Before You Click: Simple Ways to Spot a Suspicious Email
Most of us receive unwanted email. Some messages are simply advertisements, while others are designed to trick us.
Recently, some UNLA members have reported receiving suspicious emails that mention UNLA or contain information that makes the messages appear connected to the association. If you have received these emails and thought something seemed off, you were right – it was phishy. These particular messages are not being sent from UNLA’s email accounts.
Unfortunately, someone does not need access to an organization’s email system to send a message that mentions that organization. Bad actors can copy names, logos, signatures, and other familiar information into an email to make it appear more trustworthy.
That’s why one of the best things you can do with an unexpected email is simple: Pause. Check. Verify.
PAUSE before you act.
Scammers often want you to react before you have time to think. A message might tell you that something is urgent, a payment is overdue, an account has a problem, or you need to respond immediately.
Urgency should be a reason to slow down — not speed up.
Before clicking a link, opening an attachment, sending money, or providing information, take an extra moment to look at the message more closely.
CHECK who actually sent the email.
Seeing a familiar name at the top or bottom of an email does not prove who sent it. Anyone can type an organization’s name, an employee’s name, or a familiar-looking signature into an email.
Look at the full email address that sent the message, not just the name you see at first glance.
Then ask yourself:
· Do I recognize this email address?
· Was I expecting this message?
· Does the message make sense?
· Is this how this person or organization normally communicates with me?
· Is the message asking me to do something unusual?
One strange detail does not always mean an email is fake, but it is a good reason to be careful.
VERIFY unexpected requests another way.
If you are unsure whether an email is legitimate, don’t use the questionable email to verify itself. For example, if an unexpected email appears to come from an organization you know and asks you to click a link, don’t click the link just to see where it goes.
Instead, contact the organization another way.
You might:
· Visit its website by entering the website address yourself.
· Call a phone number you already know.
· Start a new email using an address you have used before.
· Contact the person directly using another method.
If the message is legitimate, taking a minute to verify it will not hurt anything. If it is a scam, that extra minute could prevent a much bigger problem.
Be especially careful when an email asks you to do something.
Take extra care with unexpected messages asking you to:
· Click a link
· Open an attachment
· Sign in to an account
· Send money
· Pay an invoice
· Change payment or banking information
· Provide personal or financial information
· Share a password or security code
An email does not have to look sloppy or unprofessional to be fraudulent. Scam messages can use real names, familiar organizations, logos, professional writing, and convincing email signatures.
Instead of asking, “Does this email look professional?” ask: “Does this request make sense, and have I verified who is asking?”
What if the email came from a real email address?
This can be confusing. An email can come from a working email account and still be part of a scam.
Someone can send you a letter with a valid return address while still lying in the letter. Email can work the same way. Technology can check many things about an email, but it cannot always determine whether everything the person wrote in the message is true.
That is why your own judgment remains important.
Protect your accounts, too.
There are also a few simple habits that can reduce the damage if someone ever gets your password.
1. Use a different password for each important account.
2. Turn on two-step sign-in whenever it is available. Two-step sign-in may also be called two-factor authentication or multi-factor authentication. Whatever the name, the idea is simple: your password alone is not enough to get into the account. You may be asked to approve the sign-in on your phone, enter a temporary code, use your fingerprint, or complete another step. That extra check makes it much harder for someone to access your account with a stolen password.
If you're unsure, ask.
If you receive an unexpected message that appears to involve UNLA and you are unsure whether it is legitimate, please contact UNLA using contact information you already know or obtain directly from the UNLA website.
There is nothing wrong with checking before you act.
Remember:
PAUSE. CHECK. VERIFY.
· A familiar name does not prove who sent the message.
· A professional-looking email is not automatically a safe email.
· A minute spent verifying something unusual can save you from a much bigger problem later.
Information from Matt Hoffman, CEO of Frontline Group North America.