Microsoft is retiring SMS and voice MFA. Passkeys become the default on 1 September 2026; SMS and voice switch off on 1 February 2027. Book your free health check
IT Next Door
โ† All insights
Awareness ยท 4 min read

Stop. Look. Think.

Protect yourself from online scams. Spot the signs. Spot the crimes.

A hand resting on a laptop trackpad, paused before clicking

Always remember: Never click on links or open attachments in an email that you weren’t expecting. This single rule will help you avoid many common hacker tactics.

Attacks succeed on speed. A message arrives, it looks routine, and the click happens before the thinking does. Three seconds of attention is usually all it takes to break the chain.

The three steps

Stop

Urgency is the tactic. A deadline, a threat, a payment that must go out today. Put the mouse down first.

Look

Check the sender’s full address, not the display name. Hover a link and read where it really goes.

Think

Were you expecting this? Would this person normally ask you this way? If not, verify on a channel you chose.

Five signs worth a second look

01

A domain that is almost right. One extra letter, a hyphen, or .co instead of .com. Read the part immediately before the first single slash.

02

A login page you arrived at by clicking. Real sign-in pages are ones you navigate to yourself. If a link asks for your Microsoft 365 password, stop there.

03

A change of bank details. Always confirm by phone, on the number you already hold for that supplier, never the one in the email.

04

An attachment you did not ask for. Invoices, delivery notices and scanned documents are the usual disguises. A QR code in an email is the same trick in a different shape.

05

An MFA prompt you did not trigger. Never approve it. It means someone already has your password. Report it the same day.

Spelling mistakes used to be the giveaway. They are not any more. Attackers write with the same tools everyone else does, so judge the request, not the grammar.

If you already clicked

Tell us straight away. Nobody gets in trouble.

The damage of a phishing click is almost always in the hours that follow, not the click itself. Reported early, we reset the password, end the active sessions, and check what the account touched. Reported late, we are cleaning up forwarded mail and fraudulent invoices.

Raise a ticket with us, or reply to any ticket you already have open. Include the message if you still have it.

Awareness is the last line, not the first

Asking people to spot every scam is asking a lot. Most of these messages should never reach an inbox, and a stolen password should not be enough to open the door. That is configuration work: multi-factor authentication everywhere, impersonation protection tuned to your domain, and access limited to what each role needs.

See how Zero Trust closes the gap Talk to us More insights โ†’