Yes, there are a couple of techniques to identify a phishing email.
Phishing emails are emails designed to look as if they are from a legitimate and trusted source. The main goal of a phishing email is to get you to do something. That something could be to either click on the link in the email or open the email attachment. Either one could result in malware, software with malicious intent, ending up on your electronic device. All of this happens without your knowledge.
To help you determine if an email is a phishing email or a legitimate email here are a few tips to remember.
- Sender’s email address does not match the source of the email (Source says “Florida Department of Motor Vehicles” but the senders email address is johndoe@yahoo.com).
- Poor spelling and grammar (misspelled words or grammar that does not make sense).
- Generic language (begins with “Dear Customer”).
- Won a contest or lottery (to win a contest or lottery you must first participate in the contest. Simply having an email address or using the Internet does not qualify as entering a contest).
- Sense of urgency (Click to reinstate your account or click to prevent your account from being suspended).
- Illegitimate link (Hover your cursor over the link to reveal the true destination).
- Attachments from unknown sender (malware can be hidden image, document and presentation files).
Log in to verify
When you receive an email organization you currently do business with, such as your bank or credit card, there is a simple way to test the validity of the email. Log in to your account.
Once you have logged in to your account you will be able to check for any messages or warnings.
Remember, do not click on the link in the email address. You will need to go directly to the company’s website by typing in the URL.
A few years ago, I received a supposed email from Amazon.com regarding delivery of a recent purchase. I knew I did not order anything but I wanted to make sure no one had hacked my Amazon account. I logged into my Amazon account and looked under order history. No recent orders were listed so I knew the email was a scam.
Spear phishing
People often tell me they only open email from people they know. Just because the email comes from someone you know does not mean that person actually sent it. This is known as spear phishing.
Spear phishing emails work because they appear to come from a person of trust such as a friend, relative or co-worker. The purpose of spear phishing emails is to either harvest connections, who do you know and who knows you, or to install malware through links and attachments.
The best defense against spear phishing is to contact the person that supposedly sent the email and ask him if he sent it. In other words, when you receive an unsolicited email from a trusted source that contains a link or attachment pick up the phone and call the person before clicking.
If you are unable to call the person simply send them an email. Draft a new email, do not reply to the suspect email, and ask the person if they sent you an email. If neither is an option delete the email. If the email was legitimate and crucial the sender will find another way to contact you.
Carrie Kerskie is a sought-after speaker, trainer and consultant on identity theft and data privacy. She is the author of “Your Public Identity: Because Nothing is Private Anymore.” Kerskie is the director of the Identity Fraud Institute at Hodges University and president of Kerskie Group Inc. You can contact her at 239-435-9111 or ckerskie@hodges.edu. Follow her on Twitter@CarrieKerskie.com.
