Spot the Phish: Most People Miss at Least Three

Ten emails. Some real, some fake. Read the sender and the link, not the tone, and see if you can beat the average.

Security Awareness · Spot the Phish

1 / 10
0 correct

Phishing, answered

The practical stuff behind the quiz: what phishing is, how to catch it, and what to do if one gets through.

What is a phishing email?

A phishing email is a message designed to trick you into handing over information or money. It usually pretends to be from a company or person you trust, such as Microsoft, your bank, or a supplier. The aim is to get you to click a link, enter your password, open an attachment, or change a payment. Catching them comes down to checking the real sender address and where any link actually points.

How can I spot a phishing email?

Read the sender’s full email address, not just the display name, and check the domain for lookalikes such as an extra word or an r and an n standing in for an m. Hover over links to see the true destination and read the domain from the right. Be wary of urgency, threats of losing access, and any request to confirm a password or change bank details. When something feels off, verify it through a channel you already trust rather than replying to the email.

What should I do if I clicked a phishing link or replied?

Act quickly. Change the password for the affected account and turn on multi-factor authentication if it is not already on. Tell your IT or security provider so they can check for unauthorised access. If you entered card or bank details, contact your bank. If you paid an invoice or changed a payment on a request that turned out to be fake, report it to your bank and to Action Fraud straight away. The sooner it is caught, the more can be contained.

What is the difference between phishing, spear phishing and business email compromise?

Phishing is sent in bulk to many people at once. Spear phishing is aimed at a specific person and uses details about them to seem more convincing. Business email compromise, or BEC, is when an attacker impersonates a colleague, a manager, or a supplier to get an invoice paid to the wrong account or to pull information out of someone. BEC often uses no links at all, which is what makes it so hard to catch.

How do businesses actually stop phishing?

The strongest defence is layered. Email filtering blocks a large share before it reaches the inbox, multi-factor authentication limits the damage if a password is stolen, and staff training teaches people to spot what gets through. Guard IQ sets up and manages all three for regulated businesses, so protection does not rest on any one person having a good day.