How to Spot Phishing Before It’s Too Late

How to Spot Phishing Before It’s Too Late

How to spot phishing

How to spot phishing is a skill everyone needs today, not just IT professionals. It is useful to absolutely anyone, every single day.

Phishing is the most widespread cyberattack in the world. It requires no sophisticated technology on the attacker’s side. Instead, it exploits something deeply human: trust, rushing, and the habit of clicking without looking.

What Phishing Really Is and Why It Works

Phishing is a manipulation technique that involves impersonating a trusted organisation such as your bank, La Poste, the tax authority (impots.gouv.fr), the French health insurance (Ameli) or your employer. The goal is to push you into taking an action: clicking a link, entering a password, confirming a payment or calling a number.

The key to its effectiveness is that it targets your judgement directly, not any technical flaw on your device. A well-crafted message, a plausible sense of urgency, a familiar logo and your brain does the rest. As a result, even experienced computer users can fall victim, particularly when they are distracted or tired.

The delivery method keeps evolving. Email remains dominant. However, phishing now arrives via SMS (smishing), phone calls (vishing), QR codes (quishing) and messages on LinkedIn or WhatsApp. The underlying mechanic, moreover, is always identical.

83% of French organisations experienced at least one phishing attempt in 2023.

According to Cybermalveillance.gouv.fr, phishing is the number one digital threat by volume for both individuals and businesses. It is no longer a fringe risk, it is everyday reality.

How to Spot Phishing: 5 Warning Signs That Betray a Fraudulent Message

A phishing message is designed to look legitimate. However, it almost always contains at least one red flag. By learning to read them, you can spot phishing in under 30 seconds.

Signal 1 — Manufactured urgency

“Your Ameli account will be suspended within 24 hours.” “Immediate action required regarding your unpaid EDF invoice.” “Your Chronopost parcel will be returned unless you act today.” Urgency is the primary tool of phishing. It short-circuits your thinking and pushes you to act before verifying. Yet no serious organisation, whether the CAF, La Banque Postale or the DGFiP, will ever pressure you this way in an email or text message.

Indeed, the more urgent a message feels, the more it should trigger caution rather than action.

Reflex: The more urgent the message, the more you take 30 seconds to verify first.

Signal 2 — The sender's address doesn't match

The display name might read “Ameli — Assurance Maladie” or “Service des Impôts”. However, the actual address behind it is something like [email protected] or [email protected]. The official Ameli domain is ameli.fr. The official tax authority domain is impots.gouv.fr. Everything else is therefore suspect. Attackers register near-identical domains by changing one character or adding a word, for instance amelii.fr, impots-gouv.net or credit-agricole-alertes.com.

Furthermore, the display name shown in your inbox is entirely controlled by the sender and can say absolutely anything. Consequently, you should never trust the display name alone.

Reflex: Click on the sender’s name to reveal the full address and verify the domain matches the official one exactly.

Signal 3 — The link doesn't go where it claims

The clickable text says www.impots.gouv.fr. However, hovering over it without clicking shows a completely different address in the bottom corner of your browser. On mobile, a long-press on the link reveals the real destination. This is moreover one of the most effective tricks because visually, the link looks entirely legitimate.

Common examples in France include fake La Poste parcel tracking pages, fake Ameli reimbursement portals and fake EDF or Engie invoice payment pages.

Reflex: Always hover over a link before clicking. On mobile, long-press to check the actual URL before doing anything.

Signal 4 — You are being asked for information no legitimate organisation requests this way

La Banque Postale will never ask for your password by email. The DGFiP will never ask for your bank card details to process a tax refund. Ameli will never ask for your RIB by SMS. Indeed, no legitimate organisation, whether the CAF, France Travail or your mobile operator, collects sensitive information via links in messages.

This is a universal rule. As a result, any message asking for this type of information should be treated as an automatic red flag, regardless of how official it looks.

Reflex: No serious French organisation ever requests sensitive information this way. Treat it as an automatic red flag.

Signal 5 — Something feels off without you knowing exactly why

Awkward phrasing, a slightly distorted La Poste or Ameli logo, your name misspelled, an unusual layout for an EDF bill or a tone that does not match the sender’s usual voice are all worth noting. Attackers are improving their techniques, particularly with AI, which now generates grammatically flawless messages in French. Nevertheless, intuition remains a valid signal. If something bothers you, that is moreover reason enough to check before acting.

Reflex: Doubt is sufficient. Pause, verify through an official channel, and only then decide whether to act.

Phishing Mail

The 30-Second Rule to Spot Phishing Every Time

Phishing relies on one thing: making you act faster than you think. The counter-measure is therefore equally simple. Take 30 seconds before acting on any unexpected message. Check the sender’s full address. Hover over the link. Ask yourself whether Ameli, La Poste or your bank would genuinely contact you this way, through this channel and with this level of urgency.

Those 30 seconds are sufficient, in the vast majority of cases, to defeat an attack that took hours to prepare. Indeed, awareness remains the first line of defence, before any technical tool.

5 Anti-Phishing Reflexes to Memorise

  • Urgency = suspicion.
  • I check the sender’s full email address
  • I hover over links before clicking to see the real URL. On mobile, a long press reveals the destination.
  • I always verify directly on the official website.
  • I report it, even if I’m not a victim.

The more pressured a message feels, the more carefully you should verify before acting. Always check the full sender address and not just the display name, since one different character is enough to reveal a fake. Hover over links before clicking to see the real URL, and on mobile use a long-press to check the destination. Always verify on the official site, whether ameli.fr, impots.gouv.fr or laposte.fr, and never through the link in the suspicious message. Finally, report it even if you are not a victim: a signal on Signal Spam or a forward to 33700 can help identify criminal networks and protect thousands of other users.

You have spotted a suspicious message and you are wondering what to do next?

Read our article Phishing: what to do and how to report it for the complete step-by-step guide.

Is your team ready to spot phishing in real conditions?

Stroople provides tailored training programs and real-world phishing simulations to assess your employees’ actual exposure level and embed the right security reflexes over the long term.

Learn more

Share:

X
LinkedIn