What You Need to Know to Report a Fraudulent Email | Complete Security

More than 3.4 billion fraudulent and phishing emails (e-mail) circulate every day. That number adds up to one trillion fraudulent emails per year. These numbers help to understand how and why employees become victims of phishing.

The typical inbox is overflowing with emails from colleagues, partners, friends and relatives, third-party vendors, newsletters, advertisements and, camouflaged among them, some from cybercriminals. Added to this glut are busy workdays and the pressure to read and respond to every email.

This is precisely why you must provide your employees with concrete information on how to report a fraudulent email. As part of your phishing awareness training , it is important to remind employees to report phishing emails, and to let you know immediately that they have been a victim.

Fraudulent Email, Complete security,


How to Report a Fraudulent Email

To report a fraudulent email, here are the steps to follow:

  1. Report the Fraudulent Email to the It Department or Their Manager

Make sure your employees know about company Complete security policy and how to report fraudulent email. As part of your ongoing campaign to promote cybersecurity awareness, remind employees, through email newsletters, posters and other communications, how to report fraudulent emails and tell them to whom address.

  1. Report the Fraudulent Email to the Email Service Provider

Most email service providers offer built-in mechanisms to make it easier to report fraudulent emails. The phishing report button can be activated in Outlook, Gmail, Yahoo! and others.

If your employees are checking their personal emails at work, make sure they have turned on the report phishing button) and remind them that they need to be proactive about this threat (even with their personal emails. ).

  1. Report the Fraudulent Email to a Governing Body

The majority of countries have bodies with authority to deal with malicious emails. In the United States, these emails can be sent to Cyber Security and Infrastructure Agency;   in Canada, at the Canadian Anti-Fraud Center;  in the UK, to National Fraud, and cyber crime Reporting center.  

  1. Place the Sender in the Spam or Fraudulent Emails List

Add the sender of the e-mail to the list of spam or fraudulent e-mails authors in your e-mail. Then, move any e-mail from that sender to the spam or fraudulent e-mails box, to remove them from the main inbox.

  1. Delete Email

Delete the email, then empty the deleted messages folder.

It is very important that your employees know what to do when they receive a phishing email. Make it easy for them to report this email, and let them know that they are doing the right thing.

What is phishing?

To report it, you first need to know what  phishing is, and how to recognize it. Phishing is a cybercrime that uses e-mail, website and text message fraud to steal confidential business or personal information.

Cleverly crafted email scams trick employees into providing personal information such as date of birth, address, credit card information, account passwords, and social insurance number. Using social engineering techniques, cybercriminals craft convincing emails that trick victims into believing their email is legitimate.

Phishing works when an unsuspecting victim responds to a fraudulent request, such as an email that prompts them to take action. This gesture can be to download an attachment, click on a link, fill out a form, update a password, or confirm credit card information.

Often times employees don't recognize the signs of a phishing email, and it is very easy to get caught up in the fast pace of a workday. Hence the importance of providing them with training and education to make them aware of phishing. See Why do phishing simulations? Build your business case and learn how to build a phishing awareness business case.

How to Recognize a Phishing?

To know how to recognize a fraudulent email, remind your employees that there are six main indicators of a fraudulent email, which you should especially avoid answering, trusting or clicking.

Here are the top six indicators of email fraud:

  1. Sender

Cybercriminals know that people are busy and don't carefully examine the sender of an email. These criminals also know that people are naturally inclined to trust, which makes it very easy to trick them into believing that, knowing the sender, the email must be legitimate.

• The sender's name and email address are very easy to forge.
• Just because you think you know the person sending the email doesn't mean it's safe.

Remind your employees to always check carefully if the sender's name and email address are spelled correctly. Advise them to hover their mouse over the name of the sender of the email and check if their name and email address are legitimate.

  1. Greeting

Normally, emails are personalized and do not use vague greetings such as "Dear Customer", "Dear Consumer", or "To Whom It May Concern". These greetings should be viewed with suspicion, especially if the email is from someone you know or from a company where you've worked before.

  1. Content

Cybercriminals know how to compose emails using clever social engineering techniques that trick people into taking action and believing that by replying they are doing the right thing.

Remind your employees to watch for these clues in the content of an email, often indicating fraud:

• Grammar and spelling mistakes or poorly structured sentences.
• Language that attracts attention and evokes urgency to create a sense of panic prompting to take action. For example, your account will be locked if you don't respond immediately.
• Request for confidential, personal or corporate information. Several cybercriminals send emails that appear to be from a bank, major online merchant, or government body asking the recipient to confirm an account, credit card, or social insurance number. No legitimate organization will request this kind of information by email.
• Password that must be reset immediately on the pretext that the company has been defrauded or that its database has been corrupted.

  1. Link or button

Phishing attacks usually include a link or button that directs the recipient to a fake website. This fake site looks real, but the domain name is not legitimate. For example, a cybercriminal could recreate the Amazon account page, but the URL is amazon.accountsupdate.ca instead of amazon.ca/gp/css/homepage.html.

Remind your employees to never click a link or button in an email, and instead should open a new browser tab and manually enter the website URL, or use a bookmark.

  1. Attachment

Attachments are used by cybercriminals to install malware on a computer and potentially on the corporate computer network. This malware can then lock down the computer or entire network, install software that logs computer keystrokes and passwords, or install a virus capable of corrupting files, with a ransom note.

Remind your employees to never open unexpected attachments in an email or on an external USB drive, and to avoid activating macros in documents in production.

  1.  Contact information

Legitimate organizations and employees request a response by providing contact information so that it is easy to contact them. Watch the greeting carefully and look for a phone number and address, and verify that the email address in the greeting matches the sender's email address.

Remind your employees that when in doubt about the legitimacy of a message, they should contact the sender to validate their request using contact information from a trusted source (eg, a website official web), not the email information itself.

Emphasize to your employees that acting safely avoids many regrets. During your cybersecurity awareness training, make it clear that you want your employees to remain suspicious of the emails they receive. Tell them that it's best to take the time to read the entire email carefully and, if in doubt, to speak to an in-house cyber hero or IT department. They should feel comfortable reporting a situation even after clicking, as the damage could perhaps be limited.

How to Protect Employees From Phishing and Email Fraud

The best way to protect employees from phishing, email scams, and other cybercrimes is to strengthen cybersecurity by continuously communicating messages to this effect. Your employees are your first line of defense against cybercrime.

By raising awareness of phishing and training in-house cyber heroes, you protect your business and your employees from the risks and threats posed by the approximately 3.4 billion phishing emails circulating every day.

Comments

Popular posts from this blog

Why Not to Restart Your Computer if It Is Infected With the Ransomware | Total Security

What Is a Ransomware Virus and How Do You Protect Your Computer From It | Total Security

What is a zero-day threat? Free Antivirus Software