Skip to main content
Defentria
01

Phishing

Tricking peopleComes in through: Email

Emails pretending to be someone they're not

An email that looks like it's from the bank, the tax office or a supplier asks you to click, download something or type your password. It's one of the most common ways an attack starts, because it only takes one person to fall for it.

Threat map

How it happens

  1. 1

    The hook

    An email arrives with a familiar logo and an urgent reason: an unpaid invoice, a returned payment or a locked account.

  2. 2

    The click

    The link leads to a page identical to the real one, or the attachment quietly installs a program.

  3. 3

    The damage

    With the password or the program inside, the attacker reads email, impersonates the company or prepares a bigger attack.

How to spot it

  • The sender doesn't match the domain of who they claim to be
  • Urgency, threats or prizes so you don't stop to think
  • Links that point somewhere else when you hover over them
  • You're asked for your password or bank details by email

How to protect yourself

  • Train the team to recognise these emails and report them
  • Turn on two-factor authentication for email
  • Set up SPF, DKIM and DMARC on your domain
  • Have a clear channel for reporting suspicious emails

If it has already happened

Change the password straight away, sign out all sessions and tell whoever manages your IT. If bank details were entered, call the bank.

Next step

How many of these risks does your company have right now?

Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.

Take the cybersecurity test

Free · No sign-up · 3 minutes