Protect Yourself
Spot the Social Engineering Tactic

The hands-on activities help find patterns that can help protect us from common Social Engineering tactics. Below is a list of the most common signs to be aware of and on the lookout for when you receive a suspicious message as recommended by Get Cyber Safe.
Urgent or threatening language. The message will want you to act quickly and not think too much about the situation. It may try to force you to act by including tight deadlines or legal action. Always take time to think, ask someone you trust and then act.
Requests for sensitive information. No one should be asking for your personal information via email, text or phone. When contacted by an organization, default to reach out directly via their site or phone, instead of clicking links on the email or message.
Anything too good to be true. Not only is this good advice when dealing with cybersecurity but also in your daily life.
Unexpected emails. Don't recognize the sender? Are you getting an invoice for something you did not purchase? Do not answer these messages. Delete them.
Information mismatches. Companies are very careful when it comes to their external messaging. Look for inconsistencies or things that seem wrong, such as bad grammar or spelling.
Suspicious attachments. Question receiving attachments unless you are expecting them. They can contain malware to infect your system.
Unprofessional design.

🤿 Optional - Deep Dive: Look for
A more comprehensive list of warning signs:
Generic Greetings: Phishing emails often use generic greetings like "Dear User" or "Hello Customer" instead of your name.
Urgent or Threatening Language: Phishers create a sense of urgency by using phrases like "Your account will be locked" or "Immediate action required."
Unsolicited Attachments or Links: Be cautious of emails or messages with unexpected attachments or links. Hover over links (without clicking) to see where they lead.
Misspelled Words and Bad Grammar: Phishing emails often contain spelling errors, grammatical mistakes, and awkward language.
Mismatched URLs: Check the actual URL by hovering over links. Ensure it matches the legitimate website's domain.
Requests for Personal Information: Legitimate organizations rarely ask you to provide sensitive information (like passwords or Social Security numbers) via email.
Too Good to Be True: If an offer seems too good or too easy, it's often a phishing attempt. "You've won a prize" is a common ploy.
Impersonation: Be cautious if an email appears to be from a well-known organization but asks for unusual or sensitive information.
Spoofed Sender Addresses: Phishers can manipulate the "From" address to make it look like it's from a legitimate source.
No Contact Information: Legitimate organizations provide contact information. If there's none, it's a red flag.
Unusual Sender: An email from an unusual or unrelated source is suspicious. Verify the sender's identity.
Unusual Sender Address: An email from a free, uncommon, or unusual email service should raise suspicions.
Too Much Personalization: Phishing emails might use too much personal information to seem more convincing. Be cautious.
Mistaken Identity: Watch out for messages claiming to be from friends or family but asking for money or personal information. Verify with the person directly.
No Security Indicators: Lack of "https" in the URL or a padlock icon in the address bar can indicate a non-secure website.
Inconsistent Logos and Branding: Compare the email's logos and branding to the legitimate company's website. Discrepancies are a red flag.
Unexpected Email Sources: Be cautious of emails claiming to be from government agencies or unfamiliar organizations.
No Opt-Out: Legitimate marketing emails usually have an option to unsubscribe. Phishing emails often lack this.
Attachments with Strange Extensions: Email attachments with unfamiliar or suspicious file extensions could be harmful.
Too Many Recipients: Be wary of emails that display many recipients, especially if you don't know them.
Always exercise caution when you encounter these red flags, and verify the authenticity of the message or sender when in doubt.
Last updated
Was this helpful?
