Recognizing phishing: seeing through attacks and responding correctly
Phishing does not target technology, it targets people. This guide shows which psychological levers attackers use, which channels attacks run through today, how to check for forgeries in concrete terms, what to do immediately after a click, and how to prepare your team without singling anyone out.
This article provides general information and is no substitute for legal advice. For binding answers on your situation, consult a law firm.
Why phishing works: the psychology behind the attack
Phishing is the attempt to use forged messages to get people to hand over credentials, money, or confidential information. The attack is therefore not aimed at a technical weakness but at human patterns of reaction. That is exactly why a good firewall is of little help when an employee under time pressure clicks a convincingly designed link. If you want to recognize phishing, you first have to understand which levers attackers use.
Three levers appear in almost every phishing message. First, pressure: a deadline is expiring, an account is supposedly being locked, a payment is failing. Under time pressure, people check less carefully. Second, authority: the message appears to come from the bank, a public authority, or your own management. In a technique known as CEO fraud, attackers pose as senior management and demand a supposedly urgent, confidential transfer. Third, curiosity or helpfulness: an unexpected job application, a parcel notification, a request for a small favor. All three levers aim to make the recipient act before thinking.
An important point for how to frame this in your company: falling for phishing is not a question of intelligence or experience. The messages reach people in the middle of the working day, between two appointments, often on a smartphone with a small screen. In that moment, well-made forgeries are almost indistinguishable from genuine messages. This insight is the basis for everything that follows, especially for how you deal with employees who have clicked.
Current scams: no longer just by email
The classic phishing email still exists, but in our observation its quality has changed considerably. Spelling mistakes and clumsy wording, long the most important warning sign, have become rarer, partly because attackers can now generate text by machine in flawless German. In our observation, some attacks even insert themselves into genuine, already ongoing email threads: the attackers have previously taken over the mailbox of a business partner and reply there to existing conversations. Such a message inevitably appears trustworthy.
Then there are channels beyond email. In what is known as quishing, the malicious link is hidden in a QR code, the square pattern you scan with your phone camera. That is doubly convenient for attackers: many mail filters examine images less thoroughly than links, and the recipient does not see the destination before scanning. QR code fraud can also occur physically, for example through stickers pasted over codes on parking machines or charging stations. Text messages have their own variant, smishing: fake parcel notifications, supposed bank warnings, or messages from a supposedly new number of a family member.
The telephone is also back in the attackers’ toolbox. In vishing, phishing by phone call, someone poses as IT support, a bank employee, or a colleague and asks for credentials or for confirmation of a login. There are also warnings about cases in which voices were imitated with AI tools, for example the voice of a superior. How often such attacks actually occur is hard to quantify reliably. The practical consequence is nevertheless clear: a familiar-sounding voice on its own is no longer proof of identity. Always verify unusual requests on the phone by calling back on a number you know.
The concrete check: four points anyone can verify
The first check is the sender address. Mail programs initially show only the display name, which the sender can choose freely. What matters is the actual address behind it, which you can reveal by clicking or tapping on the name. Read the domain, the part after the @ sign, letter by letter: attackers use swapped characters, additional words, or similar-looking endings. A message from your bank sent from a freely registerable address at a public email provider is practically always fake.
The second check is the links. On a computer, hover the mouse pointer over the link without clicking. The actual destination then appears at the bottom edge of the window. On a smartphone, press and hold the link instead of tapping it, and the device shows the destination address in a preview. What counts is the actual domain immediately before the first single slash, not some familiar company name elsewhere in the address. For short links that obscure the destination, and generally whenever in doubt: type the provider’s address into the browser yourself or use your bookmark instead of following the link.
The third and fourth checks are the salutation and the means of pressure. An impersonal salutation such as “Dear customer” is a warning sign in supposedly important account matters, as is a misspelled name. Even more telling is the pressure applied: are you threatened with account suspension, fees, or legal consequences if you do not act immediately? Does the request deviate from the usual process, for example changed bank details of a supplier, gift cards as a means of payment, or a request for absolute confidentiality? For such cases, a fixed rule should apply in your company: changes to payment and master data are always confirmed via a second, independent channel, for example by calling the person on a number you already know.
What a click sets in motion and why every minute counts afterwards
A click alone is rarely the catastrophe. In most cases, the link leads to a replica login page designed to harvest credentials. It only becomes dangerous when a username and password are actually entered there. There are attack tools that position themselves in real time between the victim and the genuine login page and also intercept the second factor of multi-factor authentication, the additional confirmation of the login via an app or a one-time code. Multi-factor authentication nevertheless remains a very effective protective measure; it is just not a license for careless clicking.
The second route runs through attachments and downloads. An Office document with macros enabled, small embedded programs, or an executable file disguised as an invoice can install malware. This often initially gives attackers nothing more than inconspicuous remote access. The actual damage, such as data theft or ransomware, the encryption of your data followed by a ransom demand, often comes only days or weeks later, after the attackers have explored the network at their leisure.
From this sequence follows the most important message of this article: there is almost always a window of time between the click and the damage. Anyone who reports a mistake immediately gives IT the chance to reset passwords, isolate devices, and stop the attack before it spreads. A quick report is therefore worth more than a perfect score of unclicked test emails.
When it happens: the right steps after a click
If credentials were entered on a fake page: change the affected password immediately, everywhere the same or a similar password is used. Sign out the account’s active sessions if the service offers that. In parallel, inform your IT team or your IT service provider, without delay and without playing the incident down. If a suspicious file was opened, disconnect the device from the network, that is, disable Wi-Fi or unplug the network cable, and leave it switched on so that traces remain available for analysis.
For IT managers, several checks are then standard: review the sign-in activity of the affected account, search the mailbox for newly created forwarding or deletion rules, which attackers like to set up inconspicuously, check who else in the company received the same email, and remove it centrally from the mailboxes. Depending on the findings, password resets for further accounts and a closer examination of the affected device follow.
If money has already been transferred, contact your bank immediately. With a very fast response, a transfer can sometimes still be stopped. File a report with the police, which in many German federal states is also possible online. And clarify whether personal data could be affected: in that case a notification to the data protection supervisory authority may be required, and short deadlines apply. Involve your data protection officer for this.
Training your team without singling anyone out
One very effective measure costs nothing: a culture in which reporting a suspicion or one’s own mistake is explicitly welcome. Anyone who fears ridicule or sanctions reports late or not at all, and that is exactly when the major damage occurs. Define a simple reporting channel, for example a fixed internal address or a report button in the mail program, and say thank you for every report, including false alarms. A false alarm is a sign of attentiveness, not of carelessness.
Phishing simulations, internally commissioned test emails, can be useful if they are set up correctly. Announce the program as such without revealing individual dates. Evaluate results only in aggregate: no name lists for managers, no notice board, no being called out in front of the team. Anyone who clicks lands on a short, friendly explanation page and gets a minute of learning material instead of a reprimand. Also avoid lures that destroy trust, such as fake messages about pay raises or dismissals. Tests like that create resentment instead of vigilance.
To be honest about it: you can build the reporting channel, basic rules, and short, regular awareness sessions internally yourself. For the technical side, that is, mail filtering, multi-factor authentication, and the analysis in an incident, as well as for professionally designed simulations, external support is usually more efficient, especially if there is no dedicated IT security role in-house. The order matters: first a reporting culture and baseline protection, then simulations. If you test before a safe reporting channel exists, you are mainly measuring frustration.
The short version
Phishing targets people under time pressure, not inattentive individuals. If you know the typical levers, consistently check senders and links, and can report suspected cases without fear, you take the sting out of most attacks. The decisive factor is the window of time after a click: fast reporting, fast response. If you do not want to build reporting channels, training, or the technical safeguards on your own, Ruknova, based in Schwerin, supports you, Germany-wide and available Mon-Fri 8 am to 4 pm.