How to Spot Fake or Scam Emails
And What To Do About It
Fake or scam emails, also referred to as Phishing Emails are used to steal private information from you (such as passwords or bank details). Find out how to spot these emails, what to do about it and how to protect yourself from them in future.
Before we start
What is “Phishing”?
Essentially it’s a method used to trick you into giving away your passwords or other sensitive data by pretending to be a website or service that you are familiar with; such as Microsoft, Google, Dropbox, etc.
A common trick is to masquerade as a person or company that you trust. Attackers can use public information such as Directors names, your website staff information or LinkedIn relationships to send targeted emails to you or potential victims.
We recommend double checking the email address of the sender when you receive an email, particularly if the email is requesting you to log into a website or send money from one location to another. Make sure you recognise the email address, look out for email addresses that appear to copy an existing address or domain as these will likely be phishing emails.
Beware of Links and Downloads
Many Phishing emails will contain links, buttons and downloads all with the purpose of stealing your sensitive data. These links will typically direct you over to a website that will show a fake login or banking form, where you will input details and give the attackers your data.
On desktop, you should be able to right click on a link or button and copy the address, or on a mobile device hold your finger on it and copy. (This may vary depending on your email software/device). This will allow you to preview the full link before visiting it. If the link appears to mimic an existing domain, or directs you to a website you’re unfamiliar with do not visit the link.
Similarly, if the email is from an unknown or suspect email address, or contains unfamiliar or suspect links we would also discourage you from installing any downloads.
We’ve included some examples of Phishing Emails towards the end of this article.
Preventative Measures
In recent years phishing attempts have become far more credible looking . The untrained eye of your users will be more likely to fall for these tricks, so how can you better protect yourself and your business?
The first thing to do is give all your users regular training reviews on what to spot, you could point them to this article for them to understand some examples and the types of techniques used. Consider enlisting them on a safe Internet training course, although this can be expensive, consider the damage in reputation or financial loss that could occur from a successful attack.
If you’re in a high risk business you should also consider taking out specialist insurance to cover you for losses or legal reprisals from technology related security breaches.
We also strongly recommend Two Factor Authentication (also known as 2 Step Authentication) for all websites that are important to you; such as email access, your bank access, cloud login accounts etc.
This works by requiring a code in addition to your username and password to login to your account and typically works as follows:
- Enter your username and password
- The system sends an additional code either to your email or mobile.
- Enter the code and gain access to your account.
There’s a comprehensive list of platforms and advice on how to enable this available here https://twofactorauth.org, below are some links to get you started with the bigger platforms:
How to Report Phishing
Many people feel there’s nothing you can do about phishing attempts other than to ignore them, but there are actually a few things you can do to help make their lives more difficult. These actions could be essential to manage the fallout if it is your email account which has been hacked and your contacts are receiving fraudulent information.
Reporting The Email
In most web based email clients you should have an option to highlight an email as suspicious or abuse. Note, this is not the same as Spam – so do not report it as spam. Be mindful that once you report it, the email will likely disappear from your inbox.
In the UK you can report Internet fraud and scam email via Action Fraud. You usually won’t hear anything back unless you’ve had an actual loss.
You should report the website to Google who will flag this up in their search engine to advise future visitors that it is “suspicious”.
Similarly you can also report the website to Microsoft.
Report Bank Details
If you are sent banking information with IBAN or SWIFT codes you can discover the real bank information and report this account as potential fraud to the bank directly. The hope is that the bank will prevent anyone from making payments into the account. Most likely this bank account will have been hijacked and nothing to do with the account owner.
Use a tool such as iban.com to validate IBAN /BIC codes and discover the bank address or if you have a UK sort code fasterpayments.org.uk can help.
Then look up that bank on the Internet and attempt to call, online chat or email them. The conversation should go along the lines of:
”I have been asked to make a fraudulent payment into one of your accounts. There has been no loss and I am happy to send you the details I have to investigate this account further. Here are the account details.”
Send them the account number and hopefully they can assist you. They will often ask for your name and contact details as well.
Most banks should have an official way to report fraud, use a search engine to find that information or contact them directly.
Phishing Examples
Basic Phishing Example
The following email is an example of a phishing email sent to trick a user into giving away their Google account details.
You can see the From: address is a generic address (default-host.net), not a Google domain. The email body does look nicely crafted, but the spacing isn’t right and it just ‘feels’ wrong, but if you’re new to using Google apps you might not have this intuition.
Clicking on the “VERIFY IMMEDIATELY” button will direct the user to a scam website called “Assignment Help Team”.
The scam “Assignment Help Team” website closely mimics the real Google login page. If you typed your password into here then it will return an incorrect password message and you’ve just given away your credentials to a hacker!
The Tell Tale Signs
- The scam site isn’t a legitimate Google domain.
- The email address passed to that page is also in the URL, which indicates that the page is getting your email from the URL, and not a Google database.
- Although the scam site has a security certificate, this is no guarantee of authenticity. Your browser will show a padlock and the site is said to be “secure”, but this just indicates that the communication between your browser and this website is encrypted, not that the website is authentic.
Real vs Fake
Checkout the comparisons between the real login and the fake one:
It’s pretty easy to tell when they’re side by side, but if you’re in a rush you could be forgiven for thinking they’re the same.
First big giveaway is that the real one has your name on it and logo. Although the layout of both is the same, the text on the links and button is fuzzy. They’re images and not real text links, they also do not link to anywhere.
The URL is always important to check. The real login page is https://accounts.google.com
The domain name is important, this is google.com. Sometimes they will try to trick you with a long url like this, http://secure.myhackeddomain.co/uifaiyg397/mail.google.com – the domain name on this URL is “myhackeddomain.co” – not google.com!
Also note the https:// means secure and if you click the padlock you should be able to read the certificate information in your browser and it will refer to Google like this:
Sophisticated Phishing Example
Google Docs Authorisation Request
This one is nasty and will fool a lot of people – it took me a couple of views to spot what they’d done here.
Once a victim clicks on the fake Google Doc link, he or she is taken to a real Google page prompting you to select an account. After that, they are taken to a new page asking that they allow “Google Docs” to access the account.
If you click “allow,” the attacker can access your account. And all your contacts will likely soon receive a fake Google Doc invite from you.
If your browser supports animated GIFs you’ll see a demo of how it works below. Note that the Developer info and email address are not Google and this link is requesting permission for you to access.
LET’S TALK ABOUT IMPROVING YOUR BUSINESS
To find out how we can develop software that drives your business, call us on 01952 898626, email us at [email protected] or send us a message using the contact form below










