Skip to main content

How to spot a phishing email


Courtesy of Gene Sorkin, Associate Director of Information Technology Support, here are some telltale signs to look for the next time an email that smells phishy hits your inbox. 
  • Keep an eye out for misspellings, such as legitimate business names that are missing or off by just one or two letters. Additionally, an unexpected email from an address that you never communicated with before is a good early sign of a possible scam.
  • Subject lines containing too-good-to- be true offers or threatening statements meant to elicit an emotional reaction are clues that someone’s trying to phish you.
  • Watch out for mass email sends or unexpected emails to email aliases like the example below.
  • Any messages addressed generically, especially ones regarding financial transactions are suspicious.
  • Extreme caution should be exercised with any link appearing in an unexpected or unsolicited email. Hover over the hyperlink text to see where the URL would actually direct you if clicked. Scammers will also try to implant real business names in fake URLs.
  • Phishing emails can take many forms, whether it's threatening legal action or telling you an unexpected package has arrived.  Be on the lookout for demands to click, free offers, bad grammar or misspelled words.
  • In all circumstances, unexpected attachments should not be opened.
Here is an example of a scam email, take a look at the items outlined in orange:





The signs above are good overall points to look for when scrutinizing a suspicious email. However, they do not represent all ways in which scammers will attempt to phish you or other employees. That’s why a separate but vitally important way of spotting a phishing email is to email CCITECHSUPPORT@nycourts.gov.

If an email just feels off for any reason, that’s enough to be wary of it. A healthy dose of security awareness, with some skepticism and situational awareness thrown in, can go a long way.

Comments

Popular posts from this blog

Listing a meeting attendee as optional vs. required

When sending an Outlook calendar invite out, you can select who is required to attend vs. who is optional to attend.   When you open a new meeting invite, first add attendees in the "To" field.  Then click on "Scheduling Assistant" in the top navigation bar. When in Scheduling Assistant, to the left of each person's name, you'll see a small icon.  This shows that the attendee is currently listed as "Required" for this meeting. When you click on this icon a drop down menu will appear.  Here you can change the status for this person to "Optional". You'll see the icon by the attendees name has now been changed. For any invite you can have a mixture of Required and Optional attendees, just change the icon for each person to the appropriate status.

Creating your new branded e-mail signature!

As part of our  branding efforts, the Center wants all staff to use the same format for signing e-mails – also called an “e-mail signature.” To make sure these e-mail signatures are consistent, we have created a Signature template webpage . Use this page to create your own e-mail signature, complete with your operating program logo. which you can then easily copy and paste into any e-mail program so it automatically appears at the end of your emails.   Do not use these logos for any other purposes.  E-mail smeah@nycourts.gov to get high-quality logos. Here are detailed video instructions, as well as overview instructions, to use the template for Desktop Outlook, web Outlook, and Gmail (which includes the courtinnovation.org account). See the bottom of this post for mail app instructions on your phone.  You can also print out these instructions (Ctrl+P). Questions or issues?  E-mail CCI Tech Support for extra help! Desktop Outlook Clicking Fi...

Creating online forms and spreadsheets

Two online services to collaboratively collect data, and manipulate it, are Google Forms and Airtable.  Unsecure forms such as Google and Airtable are helpful to: Collect food preferences for an upcoming event or large meeting Get additional information from people attending a training on what their goals or skill level is Collect feedback after an event Get clothing sizes for the swag you are going to order Note: These forms should never be used with clients because they are not a secure way to collect data  and  all research projects involving clients should be reviewed by the Center’s Institutional Review Board.  If you are interested in conducting research or data collection from clients, always contact  CCI_IRB@courtinnovation.org  first or the researcher assigned to your operating project.  Google Forms , which all CCI staff have access to, allow you to easily create forms to send to CCI staff, collect data, and have the dat...