{"id":2107,"date":"2011-04-05T14:46:00","date_gmt":"2011-04-05T20:46:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2107"},"modified":"2025-01-03T13:01:33","modified_gmt":"2025-01-03T19:01:33","slug":"how-to-spot-and-stop-a-phish","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/","title":{"rendered":"How to Spot and Stop a Phish"},"content":{"rendered":"\t\t<section id=\"block_77195c0cba1b7d9129287a189b06e467\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>How to Spot and Stop a Phish<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_199abf8444727ea31467a3c5136ab284\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Six tips to spot and stop a phish<\/h2>\n<p>Over the weekend, a security breach came to light that compromised the email addresses and names of an undisclosed number of consumers from major national companies. You may have received an email over the past few days from one of these companies notifying you of the breach.<\/p>\n<p>While this incident does not pose any direct risk (except spam) to consumers, it does pose an indirect risk through phishing attacks. Malicious parties may use these names and addresses to email affected consumers, posing as a legitimate company to solicit the victim to provide sensitive personal information so they can commit identity theft and financial fraud.<\/p>\n<p>Such bogus emails often ask the victims to confirm an account or log in to their existing account to receive a prize or discount. However, they typically direct consumers to fake sites or ask that the recipient send sensitive personal information in a direct email response.<\/p>\n<p>The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. If you receive a phishing email, you can notify the Secret Service (who is investigating this particular breach) at: <a href=\"mailto:phishing-report@us.cert.gov\">phishing-report@us.cert.gov<\/a>.<\/p>\n<h2>So how do you spot a phishing email? Here are six tips:<\/h2>\n<h3>1. Trust your gut and when it doubt, contact the company directly<\/h3>\n<p>If you get an email from a company or authority where something seems \u201coff,\u201d then contact the company via normal means to confirm the email\u2019s authenticity.<\/p>\n<p>Do not contact the company or authority via any URL, email address, phone number, or other contact information provided within the suspicious email.<\/p>\n<p>Instead, you should go directly to the company\/authority website or call them using a URL or phone number you or someone else has previously confirmed as legitimate.<\/p>\n<h3>2. Check the \u201cfrom\u201d field<\/h3>\n<p>Phishers can easily spoof authentic email addresses, making it appear that an email is coming from an authentic, trusted sender.<\/p>\n<p>Still, checking the \u201cfrom\u201d field can at least help you identify unsophisticated phishers.<\/p>\n<p>If the \u201cfrom\u201d email contains excessive characters, has spelling mistakes, or does not share the same domain as the company (e.g. \u201c@gapcustomershelp.com\u201d (illegitimate) vs. \u201c@gap.com\u201d (legitimate)) you might have found a phish.<\/p>\n<p>But again, just because the \u201cfrom\u201d email address checks out it does not mean that the email is authentic since this \u201cfrom\u201d email field can be easily spoofed.<\/p>\n<h3>3. Check the \u201cto\u201d field<\/h3>\n<p>Legitimate companies with whom you have an established relationship will often (but not always) send you emails with personalized subject lines or introductions (e.g. \u201cJohn, it\u2019s time to renew your account\u201d or \u201cDear John A Doe,\u201d.<\/p>\n<p>This is not a hard rule, however, so if you receive an email with a generic subject line or introduction do not automatically assume it is a phish or if they do personalize the email do not assume it\u2019s not a phish.<\/p>\n<p>Also, if you have multiple email addresses, verify that the email address they used to contact you is the one you used to sign up for that online account. If it\u2019s not, you might have found a phish.<\/p>\n<h3>4. Check the links<\/h3>\n<p>If the email contains links hover over them (but do not click them) with your mouse \u2013 does the preview URL that appears match the URL in the email text?<\/p>\n<p>Phishers may include a legitimate URL in their email that redirects to an illegitimate URL. Look how I can redirect you to Google from the following TRUSTe link: www.truste.com.<\/p>\n<p>Scammers use the same technique to make you think you are navigating to a legitimate site. If the URL preview does not match the written URL, this can be a strong sign that you have found a phish.<\/p>\n<p>Additionally, if either the link or preview link does not contain the traditional company domain address (e.g. \u201cwww.gapcustomershelp.com\u201d (illegitimate) vs. \u201cwww.gap.com\u201d (legitimate)) you should be suspicious and suspect phishing.<\/p>\n<h3>4. Fact check the email content<\/h3>\n<p>Look carefully at the contents of the email. If they refer to a previously established account, does the information they provide about the account match up with your actual account information?<\/p>\n<p>Phishers may try to trick you into believing in the email\u2019s authenticity by adding erroneous account or confirmation details, hoping you will not be attentive enough to notice the errors. Look carefully. If something doesn\u2019t add up, you\u2019ve probably got a phish on your hands.<\/p>\n<h3>5. Legitimate companies and authorities do not ask for personal information via email<\/h3>\n<p>If you\u2019ve received an unsolicited email asking you to provide sensitive personal information directly within an emailed response you can pretty safely assume that it\u2019s a phishing attack.<\/p>\n<p>Reputable companies would almost never ask you to confirm details like your account, social security, or credit card number via an emailed response, but would instead direct you to a secured company page using SSL to protect your information via encryption.<\/p>\n<h3>6. Look for grammatical errors and spelling mistakes<\/h3>\n<p>A lot of phishing activity originates from outside the United States in countries where English is not the first language so when they craft these emails these often make grammatical errors or spelling mistakes in abundance \u2013 errors your real bank or account provider would never make in a professional customer email.<\/p>\n<p>If the grammar and spelling do not add up or if the language seems odd and non-sensical there\u2019s a good chance you\u2019ve found a phish.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/cyber-security\/\" class=\"badge\">Cyber Security<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. So how do you spot a phishing email?<\/p>\n","protected":false},"featured_media":1699,"template":"","topic-resource":[62],"type-resource":[6],"class_list":["post-2107","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-cyber-security","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How to Spot and Stop a Phish | TrustArc<\/title>\n<meta name=\"description\" content=\"The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. So how do you spot a phishing email?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/\",\"name\":\"How to Spot and Stop a Phish | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-purple.png\",\"datePublished\":\"2011-04-05T20:46:00+00:00\",\"dateModified\":\"2025-01-03T19:01:33+00:00\",\"description\":\"The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. So how do you spot a phishing email?\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/how-to-spot-and-stop-a-phish\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-purple.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-woven-purple.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to Spot and Stop a Phish | TrustArc","description":"The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. So how do you spot a phishing email?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/","url":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/","name":"How to Spot and Stop a Phish | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-purple.png","datePublished":"2011-04-05T20:46:00+00:00","dateModified":"2025-01-03T19:01:33+00:00","description":"The best way to protect yourself from a phishing attack is to recognize these fraudulent emails and not engage them. So how do you spot a phishing email?","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/how-to-spot-and-stop-a-phish\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-purple.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-woven-purple.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1699"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2107"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2107"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}