Training

Recognising phishing emails

Phishing is by far the most commonly used attack method: an email that tempts you to click, log in or open an attachment. Learn to recognise the warning signs and don't fall for it.

Preventing phishing: check first, then click (video by Tip ICT, video in Dutch)
Food for thought, first

You receive an email from "your bank": "Your card expires today, click here to renew it." What's the first thing you do — click, or something else?

What is phishing?

With phishing, a criminal poses as a trusted party — your bank, a delivery service, Microsoft, or even your own director — to trick you out of your login details, money or access to systems. With spear phishing, the attack targets you personally or your company, often using information taken from LinkedIn or the company website. That makes the email extra convincing.

The 7 warning signs — click to open

1. The sender address doesn't add up

Look at the address, not the display name. "Rabobank" could email you from service@rab0bank-klant.info. If the domain after the @ isn't exactly right, something's wrong.

2. Urgency and threats

"Your account will be blocked within 24 hours" — applying pressure is the classic trick to make you click without thinking. Real organisations give you time.

3. The link leads somewhere else

Hover your mouse over a link (or press and hold on your phone) to see its real destination. Expecting microsoft.com, but seeing something else? Don't click.

4. Unexpected attachments

Invoices, job applications or "scanned documents" you weren't expecting — especially .zip, .html or macro files — should not be opened.

5. Requests for login details or payments

No serious organisation asks for your password by email. Always verify payment requests from "the director" (CEO fraud) through a different channel: just call them.

6. Unusual language

A strange greeting, awkward sentences or an unusual tone. But watch out: thanks to AI, phishing emails are often flawless nowadays — good language is no guarantee it's safe.

7. Too good to be true

Prizes, refunds or gift cards that appear out of nowhere. That's exactly where they came from: out of nowhere.

Not sure?

✔ Do

  • Go to the website yourself, via your bookmark or by typing the address
  • Call the sender on a number you look up yourself
  • Report the email to your IT administrator or Tip ICT
  • Forward suspicious emails to the Fraudehelpdesk — the Dutch fraud reporting centre (Dutch)

✘ Don't

  • Click on links in the email
  • Open attachments "just to take a look"
  • Reply to the email
  • Keep quiet if you've clicked anyway

Clicked anyway, or entered your details?

It can happen to the best of us. Act quickly and don't be embarrassed:

  1. Change the password immediately

    For the account in question, and everywhere else you used the same password. From now on, use a password manager.

  2. Warn your IT administrator

    The sooner, the smaller the damage. Reporting it quickly is always better than staying silent.

  3. Shared your banking details? Call your bank

    And file a police report (Dutch police, Dutch).

  4. Have your computer checked

    For malware — especially if you opened an attachment.

Test yourself

Question 1 · self-test

Which domain really belongs to the bank?

Question 2 · self-test

An email from "the director" urgently asks you to buy gift cards. What do you do?

Question 3 · food for thought

Would you notice if an attacker sent invoices to your customers tonight using your email address?

Question 4 · self-test

You clicked a phishing link and entered your password. What do you do first?

Question 5 · self-test

Which signal points most strongly to phishing?

Question 6 · food for thought

Does everyone in your organisation know who to report a suspicious email to right away — without embarrassment if they've clicked anyway?

Further reading

Phishing simulation or awareness training for your team?

Get in touch