Phishing Awareness

    Think Before You Click

    Spot impersonated senders, urgent requests and suspicious attachments, then verify independently.

    Everyday Cyber SafetyEveryday usersFinanceHR & recruitmentLeadership

    Illustrative scenario

    How It Looks in Real Life

    An email that appears to come from your bank says a payment has been blocked and asks you to “confirm your details” within one hour. The display name is correct, but the sender domain is bank-secure-example.com.

    Understand it

    How the Attack Works

    Phishing imitates people and organisations you trust. It relies on urgency and familiarity to make you click, open a file or share information before you stop to check. The link usually leads to a convincing copy of a real sign-in page.

    Red flags

    Warning Signs

    • A familiar display name with an unfamiliar or slightly misspelled sender domain.
    • Pressure such as “account suspended” or “act within 1 hour”.
    • Link text that does not match the real destination shown on hover or long-press.
    • Unexpected attachments, especially archives, HTML files or documents asking to enable content.

    Safer habits

    What to Do Instead

    • 1Open the service by typing its address or using its official app, not the link in the message.
    • 2Verify unusual requests through a contact you already know, not one supplied in the message.
    • 3Report the message using your organisation’s report button or IT channel.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: opened a message or clicked a link
    1. 1Close the page without entering anything further.
    2. 2Report the message through your usual IT or security reporting channel.
    3. 3Keep the original message; do not forward it to colleagues as a warning.
    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.
    If you: sent a payment or changed bank details
    1. 1Contact your bank immediately and ask for a recall of the transfer.
    2. 2Inform finance leadership and IT or security the same day.
    3. 3Keep all emails, invoices and call records as evidence.

    Knowledge Check

    What Would You Do?

    You receive: “Your mailbox is 98% full. Sign in at mail-upgrade.example.com within 24 hours to avoid losing messages.” What do you do?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us