Phishing targets your attention, not your expertise. Five seconds, five reflexes, and most fake emails give themselves away before you click.

An email asks you to "verify your account", "confirm a payment" or "unlock your card". The tone is urgent, the logo looks right, the link is waiting. That's where costly mistakes happen.

Good news: once you know where to look, most attempts show themselves quickly.

The five seconds that count

  1. Name vs address. The sender shows "RBC" but the address is service@rbc-support.info? Fake.
  2. Hover the link. Move your mouse over the button or link (no click). The real URL appears at the bottom of the screen. Not the real site? Fake.
  3. Urgent tone. "Action required within 24 h", "your account will be closed", legal threats: emotional triggers. Breathe first.
  4. Typos and odd wording. Bad translations, weird capitalization, random punctuation: still common, but AI-written phishing is getting cleaner. Don't rely on this signal alone.
  5. Unusual request. A vendor changing their bank details by email, a boss asking you to buy gift cards, a surprise attachment: call the person to verify.

One rule worth its weight: your bank, the CRA, Service Canada and your vendors will not ask for your password by email. Not ever.

Three traps that still work

  • Fake Microsoft, Google or Apple warning of a "suspicious sign-in". They want you to click "This wasn't me" and type your credentials on their page.
  • Invoice PDF with a link to a "secure portal" to pay it. The PDF is clean, the link is a trap.
  • Delivery SMS from Canada Post, UPS or FedEx: a small customs fee to pay. The page looks nearly identical.

What to do when in doubt

  • Don't click. Don't reply.
  • Open a new tab and go to the site yourself (type it, or use a bookmark).
  • Report the email: "Report phishing" button in Gmail and Outlook, or forward it to your IT team.
  • Delete it.

If you clicked and typed your password: change it right now, turn on MFA if it isn't already, and check every site that shared that password.

This week's practice

The muscle builds with three moves, repeated daily for a week:

  • Hover before you click. Three links a day, no click. The reflex settles fast.
  • See the full address. Turn on full sender display in Gmail, Outlook or Apple Mail. The name alone tells you nothing.
  • Report one real fake. There will be one this week. Use the "Report phishing" button instead of simply deleting.

Bookmark the real sites for your bank, government portals and credit cards. Next time an email pushes you to visit, you go through the bookmark, never through the link in the email.

Related

Phishing hurts a lot less when your accounts are locked down: MFA and a password manager blunt the impact of a bad click. For your team, see cybersecurity is everyone's responsibility.

Want to give your team the same reflex in one hour, using real examples? Book thirty minutes and we'll frame the workshop.