be prepared try to keep informed about the changes in technology, do not need to be deep knowledge just be aware about what happens in the technology.

Think before you click

It doesn't matter where on the internet you are, it doe´s not just be links in mail or messages, never click suspicious links and attachments. An unknown link can contain malware. 


Sadly this also include fake unsubscribe links. Instead of unsubscribing, you may be taken to a malicious website or marked as an active email account.

WHAT TO DO IF YOU GET A PHISHING EMAIL

WHAT IF I HAVE CLICKED OR RESPONDED?

  1. Report the message
  2. Change passwords
  3. Inform your financial institution of the attack
  4. keep a close watch over your online accounts and banking statements to be able to see if the scammer successfully made it into any of your accounts.
  1. Don’t respond
  2. Don’t open any links or attachments
  3. Report the email as phishing
  4. Delete the message