Every Employee Should Read: How to Spot Phishing Emails
In the incident-response cases Halocent has handled, nearly 60% of initial intrusions started with a "perfectly ordinary" email. This 5-minute read gives you the most practical detection tactics — and what to do if you've already clicked.
1. Four common phishing tricks
1) Display-Name spoofing
The sender name reads "IT · Zhang San" but the real address is zhangsan@halocent-support.com (note the extra -support). Get in the habit of clicking the sender's name to reveal the real address — that alone catches 80% of impostors.
2) Manufactured urgency
"Your account will be frozen in 24 hours". "HR: your bonus has been released, confirm now". "The CEO needs you to process a wire transfer immediately". Real compliance notices never rely on a single channel with an extreme deadline.
3) Look-alike domains
Watch for halocent-cn.com / ha1ocent.com (letter l replaced with number 1) / halocent.com.tw-secure.net (the real domain is tw-secure.net). Only trust the two right-most dot-separated parts shown in your browser's address bar.
4) Disguised attachments
"invoice.pdf.exe", "contract.docx" (asking to enable macros), "photos.zip" (containing .lnk files) — any email asking you to enable macros, enable editing, or run something after extraction should be treated as suspicious.
2. 5-question quick self-check
Before clicking any link or attachment, take 20 seconds to answer:
- Does the sender's real domain 100% match the company?
- Is the message asking me to do something "right now" or "today only"?
- Is it asking me to bypass normal process (skip the ticket, skip approval)?
- When I hover over the link, does the real URL match the displayed text?
- If I got this wrong, what's the worst-case outcome?
If any answer is "I'm not sure", switch channels — call, use internal IM, or walk over. The correct answer for security is: slow down.
3. If you already clicked
Don't panic and don't delete evidence. Do three things immediately: disconnect from the network, report to IT / Security, and preserve the original email (forward the original .eml file, not a copy). 90% of the worst outcomes come from concealment within the first four hours.
4. Three tips for managers
- Run a company-wide phishing drill every quarter so people can practice safely.
- Provide additional training + mandatory MFA for high-value roles (Finance, HR, executive assistants).
- Provide an anonymous phishing-report channel and encourage people to raise suspicions early.
Phishing always attacks the human layer — and defence always depends on empowering every employee with the confidence to identify and report. Halocent can tailor a security-awareness + phishing-drill program for your organisation.
← Back to News & Insights