+254 (0) 786765007
Call
+254 (0) 786765007

HIT Blog

How to detect and what to do with phishing emails

Phishing emails are one of the most common cyber threats today.
The objective is usually to induce you to take an action like change your password and once you do that they gain access to your email. Here’s a clear guide on how to detect them and what to do if you receive one:

🔍 How to Detect a Phishing Email
Look out for these warning signs:
  1. Suspicious Sender
    • The email address looks unusual (e.g., support@amaz0n.com instead of support@amazon.com).
    • The display name may look legitimate but the actual address doesn’t match.
  2. Urgency & Fear Tactics
    • Phrases like “Your account will be suspended immediately” or “Act now to avoid losing access” push you to act quickly without thinking.
    • Unusual Requests
      • Asking for sensitive info like passwords, bank details, or verification codes via email (legitimate companies never do this).
  3. Suspicious Links or Attachments
    • Links may look real but actually redirect to a fake site. (Hover over the link without clicking to preview the real URL.)
    • Attachments with unusual extensions (.exe, .zip, .scr, etc.) may contain malware
  4. Generic Greeting
    • Phishing emails often say “Dear Customer” instead of using your real name.
  5. Spelling & Grammar Errors
    • Poor spelling, grammar mistakes, or awkward phrasing can indicate a fake email.

âś… What to Do If You Get a Phishing Email
  1. Don’t click links or download attachments.
  2. Don’t reply to the email
  3. Mark as Phishing / Spam:
    • Use your email application “Mark as spam” option.
  4. Delete the email immediately.
  5. If you clicked the link or gave out information:
    • Immediately change your passwords.
    • Monitor your accounts for unusual activity.
  6. Verify directly:
    • If the email claims to be from your bank, Amazon, PayPal, etc., go directly to their official website or call their verified number.

🚨 Extra Tips for Safety
  • Always use strong, unique passwords for different accounts.
  • Keep your antivirus and operating system updated.
  • Use a password manager to detect fake login pages.
  • Be cautious with emails that come from unexpected sources, even if they look professional.