Home > FAQs > Accounts, Authentication and Security > How to avoid phishing
How to avoid phishing

WHAT IS PHISHING?

Phishing is one of the most widely used techniques by Cybercriminals today. It is a form of Internet fraud where cybercriminals try to trick the user into obtaining personal or confidential information, usually by sending emails, SMS messages or phone calls that seem completely legitimate.

In the face of this threat, all the staff of the institution must be alert so as not to fall into the trap of phishing, must know how to identify a false message or e-mail and must quickly inform the systems department in the event of detection or suspicion.

In the face of even the slightest suspicion BEWARE and REPORT!

HOW DO WE AVOID PHISHING?

The best tools we have to defend ourselves are common sense and caution.

We must always keep in mind certain important precautions in order not to become victims of phishing, which are, above all:

The cybercriminals will always try to MAKE US FALL INTO THE TRAP using different techniques:

In the event that someone opens the file or clicks on the attached link the malware can act in several ways

LEARN WITH EXAMPLES

Suppose we receive the following email:

This email, at first sight, seems completely legit as it is a response to a previous conversation. But no, this email is malicious.

Unfortunately for us the cybercriminal has (fictitiously) had access to previous emails and is using them to try to trick users into such a conversation.

WE MUST BE ALERT WHENEVER WE RECEIVE ANY EMAIL

In the face of even the slightest suspicion BEWARE and REPORT!

Details that we should ALWAYS look out for when we receive an email:

  1. Check in detail who is the sender of the email, both the name and the email address. In the email we've seen, you can see that the name includes someone from the organisation, but if you look at the email address, you will see that it does not belong to the organisation:

     

  2. . We can see how the email incorporates an internet link. In these cases, before clicking on a link, you must ALWAYS CHECK the real address of the link, PLACING the MOUSE above the NON-CLICKED link.

    We can observe that the link address is totally unknown (the domain healthcorner.ae is not a corporate domain) and, therefore, absolutely suspicious.
  3. We can also see that the telephone number does not correspond with any of the institution, not even from the province of Barcelona. Again, another detail that should make us suspicious.

REMEMBER, NEVER CLICK ON A LINK IN AN EMAIL WITHOUT FIRST CHECKING IF IT IS SUSPICIOUS!!!

In the face of even the slightest suspicion BEWARE and REPORT

Other types of messages that we should be wary of in the first place:

WHAT WE SHOULD DO IF WE SUSPECT PHISHING: REPORT

In the case of being clear or of the slightest suspicion, that we are victims of phishing, we must quickly inform Serveis TIC by performing these actions:

In this case we will have to access https://outlook.office365.com/mail/ and continue with the following steps:

1. In the mail list, right-click on the mail

2. Select "Report" and then "Report phishing" or "Report spam".