What is: Phishing

IT Consultancy & Repairs, located in Crewe, servicing Cheshire and surrounding areas.

What is: Phishing

What is Phishing?

Phishing is one of the most common ways cyber criminals steal passwords, money and personal information. The good news is that once you know what to look for, many phishing attacks become much easier to spot.

We have all received them. An email apparently from Microsoft telling us that our password is about to expire. A message from a delivery company saying that a parcel could not be delivered. Perhaps an urgent request from the boss asking you to pay an invoice or buy some gift cards.

Some are laughably bad. Others are frighteningly convincing.

Welcome to the world of phishing.

So, what exactly is phishing?

Phishing is a form of social engineering. Rather than trying to break through security systems directly, the attacker attempts to trick a person into doing the hard work for them.

A phishing message will usually pretend to come from somebody or something you trust, such as a bank, Microsoft 365, a delivery company, HMRC, a colleague, supplier or even somebody within your own organisation.

The objective is usually simple: persuade you to click a link, open an attachment, enter your password, approve a login request, make a payment or reveal information that the attacker can use.

What does a phishing attack look like?

📧

Fake emails

An email appears to come from Microsoft, your bank, a supplier or another trusted organisation and asks you to take urgent action.

🔐

Fake login pages

You click a link and arrive at a convincing copy of a Microsoft 365 or other login page designed purely to capture your username and password.

📱

SMS phishing

Also known as smishing, attackers send text messages claiming there is a problem with a parcel, payment, bank account or online service.

▦

QR code phishing

A QR code takes you to a malicious website. These attacks can be particularly effective because the destination address is not immediately obvious before you scan it.

💼

Business email compromise

An attacker impersonates a director, colleague or supplier and requests a payment, bank-detail change or confidential information.

📎

Malicious attachments

An innocent-looking invoice, document or other attachment may attempt to install malware or persuade you to enable dangerous content.

Phishing has become much more convincing

One of the problems with modern phishing attacks is that we can no longer rely on bad spelling and terrible grammar to identify them.

Attackers can create professional-looking emails, convincing websites and realistic messages extremely quickly. They may also research an organisation before attacking it, allowing them to mention real employees, suppliers, projects or services.

Even more concerning, a phishing email may sometimes arrive from a genuine email account that has already been compromised. If an attacker gains control of a supplier’s mailbox, for example, they can reply to an existing email conversation. That makes the message significantly harder to identify as fraudulent.

⚠️ Don’t rely on the sender’s name

Seeing the name of somebody you recognise does not prove that the message really came from them. Display names are easy to impersonate, and genuine accounts can also be compromised.

Warning signs to look out for

No single warning sign proves that an email is malicious. However, several of these together should make you suspicious:

  • Unexpected urgency – “Act immediately”, “Your account will be disabled” or “Payment required today”.
  • Requests for passwords or other sensitive information.
  • Unexpected login links, particularly for Microsoft 365 or banking services.
  • Changes to bank details sent by email.
  • Unexpected attachments, invoices or shared documents.
  • Unusual requests from senior staff, particularly involving payments or gift cards.
  • A strange sender address that looks similar to a genuine domain but is not quite right.
  • Links that don’t go where they claim when you inspect the destination.
  • Unexpected QR codes asking you to sign in or make a payment.
  • MFA approval requests you didn’t initiate.

The Microsoft 365 login trap

One particularly common attack targets Microsoft 365 users.

You may receive an email claiming that somebody has shared a document with you, your password is expiring, your mailbox is full or your account needs to be verified.

The link takes you to what appears to be the normal Microsoft sign-in page.

Except it isn’t.

The website has been created by the attacker. When you enter your email address and password, those details are sent directly to them.

Before entering your Microsoft 365 password, check where you actually are. A page can look identical to Microsoft’s login page while being hosted on a completely unrelated website.

Does MFA stop phishing?

Multi-factor authentication (MFA) provides an extremely important additional layer of security and should be enabled wherever possible.

However, MFA does not mean that you can safely click anything.

Attackers may repeatedly send authentication requests hoping that somebody eventually presses Approve. More sophisticated phishing attacks can also attempt to steal authenticated sessions rather than simply collecting passwords.

This is why modern security increasingly uses technologies such as passkeys and phishing-resistant authentication, alongside Conditional Access and other security controls.

Golden rule: If you receive an MFA request and you are not actively trying to sign in, do not approve it.

What should I do with a suspicious message?

Don’t click anything

Avoid links, QR codes and attachments until you have established whether the message is genuine.

Check independently

If your bank, Microsoft account or another service supposedly requires attention, open the normal website yourself rather than using the link in the message.

Verify unusual requests

If a colleague or supplier suddenly asks for money or changes their bank details, verify the request using a known telephone number or another trusted method.

Report it

If you are at work, report suspicious messages to your IT department or IT support provider. Reporting an attack may also protect other people in the organisation.

I’ve clicked the link. What now?

First of all, don’t ignore it and hope for the best. Acting quickly can make an enormous difference.

If you entered your password

Change the password immediately using the genuine website and contact your IT support team. Your account may need to be checked for suspicious logins, malicious mailbox rules, unauthorised MFA methods or stolen sessions.

If you downloaded or opened something suspicious, disconnecting the affected computer from the network may help prevent further activity while it is investigated.

If financial information was involved, contact the relevant bank or payment provider immediately.

Most importantly, report what happened quickly. Security incidents become much harder to contain when somebody waits several hours – or several days – before telling anyone.

When an email is trying to make you panic, rush or bypass normal procedures, that is exactly when you should slow down and check it.

Technology helps, but people still matter

Modern email security can block enormous numbers of malicious messages before they ever reach an inbox. Microsoft 365 security, spam filtering, web protection, endpoint security, Conditional Access and MFA can all significantly reduce the risk.

But no security product catches everything.

A successful phishing attack often relies on a perfectly normal human reaction: curiosity, urgency, helpfulness or trust.

Understanding that is one of the best defences you have.

Think before you click

If something doesn’t look right, there is no harm in checking. Contact the supposed sender another way, open the organisation’s website yourself or ask your IT support provider to investigate the message.

Taking thirty seconds to check an email is considerably easier than recovering a compromised Microsoft 365 account.

Follow by Email
FbMessenger