How to Spot and Report a Phishing Email
Phishing emails are the single most common way attackers get into a business. Spotting them takes a moment; the damage from clicking one can take weeks to undo.
What to look for
Section titled “What to look for”- Urgency or pressure — “Your account will be suspended in 24 hours,” “Pay this invoice immediately.”
- A sender address that doesn’t quite match — check the actual email address, not just the display name (e.g.
accounts@micros0ft-billing.com). - Unexpected attachments or links, especially from people you weren’t already expecting to hear from.
- Requests that bypass normal process — a “CEO” asking you to buy gift cards, or change a supplier’s bank details by email alone.
- Generic greetings (“Dear Customer”) on something that claims to be personal or urgent.
What to do the moment you’re unsure
Section titled “What to do the moment you’re unsure”- Don’t click anything — links or attachments — until you’ve checked.
- Don’t reply to the sender, even to ask if it’s genuine.
- Report it using the steps below.
- If you’ve already clicked a link or opened an attachment, report it immediately anyway — speed matters far more than avoiding embarrassment.
Reporting an email
Section titled “Reporting an email”- Use the Report Message button in Outlook or the Mail app, if available — this sends it straight to your IT team for review.
- If that button isn’t available, forward the email as an attachment to security@faraday-it.co.uk.
- If you’re not sure whether to report something, report it anyway — false alarms cost nothing, missed real ones cost a lot.
If you already clicked something
Section titled “If you already clicked something”Contact support immediately by phone rather than email — we’ll walk you through securing the account and check whether anything else needs attention. There’s no penalty for reporting quickly; the only bad outcome is not reporting at all.