Objective: Identify phishing attempts in emails, messages, and phone calls.
Phishing is a digital deception technique used by cybercriminals to obtain confidential information such as:
- Passwords
- Credit card numbers
- Banking details
- System access credentials
They do this by impersonating a trusted entity (such as a bank, a social network, or your company) through fraudulent emails, text messages, or fake websites.
How to Detect It
- Suspicious links
- The link does not match the official domain (e.g., www.banc0.com instead of www.banco.com).
- Hover over the link (without clicking) and verify the actual URL.
- Unusual spelling or grammar
- Many phishing messages are poorly written.
- They often contain spelling mistakes or unnatural phrasing.
- Urgency or threats
- “Your account will be blocked within 24 hours.”
- “You must confirm your information now or you will lose access.”
- Requests for confidential information
- No legitimate company will ask you via email or message to provide your password or banking information.
- Suspicious attachments
- They may contain viruses or malware.
- Do not open unexpected files, especially those with extensions such as .exe, .zip, .scr, etc.
- Unknown or spoofed senders
- Messages may appear legitimate, but upon closer inspection, the sender’s address may contain extra letters or subtle errors.
What to Do If You Receive a Suspicious Email
- Do not click on any links.
- Do not download or open attachments.
- Do not reply to the message.
- Report it to the IT or Security team via Emma or the phishing button.
- Delete it once it has been identified as fraudulent.



