Guide · Data security

Recognising phishing: six signs that always hold true

Fake invoices and CEO fraud are getting better. How to recognise them anyway – and what to do if someone has clicked.

By Dipl.-Ing. Mohamed Khater, Founder and Managing Director, since 1992 · · 8 min read

Reliable

Six signs that always hold true

Spelling mistakes and clumsy greetings stopped being a giveaway long ago – fake emails are now written with the same tools as genuine ones. These six points still apply.

  • Time pressure. "Within 24 hours", "final reminder", "your account will be blocked". The pressure is meant to stop you from thinking or asking. Genuine business partners rarely set deadlines of a few hours.
  • A transaction you did not initiate. An invoice for something you did not order. A parcel notification without an order. A password change you did not request.
  • A request to enter your login details. No reputable provider asks for this via a link in an email. If you want to check whether something is genuine, type the address in yourself – do not click.
  • The actual sender address. The display name can be anything. What matters is what comes after the @ – and whether it matches the company it claims to be. On a phone this is often hidden and has to be expanded.
  • The actual link target. Hover the mouse pointer over the link without clicking. The address appears at the bottom of the window. Pay attention to the part immediately before the last slash – that is where the real domain is.
  • Changed bank details. This is the most expensive sign. An invoice from a known supplier with a new account number is never confirmed by email, but by phoning the number you already have on file.

What actually causes damage

Three scams that really hit businesses

Classic mass mailings rarely cause much damage. These three variants are targeted – and that is why they are expensive.

CEO fraud

An email apparently from management to the accounts department: urgent bank transfer, confidential, please do not discuss with colleagues. Often sent during a business trip, because follow-up questions are less likely then.

  • The request for confidentiality is the warning sign
  • Fixed rule: above amount X, always call back

Invoice fraud

A genuine invoice from a genuine supplier – only the bank details have been changed. This becomes possible when someone has access to a mailbox and is reading along with ongoing correspondence.

  • Always verify changes of account by phone
  • Use the number from your own records, not from the email

Credential theft

A replica sign-in page for Microsoft 365. Anyone who enters their password and two-factor code there gives attackers access to their mailbox – usually unnoticed for weeks.

  • Starting point for the two scams above
  • Never sign in via a link in an email

If it has happened

Someone has clicked – what to do now

The most common reaction is to stay silent out of embarrassment. That is the most expensive reaction. Take these steps, in this order:

  1. Report it immediately, without blame

    Whoever reports it limits the damage. Whoever stays silent for fear of getting into trouble extends the time during which someone can read along unnoticed. This should be communicated explicitly – beforehand, not afterwards.

  2. Change the password, but not from the affected computer

    If malware may have been installed, the new password will be captured too. Use a different device.

  3. End active sessions

    Changing the password does not automatically end existing sign-ins. In Microsoft 365, sessions have to be revoked explicitly.

  4. Check mailbox rules

    An attacker's first step is usually a rule that moves incoming messages from certain senders into a folder or forwards them. That way the access goes unnoticed.

  5. Review the sign-in log

    Where and when did the sign-ins take place? Sign-ins from abroad or at unusual times show whether – and since when – someone had access.

  6. Assess whether a notification is required

    If personal data is affected, the 72-hour deadline under Article 33 GDPR may apply. Document this assessment – even if you conclude that no notification is required.

Frequently asked questions

What we are often asked about this

Doesn't two-factor authentication protect against this?

It helps considerably, but it is no guarantee. Replica sign-in pages now ask for the two-factor code as well and pass it on in real time. The trick of bombarding someone with approval requests until they give in out of sheer annoyance also works.

Methods that are bound to the device – such as passkeys or security keys – are considerably more secure. They cannot be harvested through a fake page.

Are simulated phishing emails to our own staff worthwhile?

If used correctly, yes. Used wrongly, they do harm: if you expose employees or let click rates feed into performance reviews, the result is that nobody will report a real incident in future.

What makes sense is evaluating results for the group, not for individuals, and a short explanation immediately after the click rather than a round-robin email weeks later. In Germany, the works council (Betriebsrat) must be involved.

How do we recognise a fake invoice from a genuine supplier?

Most likely by the changed bank details – and otherwise often not at all, because the invoice is genuine and has merely been intercepted. That is why the rule matters more than spotting it: every change of account details is confirmed by phone, using the number from your own records.

This rule should be written down and binding for everyone, including management.

Should we forward suspicious emails?

Yes, but as an attachment, not as a normal forward. Forwarding loses the technical headers that show where the email really came from. Set up a shared address for this that anyone can send to without having to ask first.

Dipl.-Ing. Mohamed Khater

Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992. The three scams described here are the ones that actually cause damage to small and medium-sized businesses in the Rhineland – not the ones that get written about the most.

Further reading

Free security check

How well protected is your mailbox?

We check two-factor sign-in, mailbox rules, forwarding and sign-in logs – and in the process we often find access that nobody knew about.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement