Never click on links in emails! Never open an email that seems strange to you! Never reply to an email from a sender you don't know! These are all warnings that we hear over and over again about phishing emails, but what exactly are phishing emails and how can you tell whether an email is a phishing email or not?

What is phishing and what is a phishing email?

The word Phishing  is derived from the English terms „Password Harvesting (the collection of passwords) and fishing“ i.e., „Fishing for Passwords“. It describes the attempt to steal other people's personal data using fake emails, websites, profiles, or even manipulated phone calls and voices. Often, several of these methods are combined.

Cybercriminals pose as trustworthy individuals or organizations and try to trick their victims into voluntarily disclosing sensitive data such as passwords, credit card numbers, or login details.

Phishing emails are emails sent by hackers who pretend to be someone the victim knows or a company in order to gain their trust and steal personal data.

How can you recognize phishing emails?

Nowadays, phishing emails are quite difficult to distinguish from genuine messages. Unfortunately, simply looking out for spelling mistakes, strange sentence structure, missing personal salutations, or poor writing style is no longer sufficient. Due to new technology, more attention must be paid to details.

The first and most important thing to check when an email seems strange is the sender. It is not enough to just see if you know the sender's name, because even that could be fake. You have to check the email address very carefully: read it letter by letter and compare it with the original address. You should also ask yourself whether it is normal for the sender to send an email at all.

In some cases, you may be familiar with the company, but have never contacted them by email. In this case, it is advisable to make a note of which companies you have given your email address to. In general, you should try to avoid giving out your email address. This not only saves you unnecessary advertising in your spam folder, but also allows you to keep track of your emails and immediately recognize whether a message is a phishing email or not.

Another point to consider is the language. For example, if you receive an email in English, you should check it carefully for phishing, especially if you normally only receive emails in German.

Now we come to the points that most characterize a phishing email. Such emails very often describe a problem that supposedly requires urgent action. Whether it's an unknown password reset, the closure of a bank account, or a job offer, all variants want you to react quickly and offer a direct link or a form in the attachment, seemingly very "helpfully."

Threats or deadlines are used to put pressure on the victim so that they don't think twice and click on the link or download the document straight away. Once that happens, the "fish is caught" and the phishing email has worked. Every phishing email always contains at least one of these elements: a link, an attached document, or a place to enter and return personal data. Without at least one of these elements being clicked or opened, the attacker cannot collect any data.

Pure text emails do no harm as long as no links are clicked or attachments opened. Emails in HTML format are an exception. Here, simply opening the email can cause damage. It is therefore advisable to disable the receipt of emails in HTML format.

When checking the sender, it is advisable to look at the complete header. Even if the email address appears trustworthy at first glance, the sender's IP address may be fake. However, this check requires technical knowledge and is quite time-consuming. Nevertheless, if you follow the above points, you can reliably determine whether an email is a phishing email or not in most cases.

Phishing email detected

If you recognize a phishing email, you should delete it immediately, including from the trash folder, so that you don't accidentally click on it later. Very important: Do not reply to the email! This will alert the hacker that the email address is active, and you will receive more and more phishing emails.

Consumer protection agencies recommend forwarding phishing emails before deleting them. The email can be sent to the following address:
phishing(at)verbraucherzentrale.bw bzw. phishing@verbraucherzentrale.{bundesland-kürzel} .

Victim of a phishing email – what should you do?

Important: Don't panic and don't delete the phishing email! It will be needed later as evidence for the police.

The first step is to disconnect the device from the internet and check the system for malware. If the scanner finds anything, all passwords should be changed immediately, especially those for email accounts, online banking, and other sensitive services. It is best to use long and secure passwords.

Next, back up all important data, for example by creating backup copies on external hard drives or USB sticks.

If damage has already been done, file a criminal complaint with the fraud department of your local police station immediately. If in doubt, you can also contact the police's online advice center for information.


Related news

Blog

Cyber risks in the financial sector The digitization of the industry is advancing rapidly and…
Blog

Attack on the Canadian House of Commons Threat Actor exploited a recently discovered Microsoft…
WAS IST DIESE WOCHE IN DER HACKING-WELT PASSIERT?
Blog

US court system hacked - witness information compromised A targeted attack on the US federal court…