Phishing
Tricking peopleComes in through: Email
Emails pretending to be someone they're not
An email that looks like it's from the bank, the tax office or a supplier asks you to click, download something or type your password. It's one of the most common ways an attack starts, because it only takes one person to fall for it.
Threat mapHow it happens
- 1
The hook
An email arrives with a familiar logo and an urgent reason: an unpaid invoice, a returned payment or a locked account.
- 2
The click
The link leads to a page identical to the real one, or the attachment quietly installs a program.
- 3
The damage
With the password or the program inside, the attacker reads email, impersonates the company or prepares a bigger attack.
How to spot it
- The sender doesn't match the domain of who they claim to be
- Urgency, threats or prizes so you don't stop to think
- Links that point somewhere else when you hover over them
- You're asked for your password or bank details by email
How to protect yourself
- Train the team to recognise these emails and report them
- Turn on two-factor authentication for email
- Set up SPF, DKIM and DMARC on your domain
- Have a clear channel for reporting suspicious emails
If it has already happened
Change the password straight away, sign out all sessions and tell whoever manages your IT. If bank details were entered, call the bank.
How we help
Training
Fake emails and phishing
A practical course so your team recognises it in time.
Audit
We check whether this door is open in your company and how to close it.
Full guide · in Spanish
Phishing en gestorías: cómo detectarlo antes de que sea tarde
Other threats through this door
See all threatsHow many of these risks does your company have right now?
Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.
Free · No sign-up · 3 minutes