Stop. Look. Think.
Protect yourself from online scams. Spot the signs. Spot the crimes.
Always remember: Never click on links or open attachments in an email that you weren’t expecting. This single rule will help you avoid many common hacker tactics.
Attacks succeed on speed. A message arrives, it looks routine, and the click happens before the thinking does. Three seconds of attention is usually all it takes to break the chain.
The three steps
Urgency is the tactic. A deadline, a threat, a payment that must go out today. Put the mouse down first.
Check the sender’s full address, not the display name. Hover a link and read where it really goes.
Were you expecting this? Would this person normally ask you this way? If not, verify on a channel you chose.
Five signs worth a second look
A domain that is almost right. One extra letter, a hyphen, or .co instead of .com. Read the part immediately before the first single slash.
A login page you arrived at by clicking. Real sign-in pages are ones you navigate to yourself. If a link asks for your Microsoft 365 password, stop there.
A change of bank details. Always confirm by phone, on the number you already hold for that supplier, never the one in the email.
An attachment you did not ask for. Invoices, delivery notices and scanned documents are the usual disguises. A QR code in an email is the same trick in a different shape.
An MFA prompt you did not trigger. Never approve it. It means someone already has your password. Report it the same day.
Spelling mistakes used to be the giveaway. They are not any more. Attackers write with the same tools everyone else does, so judge the request, not the grammar.
Tell us straight away. Nobody gets in trouble.
The damage of a phishing click is almost always in the hours that follow, not the click itself. Reported early, we reset the password, end the active sessions, and check what the account touched. Reported late, we are cleaning up forwarded mail and fraudulent invoices.
Raise a ticket with us, or reply to any ticket you already have open. Include the message if you still have it.
Awareness is the last line, not the first
Asking people to spot every scam is asking a lot. Most of these messages should never reach an inbox, and a stolen password should not be enough to open the door. That is configuration work: multi-factor authentication everywhere, impersonation protection tuned to your domain, and access limited to what each role needs.
