Think Before You Click
Spot impersonated senders, urgent requests and suspicious attachments, then verify independently.
Illustrative scenario
How It Looks in Real Life
An email that appears to come from your bank says a payment has been blocked and asks you to “confirm your details” within one hour. The display name is correct, but the sender domain is bank-secure-example.com.
Understand it
How the Attack Works
Phishing imitates people and organisations you trust. It relies on urgency and familiarity to make you click, open a file or share information before you stop to check. The link usually leads to a convincing copy of a real sign-in page.
Red flags
Warning Signs
- A familiar display name with an unfamiliar or slightly misspelled sender domain.
- Pressure such as “account suspended” or “act within 1 hour”.
- Link text that does not match the real destination shown on hover or long-press.
- Unexpected attachments, especially archives, HTML files or documents asking to enable content.
Safer habits
What to Do Instead
- 1Open the service by typing its address or using its official app, not the link in the message.
- 2Verify unusual requests through a contact you already know, not one supplied in the message.
- 3Report the message using your organisation’s report button or IT channel.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: opened a message or clicked a link
- 1Close the page without entering anything further.
- 2Report the message through your usual IT or security reporting channel.
- 3Keep the original message; do not forward it to colleagues as a warning.
If you: entered credentials or shared a code
- 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
- 2Change the password from a trusted device by typing the real address yourself.
- 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
- 4Review recovery email, phone number and forwarding rules for unexpected changes.
If you: sent a payment or changed bank details
- 1Contact your bank immediately and ask for a recall of the transfer.
- 2Inform finance leadership and IT or security the same day.
- 3Keep all emails, invoices and call records as evidence.
Knowledge Check
What Would You Do?
You receive: “Your mailbox is 98% full. Sign in at mail-upgrade.example.com within 24 hours to avoid losing messages.” What do you do?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.