What you will learn
- recognise common signs of phishing;
- inspect senders, links, attachments and QR codes;
- verify requests involving money, data or sign-in;
- respond to unexpected MFA prompts;
- report an attack and limit damage after a mistake.
Why phishing works
Attackers try to make people reveal credentials, approve a sign-in, transfer money, open a file, scan a QR code or install software. AI makes polished and personalised messages easier to create, so perfect spelling is no proof of authenticity.
Sources: ENISA Threat Landscape 2025 and CERT Polska, June 2026.
Emotions attackers exploit
Pressure + secrecy + an unusual request is a particularly strong warning.
Warning signs
Sender
- inspect the full address, not the display name;
- look for changed letters;
- notice a sudden change in writing style.
anna@company.com
anna@cornpany.comMessage
- threats, urgency or secrecy;
- a changed bank account;
- requests for passwords, MFA or remote access.
Link
- preview it without clicking;
- read the real domain from the right;
- a padlock does not make a site honest.
microsoft.customer-help.exampleAttachment and QR
- do not enable macros or editing;
- beware ZIP, HTML and executable files;
- do not sign in through an unexpected QR.
MINI CHALLENGE
How many red flags can you spot?
Reveal the answer
At least six: a lookalike domain, urgency, secrecy, an unusual request, bypassing procedure and blocking independent verification.
STOP — CHECK — REPORT
STOP
Do not click, reply, scan the QR code or open the attachment.
CHECK
Call a known number, start a new message or open the official app. Never use contact details supplied in the suspicious message.
REPORT
Use your organisation’s reporting button or contact IT. Keep the message available for analysis.
Money, data and identity
Independently verify bank-detail changes, urgent payments, gift cards, cryptocurrency, customer lists and every request to bypass approval. Voice, video and writing style can be forged with AI.
- call back using a number you already know;
- apply the four-eyes principle;
- follow formal approval even for an apparent executive request.
Passwords, passkeys and MFA
Use unique passwords and an approved password manager. Never enter credentials after following an unexpected message or share an MFA code. Phishing-resistant FIDO/WebAuthn, such as a passkey or security key, offers the strongest protection.
What if you clicked?
I only opened the link
Close the page, download nothing and tell IT the time and device involved.
I entered credentials or an MFA code
Report it immediately, change the password through the official site, update reused passwords and sign out unknown sessions.
I opened a file or installed software
Stop using the device, preserve evidence and follow your IT team’s instructions.
I transferred money or shared card data
Contact the bank and your organisation immediately, preserve evidence and report suspected crime.
Silence is the worst response. A fast report can stop an attack. Mistakes should lead to support and learning, not blame.