Images are AI-generated illustrations, not documentary photographs or product screenshots.
Phishing red flags: look at the requested action
Phishing often asks you to open an attachment, follow a link, reveal information or approve an action. CISA’s guidance emphasizes recognizing and reporting these attempts. A message can be polished and use familiar branding while still being malicious. Instead of judging only spelling, ask what the sender wants you to do and whether that action fits the relationship. Unexpected password resets, payment changes and urgent document access deserve independent verification.
Notice pressure and unusual workflows
Attackers may use deadlines, fear or attractive job offers to discourage checking. A supposed client might require unknown software before discussing the project, or a recruiter might ask for payment to secure a job. The FTC warns about job-related scams and fake-check arrangements. Do not assume a professional profile establishes legitimacy. Pause when a request introduces an unusual financial transfer or account step that was not part of the agreed workflow.

Verify through a known route
Open the service from a saved address or its legitimate application rather than the message link. Contact a client using an established channel if bank details or payment instructions change. Do not use contact information supplied only in the suspicious message to verify itself. If an attachment is unexpected, ask about its purpose before opening it. Verification should establish both the sender’s identity and authorization for the action, not merely that a name is familiar.
Protect passwords and verification codes
Use unique credentials and supported MFA, but remember that some codes and approval flows can still be phished. Never disclose a password or one-time code to a person claiming to need it for hiring, support or a refund. Review the context of an approval notification before accepting it. A legitimate account owner should use the site’s supported process. Do not disable protections because someone says they are delaying a business opportunity.
Respond carefully if you already acted
Use the provider’s legitimate recovery and incident-reporting routes. Change exposed credentials, review relevant sessions and contact the account owner or security lead. If a device may be compromised, seek appropriate technical help rather than repeatedly opening the suspicious file. Preserve useful information without forwarding harmful attachments widely. Financial loss may require contacting the bank or payment provider promptly. Reporting mechanisms differ by country; U.S. FTC guidance is not a universal local reporting service.

Build verification into normal work
Agree on approved payment-change and access procedures before an urgent request arrives. Make it easy for team members to question a message without embarrassment. Keep contact records current and use named access where possible. Review examples as learning material without publishing private client information. The goal is not to become suspicious of every interaction, but to make risky actions depend on reliable checks rather than urgency, familiarity or a persuasive message.
Sources and further reading
CISA: passwords, MFA, phishing and updates
U.S. Federal Trade Commission: job scams
