Staying Safe Online pt. 1: Spotting Phishing Attacks
A few days before Christmas, employees of the web-hosting company GoDaddy received an email containing a link to claim a $650 bonus. Unfortunately for the employees, the email was fraudulent and there was no bonus. GoDaddy sent out this fake email which pretended to be real to test how it’s employees respond to a type of attack called “phishing”.
Phishing is a type of “social engineering” attack, meaning that it targets humans instead of machines. A phish email or text seems legitimate and usually contains either a link to a malicious website, or a malware file for the target to download. Luckily there are often telltale signs that an attempt is not legitimate.
- Impersonal Greeting: Attackers often send these emails in bulk, and do not greet every person individually. A typical phish will start with “dear sir/madam” instead of “dear <name>”
- Spelling Mistakes: Phishing messages often contain multiple spelling/punctuation/grammatical mistakes, as well as formatting mistakes.
- Incorrect URL: A common method of phishing includes sending the target a link to a spoofed login page. At first the link may look legitimate, but on further inspection you may find it is not. Look for spelling mistakes or incorrectly formatted URLs (www.example.realbank.com belongs to realbank.com, whereas www.realbank.example.com belongs to example.com)
- Carrot or Stick: The attacker knows you have to have a reason to click the link. This can either be a good reward (such as a large amount of money) or a stick (punishment if you do not click the link)
- Pressure: The attacker will normally give a deadline to click the link. The short deadline tries to make you panic, which will reduce your critical thinking skills and increase the chance of you missing the red flags.
Phishing Breakdowns:
Here is an example of a not very convincing phishing attempt I received.

Right off the bat, we can tick off numbers 1 & 2 from the list. Instead of being greeted personally, I just got “Dear Sir/Ma”, with an error spelling “Ma’am”. There isn’t a link for us to click, but a curious thing is that the address of the sender is different to the address I’m meant to contact. We can also see no. 4, being an unclaimed fund (presumably money), there is no no. 5 besides the chance of not receiving the money.
Not all phish attacks are emails, here’s an SMS one I received a while ago:

1 can be ticked off, as there is no greeting at all. Everything seems to be spelled correctly so number 2 doesn’t apply. The carrot here is the tax return, but on inspection the URL does not belong to the actual HMRC (UK government domains end in .gov.uk) which gives us an example of number 3.
Conclusion:
Phishing attacks rely on people’s ignorance of the warning signs, and pressuring people into responding before thinking. If you’re not sure, the best thing to do is to be cautious and think carefully.
Here is a great quiz to test your ability to spot a phish, and it teaches you what to look out for afterwards (Thanks to @YoSignals on twitter for showing it to me)