Every Employee Should Read: How to Spot Phishing Emails

In the incident-response cases Halocent has handled, nearly 60% of initial intrusions started with a "perfectly ordinary" email. This 5-minute read gives you the most practical detection tactics — and what to do if you've already clicked.

1. Four common phishing tricks

1) Display-Name spoofing

The sender name reads "IT · Zhang San" but the real address is zhangsan@halocent-support.com (note the extra -support). Get in the habit of clicking the sender's name to reveal the real address — that alone catches 80% of impostors.

2) Manufactured urgency

"Your account will be frozen in 24 hours". "HR: your bonus has been released, confirm now". "The CEO needs you to process a wire transfer immediately". Real compliance notices never rely on a single channel with an extreme deadline.

3) Look-alike domains

Watch for halocent-cn.com / ha1ocent.com (letter l replaced with number 1) / halocent.com.tw-secure.net (the real domain is tw-secure.net). Only trust the two right-most dot-separated parts shown in your browser's address bar.

4) Disguised attachments

"invoice.pdf.exe", "contract.docx" (asking to enable macros), "photos.zip" (containing .lnk files) — any email asking you to enable macros, enable editing, or run something after extraction should be treated as suspicious.

2. 5-question quick self-check

Before clicking any link or attachment, take 20 seconds to answer:

  1. Does the sender's real domain 100% match the company?
  2. Is the message asking me to do something "right now" or "today only"?
  3. Is it asking me to bypass normal process (skip the ticket, skip approval)?
  4. When I hover over the link, does the real URL match the displayed text?
  5. If I got this wrong, what's the worst-case outcome?

If any answer is "I'm not sure", switch channels — call, use internal IM, or walk over. The correct answer for security is: slow down.

3. If you already clicked

Don't panic and don't delete evidence. Do three things immediately: disconnect from the network, report to IT / Security, and preserve the original email (forward the original .eml file, not a copy). 90% of the worst outcomes come from concealment within the first four hours.

4. Three tips for managers

  • Run a company-wide phishing drill every quarter so people can practice safely.
  • Provide additional training + mandatory MFA for high-value roles (Finance, HR, executive assistants).
  • Provide an anonymous phishing-report channel and encourage people to raise suspicions early.

Phishing always attacks the human layer — and defence always depends on empowering every employee with the confidence to identify and report. Halocent can tailor a security-awareness + phishing-drill program for your organisation.

← Back to News & Insights

Ready to run a phishing drill for your team?

We'll respond within one business day with a scenario deck tailored to your industry.