Spotting phishing emails: 8 signals every employee should know
Most cyber incidents start with a single wrong click. Here is how to teach your team to recognise phishing, with concrete examples and one simple rule.
By Limburg Cyber Group
You can have all the firewalls and virus scanners in the world, but most incidents start in the same place: an employee who clicks the wrong link at the wrong moment. Phishing, a fake message designed to trick you into handing over data or installing malware, remains the number one way businesses get hit.
The good news: recognising phishing is a skill you can learn. Below are the eight signals we cover in every training.
1. An unexpected sense of urgency
“Your account will be blocked within 24 hours.” “Pay now or face additional charges.” Attackers want you to act before you think. An unexpected deadline or threat is the very first warning sign.
2. The sender address is just slightly off
The name in your inbox may look right, but check the actual email address behind it. invoice@micros0ft-support.com is something entirely different from microsoft.com. Watch for subtle misspellings, extra words, or a strange domain name.
3. A link that points somewhere else
Hover your mouse over a link (without clicking) and check the bottom-left of your screen to see where it really goes. Does it differ from what is written? Do not click. On your phone, press and hold a link to reveal its destination.
4. An impersonal, or oddly personal, greeting
“Dear customer” from a party that should know your name is suspicious. But beware of the opposite too: attackers now use public LinkedIn data to make their messages feel highly personal.
5. An attachment you were not expecting
An invoice you did not expect, a “voicemail” as a file, a zip from an unknown sender. Unexpected attachments are a classic route for malware. When in doubt, do not open it, verify first.
6. A request that bypasses the normal procedure
“Could you quickly pay this invoice, I’m in a meeting.” This is CEO fraud: an attacker poses as the director or a supplier and asks for an urgent payment or changed bank details. A payment request that skips the usual route is always suspicious.
7. Language and formatting mistakes
A lot of phishing still contains clumsy sentences, odd translations, or a logo that is slightly blurry. Be careful though: with AI these messages are getting more polished. So do not rely on spelling mistakes alone as proof.
8. It asks for information no one should ask for
No bank, supplier, or IT department asks for your password or full PIN by email. If you are asked for it anyway, it is almost by definition fake.
The rule of thumb for your whole team
If you want to hang it on a single sentence: when in doubt, don’t click, verify through another channel. Call the sender on a number you look up yourself, not the number in the email. That one phone call is cheaper than any incident.
And perhaps most important: make reporting easy and shame-free. An employee who raises the alarm immediately after a wrong click limits the damage enormously. A culture where people dare to report mistakes is your best defence.
From awareness to habit
One training is a good start, but recognising phishing only becomes a habit through repetition and a safe reporting culture. We help businesses in Limburg with practical awareness training and, where useful, simulated phishing tests. See our cybersecurity service or get in touch for a no-obligation conversation.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.