Phishing Attempts
Recognize, resist, and report deceptive messages.
Available now →Practical cybersecurity training
Build the everyday habits that protect you, your colleagues, and your organization—one clear, practical lesson at a time.
Your learning path
Start with the threats most likely to reach your inbox, then build the habits that protect every part of your digital workday.
Recognize, resist, and report deceptive messages.
Available now →Create stronger access habits and keep accounts secure.
Next moduleUse laptops, phones, and shared devices safely.
Learning pathHandle, share, and store sensitive information with care.
Learning pathModule 01
Blocking external threats
Phishing is a deceptive message designed to make you click, share information, or take an action that benefits an attacker.
Recognize phishing emails
and fake links
A phishing email can look professional, use a familiar logo, and even include your name. Its real goal is to trigger a fast reaction before you notice what is wrong.
Hello Jordan, we were unable to process your benefits enrollment. Please review the attached form and sign in with your work account before 12:00 PM.
Thank you,
Payroll Services
https://login.microsoft.com.security-check.example.net/verifyThe true owner is immediately before the first slash: example.net, not microsoft.com.
Warning signs
of phishing
“Act now,” “final warning,” or threats of account closure.
Passwords, gift cards, payments, files, or confidential information.
A familiar name paired with a misspelled or unrelated email domain.
Generic greeting, odd phrasing, or a tone that does not fit the sender.
Link text looks safe, but hovering reveals a different website.
An invoice, QR code, shared file, or document you were not expecting.
Use a saved bookmark, company portal, or known app instead of the message link.
Call a known number or start a new message. Do not use contact details provided in the suspicious email.
A legitimate support person should never ask for your password or multi-factor authentication code.
Report attempts
promptly
Reporting protects everyone
You do not need to prove that a message is malicious. Report anything suspicious so the right team can investigate and warn others.
Do not click again, reply, download, forward, or delete the message.
Select your email client’s “Report phishing” button or contact your IT/security team through the company’s known channel.
If you clicked, downloaded, replied, or entered information, say so clearly. Honest details help responders act quickly.
Disconnect only if your organization instructs you to. Contact security immediately, keep the message, and follow their password or device guidance.
Module summary
Resist urgency. Take a breath before acting.
Check the sender, request, link, and context.
Use a separate, trusted route to confirm.
Send it to the right team—even if unsure.
Knowledge check
Choose the safest response. You’ll see an explanation after every answer.