Categories: Threat Insight

Email Phishing

What is phishing?

Phishing is a scam where psychological manipulation is used to scare or trick victims into giving away sensitive data like passwords or paying money through the use of fraudulent invoices.

What types of phishing are there?

Spear phishing – These are emails that are targeted at individuals. Typically

Whaling/business email compromise – this involves targeting upper management, usually c-level, into releasing sensitive information or making fraudulent payments.

What does whaling look like?

Clone phishing – in these attempts, a previously delivered legitimate email that contains an attachment or link has its content taken and replaced into an email

General phishing –

How do I spot phishing scams?

Grammar – since the majority of phishing email creators are not native English speakers, they tend to make mistakes in their writing. Words will be misspelled, formatting such as spacing may be off and the usage of words may not sound normal. These are all major tell tale signs that the email you are viewing is not legitimate.

Impersonal – Since the sender often does not know much about the recipient, the email

Email Header –

Asking for a quick reply –

See our blog post on how to spot phishing emails –

How do I stop phishing scams from succeeding in my organization?

Advanced email security – The best course of action is to have email security in place that will block the vast majority of phishing attempts.

Security awareness training – For when phishing emails do get past your prevention systems, you need users that are knowledgeable and vigilant.

Ron Samson

Recent Posts

SIEM Management Services: When Log Collection Becomes Too Expensive to Operate Internally

Turn SIEM logs into faster response with managed SOC services—optimize telemetry, tune detections and gain…

2 weeks ago

Cloud Security Monitoring for AWS and Azure: What Your MSSP Should Actually Watch

Detect AWS and Azure identity abuse before it becomes a breach. Learn the signals, log…

57 years ago

Security Operations Metrics That Matter: KPIs for Risk Reduction, Response Speed, and Executive Reporting

Prove security risk reduction with KPIs for exposure aging, critical asset coverage, detection quality, and…

57 years ago

Microsoft 365 Security Monitoring: What SMBs Miss After Basic Configuration

Catch MFA and OAuth abuse in Microsoft 365 before attackers create forwarding rules or steal…

57 years ago

Managed Vulnerability Management: How to Turn Scanner Findings Into Remediation That Reduces Risk

Reduce measurable exposure with managed vulnerability management: validate findings, prioritize exploitable risk, verify fixes, and…

3 weeks ago

Co-Managed Security Operations: How Internal IT Teams Can Keep Control While Gaining 24/7 Coverage

Gain 24/7 security coverage without losing control. Learn how co-managed operations cut alert fatigue, share…

57 years ago