What Is Phishing and How Do Employees Spot It?
Fake messages built to steal credentials or money, and the tells that give them away.
Phishing is a message, usually email but also text, phone or chat, that impersonates someone you trust in order to steal a password, install malware or trick you into sending money. It remains the most common starting point for breaches because it targets people, not systems.
The common forms
- Credential phishing. "Your password expires today," with a link to a fake Microsoft 365 login page.
- Attachment phishing. An invoice, shipping notice or shared document that installs malware when opened.
- Business email compromise. A message that appears to come from your CEO or a vendor asking for a wire, gift cards or a change of bank details. See what is business email compromise.
- Smishing and vishing. The same tricks by text message or phone call, often posing as IT support.
How employees can spot it
- Urgency and pressure. "Immediately," "final notice," "do not tell anyone."
- The sender does not match. The display name says a colleague; the actual address is a lookalike domain or a free mail account.
- Links that go somewhere else. Hover before clicking. A Microsoft login should be on a Microsoft domain.
- Unexpected attachments, especially from people who do not normally send them.
- Requests to bypass process. Any request to change payment details or skip a normal approval should be verified by phone using a number you already have.
- Generic greetings and small errors still show up, though AI-written phishing is cleaner than it used to be.
What to do with a suspicious message
Do not click, reply or forward it around. Use the report button if your email has one, or send it to your IT support team, then delete it. If you already clicked, report it immediately. Speed matters far more than embarrassment.
The organizational fix
Email filtering catches much of it, multi-factor authentication limits the damage when a password is stolen (what is MFA), and recurring security awareness training with simulated phishing keeps people sharp. Mentis Group includes all three in Enhanced Cybersecurity and our managed IT programs.
Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.