BRF-02 / Phishing

Phishing emails, texts and calls, and how to tell a real message from bait

Phishing is a message pretending to be someone you trust so you'll click, sign in, pay or share something. It shows up as email, text messages (sometimes called smishing), phone calls (vishing), social media DMs and QR codes. The name changes. The trick doesn't.

What makes phishing work isn't technical skill. It's timing and pressure. A final notice from a toll road. A delivery text the week you're expecting a package. A message from your boss's name asking you to buy gift cards before a meeting.

This section breaks phishing into the parts anyone can check: who really sent it, where the link really goes, what it's asking you to do, and how to confirm it through a channel the message didn't give you. We also cover what to do after you've clicked, because that happens to careful people too, and the first hour matters most.

Red flags

  • Pressure to act within minutes or hours.
  • A sender or link domain that's close to the real one but not quite.
  • A request to sign in from a link instead of going to the site yourself.
  • Any request for gift cards, crypto or a payment-app transfer.

5-minute security check

  • Long-press or hover over links before you tap them.
  • Use your email app's Report phishing button.
  • Bookmark the login pages you use most.
  • Agree on a callback rule for payment requests at work.

Phishing briefings

No phishing briefings are filed yet. The first one is in the works; until then, the headlines below track what’s happening.

Current attack reporting from The Hacker News

Keep reading

Follow on Google News