What is phishing?
Phishing is a form of digital fraud in which an attacker poses as a trustworthy sender to lure you into handing over credentials, approving a payment or opening an infected file. A phishing email typically imitates a sender you already know: your bank, Microsoft, a courier company or a colleague. Phishing literally means "fishing": the attacker casts out bait and waits for a bite.
According to the Danish Centre for Cyber Security, phishing is one of the most widespread cyber threats against Danish businesses, and the most frequent entry point for ransomware attacks and compromised email accounts.
How to recognise a phishing email (with examples)
Most phishing emails follow the same recipe. Look for these signs:
- The sender address looks right but is not genuine, for example
support@micros0ft-login.cominstead ofmicrosoft.com. - Artificial urgency: "Your account will be closed within 24 hours" or "Pay this invoice today".
- Links that point somewhere other than the text suggests. Hover over the link before you click.
- Unexpected attachments or requests for login details and payment information.
Classic examples of phishing emails are the fake parcel notification ("your parcel is being held: pay a small customs fee"), the fake Microsoft warning ("unusual sign-in activity: confirm your account") and CEO fraud, where "the CEO" asks the finance team for an urgent transfer.
Phishing by SMS (smishing)
Phishing via SMS is called smishing and is growing fast, because we click less critically on our phones. The messages typically claim to come from PostNord, MitID (Denmark's national digital ID), the bank or the tax authorities and contain a link to a fake login page. Remember: no serious authority or bank will ever ask you to confirm details via a link in a text message.
What do I do if I have clicked a phishing link?
If you have clicked or entered details, act immediately:
- Change your password on the affected account straight away, and everywhere else you use the same password.
- Contact your IT department or IT partner: better one false alarm too many than an attack that is allowed to develop.
- Enable multi-factor authentication (MFA) if it is not already switched on. It stops most account takeover attempts.
- Watch the account for emails you did not send, new forwarding rules or unknown sign-ins.
Why is spear phishing extra dangerous?
Spear phishing is a targeted attack against a specific person or company. Where classic phishing is mass-mailed, spear phishing is built on research: the attacker has read your website and LinkedIn profiles and knows who approves payments and which suppliers you use. The email therefore hits with the right names, the right context and the right timing, and slips past both filters and common sense far more often.
How MI Support IT can help
Technology alone does not stop phishing: even the best filters still let the occasional email through. Effective protection combines email filtering and MFA with ongoing security awareness training, so employees recognise the attempts in practice. MI Support IT helps Danish businesses with both the technical setup and the training. Read more under IT security, or contact us for a conversation about your situation.