Phishing emails are widespread, and scammers are becoming more adept at crafting them. “A phishing email is characterised by a call to click on something, such as a suspicious link or attachment,” explains Merle Kappak, Senior Specialist of IT Support at the Estonian IT Centre, describing the nature of the scam.
According to the expert, the links are usually fake versions of legitimate websites where the victim is tricked into entering their username and password or other personal information, which is then used maliciously. “Attachments in phishing emails are almost always malware,” she adds, providing examples of how to recognize phishing emails or how to proceed if you fall victim to one.
Anyone can fall victim to phishing emails
The IT expert emphasises the importance of being observant with both work-related emails and personal addresses and accounts. Recently, Kappak encountered a case where employees received emails that seemed to come from a familiar portal, but the sender's address ended in ".eu" instead of ".ee."
“Phishing email senders may appear to be from your home bank, a public institution, a familiar service provider, or well-known companies like Microsoft or Amazon,” Kappak cites common tactics. “They might even go as far as impersonating your boss, colleague, friend, or even a family member,” she adds. Therefore, it’s essential, according to Kappak, to always verify the sender’s address and be alert to unusual writing styles, typos, and atypical requests.
How to verify email authenticity?
“At the slightest suspicion of a phishing email, you should double-check the sender and never click on links or download attachments. I encourage using web portals that help identify phishing and virus-containing links and attachments – one such portal is virustotal.com,” says Kappak. She advises hovering over a link to see its actual address. If it is a familiar site, she recommends navigating directly to the official website instead of clicking the link.
She also points out that if an email requests personal or sensitive information, such as passwords or bank details, it is likely a scam. “No bank, public institution, or reputable company will ask for passwords through an email link,” emphasises the senior IT support specialist. Therefore, in case of doubt, she advises seeking additional confirmation either through the sender’s official phone number or website.
What to do with exceptional offers?
“Sometimes, common sense applies – if something seems too good to be true, it usually is,” says Kappak regarding unusually enticing offers received by email.
She notes that phishing emails often contain easily identifiable hints of fraud. “We’ve all encountered messages about incredible inheritances or randomly falling investments to be distributed. Over-the-top and grammatically incorrect language often clearly indicates a simple scam,” explains Kappak.
Pressure to act quickly is a red flag
“Recently, there have been messages sent to phones that appear to be from courier companies or other well-known firms, emphasising emotions and urging you to quickly click a link and enter your details to receive a package,” Kappak gives an example of a common scam. She explains that historically, scams have relied on knowing the victim’s psychology and behaviour.
“Think before you act. Don’t succumb to urgent demands; take the time to assess the situation and consult a reliable expert if necessary,” the expert stresses the need to always verify whether the urgent demand presented in the phishing email is realistic.
Fraudsters may use data much later
Kappak notes a common misconception that nothing happened if there was no immediate visible effect after clicking a link or opening an attachment. “Attachments can hide malicious code snippets that start reading data,” she says.
“After an incautious click, you should always run a virus scan on your computer and change all your passwords,” advises Kappak, adding that it is important to do this for both work-related and personal accounts since phishers count on password reuse. For work computers, she advises contacting your IT support to resolve the situation effectively. “Don’t feel ashamed, and if possible, seek background information from specialists about the email beforehand, before clicking,” concludes the senior IT support specialist.