There’s a problem with your bank account or at least that’s what the email says. Worried, you click the link and type in your username and password. The only problem is your bank didn’t send you the email!
Messages disguised in this way are known as phishing emails. Crafted to look like they are from a well-known organisation or a supplier or your bank, they get your attention and encourage you to click on a link or open an attachment. And without realising it, you hand over your credentials to an attacker or install a backdoor on your computer. Now they don’t need a key to let themselves in!
Phishing emails often persuade victims to click on links or open attachments by:
- Saying something is ready or needs your attention.
- Saying you must confirm personal information, or your account will be closed.
- Sending a fake invoice or demand payment.
- Offering a refund or a benefit you will be interested in.
Part of the problem is that emails are still inherently insecure. Anyone can send a fake email with dangerous content that ends up in the centre of your computer network. Rather than trying to guess passwords or use other time-consuming attack methods, criminals know that it is much easier to trick an employee into giving them access to your network through a phishing email. If they do some background research first, such methods can be extremely effective.
“Email poses one of the most serious and real security threats to our businesses and organisations.”
Let’s look at how we can minimise the risks:
- Be suspicious of all emails, especially ones with attachments or urgent requests.
- Check the sender’s email address, which is often similar but different from the real organisation.
- Check that the style and content match the sender e.g. formal style from a bank. Are there grammatical or spelling errors?
- Are there formatting or layout issues or maybe the logo doesn’t look right?
- Type web addresses into your browser or create short-cuts. Avoid clicking links in emails.
- Keep your computers up-to-date, properly patched and security hardened.
- Conduct awareness with all employees and keep reminding them of the dangers and the need to be careful.
“Pick what you click and if in doubt, delete it out!”
Here is a real example of a phishing email that appears to have come from ANZ Bank. Notice the email address of the sender – it is the only real giveaway in this case.
With so many potential threats, every office needs to employ multi-layered security that includes a modern firewall, capable anti-virus and an email system that can stop dangerous messages before they reach your inbox.
Get advice, take preventative action early and make sure you have all your staff on board. If you leave things to chance, you will eventually find yourself on the end of a hackers phishing line! Remember, even the best security systems are only as good as the weakest link and that is often us, the humans!
For more information, call us on 22770, email support@positivesolomon.com or click the “chat” link.









