Fake emails are the most common cause of IT incidents. Learn how to spot phishing and what to do if you have already clicked a link.
Phishing is a fake email or message designed to make you hand over a password or card details yourself, or open a malicious file. It often arrives in the name of a “bank”, a “courier”, “Microsoft” or a familiar partner.
7 signs to watch for
- The sender’s address. The name may look right, but the address is
[email protected]. Always check the full address. - Urgency and fear. “Your account will be blocked in 24 hours”, “urgent payment” — a classic phishing trick.
- A link that goes somewhere else. Hover over the link (don’t click) and check where it really leads.
- An unexpected attachment.
.zip,.exe,.html, or a Word/Excel file that asks you to “enable macros”. - A request for a password or card details. A legitimate company never asks for your password by email.
- Generic greetings and errors. “Dear customer”, odd translations, unnatural phrasing.
- A changed bank account number. A “partner” writes that their bank account has changed — one of the most costly frauds for businesses.
💡 Rule: If an email involves money, passwords or account changes — verify it through another channel: call the person on a number you already know instead of replying to the email.
Already clicked? Act fast
- Change the password you entered on the fake page — and everywhere you used the same password. A password manager (e.g. ICOMP Pass) automatically shows which passwords you reuse.
- Notify your IT team — the sooner, the better. There’s nothing to be ashamed of — even the most careful employee can be fooled.
- Made a payment? Contact your bank immediately.
- Opened a file? Disconnect the computer from the network and wait for an IT specialist.
How to protect your company
- Spam and phishing filters on email;
- Two-factor authentication on every account;
- Short, regular briefings for employees, using real examples.