Is That Email a Phishing Scheme?

Research has revealed that over half of all users end up opening fraudulent emails and often even fall for them. Phishing is done with the aim of gathering personal information about you, generally related to your finances (or your business and its finances). The most common reason for the large number of people falling for fraudulent emails is that the phishing attempts are often so well-disguised that they escape the eyes of a busy email reader.

Here are a few tips that help you identify whether that email really came from your bank or is another attempt at defrauding you via a phishing email.

1. They are asking for personal information – Remember, no bank or financial institution asks you to share your key personal information via email, or even phone. So, if you get an email where they ask for your ATM PIN or your e-banking password, something’s amiss.

2. The links seem to be fake – Phishing emails always contain links that you are asked to click on. You should verify if the links are genuine. Here are a few things to look for when doing that:

  • Spelling – Check for the misspellings in the URL. For example, if your bank’s web address is www.bankofamerica.com, a phishing scheme email could misspell it as www.bankofamarica.com or www.bankofamerica-verification.com
  • Disguised URLs – Sometimes, URLs can be disguised…meaning, while they look genuine, they ultimately redirect you to some fraudulent site. You can recognize the actual URL upon a mouse-over, or by right clicking on the URL, and selecting the ‘copy hyperlink’ option and pasting the hyperlink on a notepad file. But, NEVER ever, paste the hyperlink directly into your web browser.
  • URLs with ‘@’ signs – If you find a URL that has an ‘@’ sign, steer clear of it even if it seems genuine. Browsers ignore URL information that precedes @ sign. That means, the URL www.bankofamerica.com@mysite.net will take you to mysite.net and not to any Bank of America page.
3. Other tell-tale signs – Apart from identifying fake URLs, there are other tell-tale signs that help you identify fraudulent emails. Some of these include:
  • Emails where the main message is in the form of an image, which, upon opening, takes you to the malicious URL.
  • Another sign is an attachment. Never open attachments from unknown sources as they may contain viruses that can harm your computer and network.
  • The message seems to urge you to do something immediately. Scammers often induce a sense of urgency in their emails and threaten you with consequences if you don’t respond. For example, threat of bank account closure if you don’t verify your ATM PIN or e-banking password.

It is vitally important that businesses make sure that their employees are trained to be able to identify phishing emails so that their sensitive data is not obtained, or worse. Rent-A-Nerd, Inc. offers cybersecurity training, which specifically includes secure “phishing emails” sent to all employees (the emails are safe, but are set up with some of the subtle signs that they are phishing emails) to track who is opening them, clicking the links, and more. Followup training is conducted on an ongoing basis to keep your business and its data as safe as possible. Call us to find out more. 504-301-1094.

 

 

Categories

Related Posts

AI Security and compliance

AI Security and Compliance: How Businesses Can Adopt AI Without Losing Control

AI security and compliance isn’t one-size-fits-all. Your obligations depend on your industry, location, and the types of data you handle. However, most businesses need to consider a few key areas. Data privacy laws vary by region and industry. The EU’s GDPR sets strict rules around how personal data is collected, stored, and processed. U.S. states like California, Virginia, and others have passed their own privacy laws. If you serve clients or customers in these regions, you likely need to comply. These laws often require that data be processed securely, that individuals have rights over their data, and that any third parties you work with (including AI vendors) meet security standards.

Read More »
AI Use Policy

How to Create an AI Use Policy for Your Business: A 9-Step Guide

Many business owners assume their existing IT security policies cover AI. They don’t. Traditional policies were written for email, file storage, and software licenses, not for tools that learn from data, generate content, and operate across public cloud platforms.

An AI use policy fills that gap. It clarifies which AI tools employees can use, which data they can input, and what guardrails apply to different roles and departments. More importantly, it demonstrates due diligence if something goes wrong. If a client’s confidential information ends up in a public AI model because an employee didn’t know better, your policy proves you took reasonable steps to prevent it.

Read More »