Hey there, and welcome aboard! I'm Sally β think of me as the friendly voice in your ear whenever something online feels a little "off."
Here's the thing nobody tells new hires on day one: our biggest defense against scammers isn't a fancy firewall or some piece of software humming away in a server room. It's you. Every single email you open is a decision point, and in the next few minutes I'll show you exactly what to look for.
Phishing is just a fancy word for a very old trick: a scammer pretends to be someone you trust β your boss, HR, IT, even a delivery company β to convince you to hand over something valuable. Usually that's your password, or your money.
It's called "phishing" because they're dangling bait and hoping someone bites. They don't need everyone to fall for it β they just need one person, one time, to click.
Scammers borrow a trusted name β a coworker, a bank, a well-known brand β because you're far more likely to act quickly for someone you recognize.
Say hi to Pete β our stand-in for every scammer out there. His one and only goal: get you to type your username and password into a fake page he controls.
You don't need to be technical to catch a phishing attempt. You just need to recognize these four behavioral tricks β they show up again and again.
Scammers want you moving faster than you think. Panic skips the "wait, does this seem right?" step.
"Act NOW or your account will be deleted!"A surprise bonus, a free gift card, an unexpected prize β offers designed to make you click before you think.
"You've been selected for a $500 reward!"The display name says one thing, but the actual address behind it tells a different story entirely.
"HR Team" <hr-update@gmail.com>Real corporate emails go through review. Odd phrasing, typos, or clumsy grammar in an "official" message is a big tell.
"Kindly to confirm you're account informations"This one targets you specifically, using a name you'd never question β the CEO.
Hi, I'm heading into a client meeting and can't talk right now β this is time sensitive.
I need you to purchase $300 in digital gift cards for a client gift. Send me the card codes as soon as you get them, I'll reimburse you personally. Please keep this between us for now.
Thanks β this needs to happen in the next 20 minutes.
Freeze β a real CEO is never going to ask a brand-new hire to secretly buy gift cards over email. Think about it: no company reimburses employees with Target gift cards.
Notice the tricks stacked together: urgency ("20 minutes"), secrecy ("keep this between us"), and a sender name that sounds official. That combo is a classic spear-phishing setup β it's aimed at you personally, using a name you'd never question.
What to do: stop, and verify through a separate channel β call or message the person directly using a number or handle you already know. Never reply to the suspicious email itself.
This one plays on habit β nobody wants to lose access to their own account.
Your password is set to expire in 2 hours. To avoid losing access, click below to keep your same current password active.
This is an automated message. Please respond within the hour.
"Come on, just one click! It's your own password, what's the harm? You've got two hours β better hurry before IT locks you out..."
Not so fast, Pete. First red flag: "keep your same password" makes no real sense β that's not how password resets work, and that's exactly why it sounds oddly reassuring.
Here's your best trick: hover your mouse over a link without clicking and look at where it actually leads (it usually shows up in the corner of your screen, or in a tooltip like the one above). If the address looks strange, unrelated to our company, or oddly spelled β that's your answer. Don't click it.
DON'T click links or download attachments. Even "just looking" can trigger something. If it's suspicious, leave it alone.
DON'T reply β not even to say "stop emailing me" or "unsubscribe." Replying just confirms your address is active and being read.
DO use the "Report Phishing" button in your email client. It takes two seconds, alerts our security team instantly, and helps protect everyone else on your team too.
You now know more about phishing than most of the internet. Stay curious, stay a little suspicious, and remember: it's always okay to pause and ask before you click. Go get 'em! β Cyber Sally π