Skip to main content

IT security

What is phishing?

Phishing is fake emails and messages that steal passwords and money. Learn to recognise phishing, and see how to protect your business.

In short

Phishing is digital fraud in which an attacker poses as a trustworthy sender (for example your bank, Microsoft or the CEO) to trick you out of credentials, payments or access to systems.

It typically happens via email, but also via SMS (smishing) and phone calls. Phishing hits businesses of every size and is the most common entry point for serious security incidents such as ransomware and compromised email accounts, because it exploits people rather than technology.

Three things are worth remembering: attackers imitate senders you trust and create artificial urgency; targeted attacks (spear phishing) are hard to see through because they are built on research about you specifically; and even the best email filters let the occasional attempt slip through, so your employees' vigilance is the last line of defence.

MI Support IT helps Danish businesses stop phishing through email security, multi-factor authentication and ongoing employee training.

Back to the glossary

What is phishing?

Phishing is a form of digital fraud in which an attacker poses as a trustworthy sender to lure you into handing over credentials, approving a payment or opening an infected file. A phishing email typically imitates a sender you already know: your bank, Microsoft, a courier company or a colleague. Phishing literally means "fishing": the attacker casts out bait and waits for a bite.

According to the Danish Centre for Cyber Security, phishing is one of the most widespread cyber threats against Danish businesses, and the most frequent entry point for ransomware attacks and compromised email accounts.

How to recognise a phishing email (with examples)

Most phishing emails follow the same recipe. Look for these signs:

  • The sender address looks right but is not genuine, for example support@micros0ft-login.com instead of microsoft.com.
  • Artificial urgency: "Your account will be closed within 24 hours" or "Pay this invoice today".
  • Links that point somewhere other than the text suggests. Hover over the link before you click.
  • Unexpected attachments or requests for login details and payment information.

Classic examples of phishing emails are the fake parcel notification ("your parcel is being held: pay a small customs fee"), the fake Microsoft warning ("unusual sign-in activity: confirm your account") and CEO fraud, where "the CEO" asks the finance team for an urgent transfer.

Phishing by SMS (smishing)

Phishing via SMS is called smishing and is growing fast, because we click less critically on our phones. The messages typically claim to come from PostNord, MitID (Denmark's national digital ID), the bank or the tax authorities and contain a link to a fake login page. Remember: no serious authority or bank will ever ask you to confirm details via a link in a text message.

If you have clicked or entered details, act immediately:

  1. Change your password on the affected account straight away, and everywhere else you use the same password.
  2. Contact your IT department or IT partner: better one false alarm too many than an attack that is allowed to develop.
  3. Enable multi-factor authentication (MFA) if it is not already switched on. It stops most account takeover attempts.
  4. Watch the account for emails you did not send, new forwarding rules or unknown sign-ins.

Why is spear phishing extra dangerous?

Spear phishing is a targeted attack against a specific person or company. Where classic phishing is mass-mailed, spear phishing is built on research: the attacker has read your website and LinkedIn profiles and knows who approves payments and which suppliers you use. The email therefore hits with the right names, the right context and the right timing, and slips past both filters and common sense far more often.

How MI Support IT can help

Technology alone does not stop phishing: even the best filters still let the occasional email through. Effective protection combines email filtering and MFA with ongoing security awareness training, so employees recognise the attempts in practice. MI Support IT helps Danish businesses with both the technical setup and the training. Read more under IT security, or contact us for a conversation about your situation.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.