A clearer view of technology.An independent journal
← Back to the journal
The basics 2 min read

How to spot phishing messages and verify an unexpected request

Recognize suspicious requests for passwords, payments, and account access, then verify the message through a separate trusted route.

Phishing messages try to persuade you to take an action that benefits an attacker, such as revealing account details or opening a harmful link. A polished design or familiar display name is not enough to establish who sent a request.

When a message unexpectedly asks for a sensitive action, pause and verify it using a route you already trust. Do not let the message itself supply every piece of evidence for its own legitimacy.

Look at the request, not just the spelling

Ask what the sender wants you to do and whether that request fits the relationship. Unexpected demands for credentials, urgent payments, or account verification deserve scrutiny even when the writing is fluent.

The Cybersecurity and Infrastructure Security Agency’s Secure Our World guidance identifies recognizing and reporting phishing as a basic protection. Use its guidance as a reference alongside your organization’s security procedures.

Verify through a separate route

If a message appears to come from a service you use, open that service through your established bookmark or app rather than following the message’s link. Check whether the claimed issue appears there. For a personal or workplace request, contact the supposed sender through an existing trusted channel.

Do not call a number supplied only in the suspicious message to prove that message is genuine. The same problem applies to an unfamiliar support page or a new address included in the request.

Keep secrets out of the conversation

Treat passwords, recovery codes, and one-time authentication codes as sensitive. A person asking for a code may be attempting to complete a sign-in or account change. Follow the provider’s official process instead of sharing credentials in response to an unsolicited message.

For work accounts, report concerns through the established security channel. Do not forward potentially harmful attachments widely to ask whether someone recognizes them.

If you already interacted

Stop using the suspicious conversation and seek the provider’s official recovery or security guidance. If work information or a work device is involved, contact the responsible team promptly and describe what happened. The appropriate response depends on whether you merely viewed a message, entered information, downloaded something, or approved an action.

Prepare ahead with an account recovery inventory. Keep the inventory itself protected, and use notification settings carefully so important account alerts still reach you.