Email and Messaging Attacks — Spot the Fake
Learn to spot the subtle signs of phishing and business email compromise in messages you receive every day.
In this lesson, you will learn to:
- Identify at least three common signs of phishing in email or messaging — such as spoofed sender, urgency cues, or unusual requests — and describe how to verify safely.
Email and Messaging Attacks — Spot the Fake
This lesson walks through real examples of email and messaging attacks. You’ll learn to examine sender addresses, spot urgency cues, recognize common tactics like invoice scams and credential harvesting, and practice safe responses.
The Anatomy of a Phishing Message
Phishing messages are designed to look legitimate, but they almost always contain subtle clues that something is wrong. Here are the most common signs:
1. The sender address doesn’t match the display name. A message might say it’s from your CEO, but the actual email address is a random Gmail or a misspelled domain. Always check the full sender address.
2. Urgency and consequences. The message creates pressure — your account will be closed, you’ll miss a deadline, there’s a security issue. Attackers want you to act before you think.
3. Unusual requests. Someone asking for gift cards, login credentials, or personal information in a way that doesn’t match their role or previous behavior. If it’s unexpected, it’s worth verifying.
4. Language and tone. Slight mistakes in grammar, formatting that’s slightly off, or a tone that doesn’t match the supposed sender. These are often signs of a generic template.
What to do: If you see any of these signs, pause. Don’t click links, don’t reply, and don’t forward without thinking. Verify the sender through a known channel — a phone call you initiate, or a separate email thread you start.