How to Recognize a Phishing Email
Look beyond a familiar display name and consider the request, destination, and context together.
Read the guideWhat Is Business Email Compromise?
A business request can be fraudulent even when there is no attachment or suspicious link.
Read the guideUnderstanding Credential Phishing
A convincing sign-in request can turn an ordinary account action into a credential disclosure.
Read the guideWhat Is QR Phishing?
A QR code is a route to a destination—not evidence that the destination is trustworthy.
Read the guideUnderstanding Lookalike Domains
Small changes in a domain can borrow the appearance of a name you recognize.
Read the guideWhat to Do After Clicking a Suspicious Link
Respond promptly and give your security team useful context about what happened.
Read the guideHow Social Engineering Works
Attackers can manipulate context and expectations instead of breaking through a technical control.
Read the guidePhishing vs Spam
Unwanted content and deceptive requests are related problems, but they are not the same thing.
Read the guideHow Executive Impersonation Attacks Work
Borrowed authority can make an unusual request feel difficult to question.
Read the guideWhy Attackers Create a Sense of Urgency
A deadline can push someone to act before they have checked the context.
Read the guideEducational content, not an incident-response service. Follow your organization’s policies and verify sensitive requests independently.