sentivaro
Home · 0%
General guidance — your organisation’s policies and procedures always take precedence.
Phishing without guessing

Don't look for mistakes. Make good decisions.

After this training, you will recognize a fraud attempt in e-mail, text message, instant messenger and telephone conversation - and if something goes wrong, you will know what to do in the first minutes.

Level: 17 lessonsPass score: 10/12 (83%)

One rule to start with

The attacker does not have to create a perfect message. All it takes is a moment of rush, routine or curiosity. Your job is not to become a detective. You are to interrupt the machine and check the request through a secure channel.

01 · Mechanism

First, pressure. Then click.

Phishing is not a spelling test. A good scam message may look error-free, know the context of the company, and come from a compromised, real account.

Haste

"Until 2:00 p.m.", "the account will be closed", "the president is waiting".

Authority

The boss, bank, human resources, administrator or well-known contractor.

Emotion

Fear, opportunity, curiosity, helping someone, or wanting to avoid trouble.

A question that makes room for reason

“Is this message trying to get me to act faster than I would normally make this decision?”

A message from the director appears on the messenger: "I'm at a meeting. Buy five gift cards urgently and send me the codes. I'll give them back when I return." What are you doing?

02 · Anatomy of a message

The sender name is label, not proof.

Message
IT
IT support
<notifications@sentlvaro-support.example>
Email access expires - confirm your account
Good morning,

We have detected a synchronization problem. To maintain access, please confirm your account within 30 minutes.

Maintain access
Link: https://konto-firmowe.secure-check.example/login
1
Expand full address

The letter "l" instead of "i", the note "support" or the real name before a foreign domain are supposed to look familiar.

2
Check the correct domain

In the address, the part immediately before the ending counts, e.g. example.com. The padlock means encryption, not the integrity of the site.

3
Don't trust context alone

The invoice number, boss's name and company footer may come from previous correspondence.

4
Enter your own way

Instead of a link, open a familiar application, bookmark or manually entered address.

The link shows "portal.sentivaro.com.safe-access.example". What domain does it lead to?

03 · More than email

The same manipulation. Another screen.

💬

SMS and instant messenger

The short form hides the details. An unknown number may use a supervisor's name and a photo from the Internet.

Phone

The number on the screen can be faked. A real IT department doesn't need your password or MFA code.

QR code

QR is a link that cannot be seen until scanned. The poster in the office can also be changed.

"It came from my friend's account"

Your friend's account may have been taken over. Judge an unusual request by the action it leads to - not just by the person on the screen.

"IT service" is calling. The caller knows your name and asks you to read the code from the application to "stop the attack".

04 · Files, logging and MFA

An unexpected document is not an obligation.

The most common sequence of events

The message promises a document → an HTML attachment or link opens a login page → the page captures the password → the scammer asks for MFA approval or uses a hijacked session.

Archives and executable files

.zip, .7z, .js, .exe, .iso and double extensions require special care. Don't try to "check" them yourself.

HTML attachment

It may look like a form or login screen. Just because a file opens in a browser does not make it safe.

Request to enable macros

A document requesting "content inclusion" should stop the process and go to review.

Unexpected MFA

Deny the request. Don't approve just to be on the safe side. Report a series of notifications as a possible password compromise.

Safe shortcut: if the message talks about a document in a known service, open that service from a saved tab. If the document is actually waiting for you, you will find it after logging in.

You expect an invoice from a supplier, but it comes as "Invoice_07.pdf.exe". What are you doing?

05 · Company and money

The most expensive phishing I don't need a link.

In Business Email Compromise, the fraudster impersonates a contractor or decision-maker. The purpose is to transfer, change the account, disclose data or circumvent the procedure.

Correspondence · reply
AK
Anna Kowalska - Orion Deliveries
<anna@orlon-dostawy.example>
RE: FV/2026/071 - new bill
As agreed, please use the new account number from the attached invoice. The old account is closing today, so payment must go out before 3:00 p.m.
Change of payment = control via a second channel

Call the number previously saved in the system or contract. Do not use the number provided in the suspicious message.

The procedure also protects you from a real boss in a hurry

Don't bypass acceptance, limits, or the two-eyes rule. Job pressure is no exception.

True scale

In a case revealed by the US Department of Justice, fake emails, invoices and documents led two large technology companies to transfers exceeding $100 million. This was not a "naive user", but a convincing imitation of a normal business process.

A regular contributor in an existing thread submits a new bank account. The message looks correct.

06 · From life

The attack works when it matches ordinary day.

Fake e-Tax Office

CERT Polska described a campaign from 2025 in which the e-mail contained an HTML file. When opened, it displayed a fake email login screen. Lesson: an official topic and a familiar screen do not confirm authenticity.

"Scanning" and "Documents for signature"

In other campaigns observed by CERT Polska, simple, office topics led to archives and malicious files. Lesson: a routine document name can be more effective than a sensational promise.

Millions by changing instructions

In 2024, American authorities described a company that sent approximately $5.4 million following a message with an address confusingly similar to the contractor's address. Quick reporting allowed the authorities to trace and secure the funds. Lesson: Independent verification saves money, and quick reporting has real value.

The common denominator

None of these attacks required magical technology. Everyone performed a familiar action: logging in, opening a document or making a payment. Therefore, your best defense is a safe way to do something, not a list of "suspicious words."

07 · Reaction

Stop. Check. Report.

1Don't follow the request
2Check another way
3Report to the company
4Tell me what happened
I just clicked

Close the page, do not enter anything and report the link immediately. The click itself does not mean failure - silence makes it harder to respond.

I entered my password or code

Contact IT/SOC immediately through a known channel. Change your password via a secure route as directed by the company; do not approve further MFAs.

I opened the file

Stop working and call support. Do not remove traces or attempt to "clean" the computer yourself. Disconnect the network in accordance with the company's procedure.

I have ordered a payment

Call your manager, finance, bank and security team immediately according to the incident plan. Minutes can be the difference between getting your funds back.

The company needs a quick report, not a guilty one. A good safety culture does not embarrass the employee. By reporting, you can warn others, block the domain and limit the consequences.

You entered your password on the website from the link, and after a while you noticed a foreign domain. What is the first right decision?

Final exam

12 decisions. No tricks.

To pass: at least 10/12 answers and all four critical questions. After checking, you will see explanations.

Your result

We check the answers

Certificate of Completion

Phishing without guessing

The participant has completed this training and demonstrated the ability to recognise, verify and respond safely to phishing attempts.

This certificate confirms the skills demonstrated during the training; it does not guarantee protection against every future attack.