If you looked at this email fast, you’d swear it came from Microsoft. Same logo, layout, tone - everything checks out. Except for one thing: The sender’s domain was rnicrosoft(.)com instead of microsoft(.)com That tiny swap of “rn” instead of “m” is what’s called typosquatting. Attackers register near-identical domains to catch people who skim their inbox too fast. What makes this effective is how subtle it is. On mobile, you barely see the full address. On desktop, your brain autocorrects it. It feels right and that’s all they need. These kinds of tricks are showing up more often in credential phishing, vendor invoice scams, even internal HR impersonations. How to handle these cleanly (real, practical steps): - Expand the full sender address every time before you click. - Hover the link to view the real href, or long-press the link on mobile to reveal the URL. - Check the Reply-To header -- scammers often route replies elsewhere. - If it’s a password reset you didn’t request, open a new tab and log in from the official site rather than clicking the email. - Forward the phish to your security team or report it (company phishing inbox / your provider’s report feature). Examples of look-alikes to watch for: swapped letters (rn → m), zero for o (micros0ft), added hyphens or extra subdomains (microsoft-support[.]com). Small habit change, big payoff. Teams that rehearse these scenarios stop reflexively clicking.
Understanding Phishing Threats
Explore top LinkedIn content from expert professionals.
-
-
Would you fall for a fake email from Amazon.xyz ? Because 690,502 people just like you did. A new rigorous, empirical study shows how modern phishing attacks work. And it's not what you think. Here's the wild part: Two-thirds of these attacks use brand new web addresses that look ~almost~ real. 📊 The Data: - 39 Months - 690,502 Phishing Sites Here's The Attacker Playbook: 1. Buy Cheap, Throw Away Fast • Use .top and .xyz domains • Cost pennies to buy • Easy to dump when caught 2. Copy Famous Names • Amazon becomes Amaz0n.xyz • PayPal becomes PayPal-secure.top • Microsoft becomes Micros0ft.xyz 3. Play Digital Hide & Seek • Switch servers every few days • Change settings constantly • Stay ahead of blockers 🔍 The Numbers Tell the Story: • 66.1% use fresh domains • 64.3% keep changing servers • Takes 11.5 days to shut them down Keep Yourself Safe: 1. Check EVERY Link • Hover before clicking • Look for weird spellings • Question unusual extensions 2. Watch Out For: • .top domains • .xyz domains • Any odd-looking web address 3. Trust Your Instincts • Looks fishy? Probably is • Verify the sender • Check independently 💡 Key Takeaway: Modern phishers aren't using obvious fake emails anymore. They're playing a sophisticated game of digital deception. Stay sharp. Stay safe. ♻️ Share this to help others spot these tricks. 👉 Follow me for more security insights that keep you protected. #Cybersecurity #PhishingAwareness #DigitalSafety #TechSecurity
-
“Stop clicking on links” 🚫 If this is your advice to people during cyber awareness month, please stop! 🚫 If you’re also maintaining a ‘repeat offenders’ list, please kindly stop that too. It’s counterintuitive and doesn’t work. You operate in a digital world. The majority of tech and tools that you provide to employees require them to click on links and apps - documents, collaboration tools, payslips etc Telling people to click sometimes, and not others is confusing and you’re shifting the onus onto the individual to know what is legitimate, and what isn’t. Even expecting them to open a new tab, or type in a URL directly into a browser instead of just clicking what is in front of them. Lets face it, most people are not going to add extra steps to their routine, unless it’s obvious that the message is a bit strange, or it impacts them directly. Threat actors learn to counteract how we train people, they obfuscate what they’re doing, so most people have no idea it’s a fake domain, or a malicious macro is running on a spreadsheet Yet you want to blame them, for not knowing about the constant changes in tactics and techniques? A few things you can do instead… ✅ The security tools you deploy should act as a safetynet, that verifies the legitimacy of each link and attachment, by scanning and launching in a sand box environment to check whether malicious to provide added assurance to the person. ✅ Instead of giving people a long list of things to do like checking headers, hovering over links and various things that they’re not going to do, help them to understand the intent behind the message. Even if something looks and sounds genuine, what are you being asked to do as a result of this action? ✅ Empowering people to say NO to unrealistic demands, timelines and requests that are outside the norm of their role, because these are also the type of things that a threat actor will do! ✅ When people are suspicious and report it as potential phishing, please actually reply to them! Ask them why, let them know whether they were right to be suspicious, and what you did as a result. ❤️ Instead of focusing on what you consider bad behaviour, how about you champion all those that are demonstrating positive behaviour instead?
-
Fraud no longer hides in the shadows. It might show up disguised as someone you know. Like when the CEO calls and her voice on the phone sounds exactly right. Her urgency feels real, and the wire transfer request to a new bank account seems legitimate, so accounting releases the funds. And just like that, the company loses $20k to a fraudster who weaponized AI. This isn't science fiction. It's happening right now to individuals and organizations alike. Fraudsters are creating disturbingly real AI deepfakes that can fool even the most cautious people. And companies need strategies to combat them. Because those audio and visual cues we've relied on for decades are no longer reliable indicators of authenticity when it comes to AI deepfakes. Organizations can fight back with these defense strategies: ✔ Stay cautious and be wary of anyone requesting money or personal information, even if they look or sound like someone you trust. ✔ Don’t send money or share sensitive data in response to a single phone or video call. Phone numbers can be spoofed, so always verify a person’s identity by contacting them separately at a number you trust. ✔ Use small action requests, like asking a person to turn their head, blink repeatedly, or hum a song while on a video or phone call. If they decline, freeze up, or go silent, it could be a fraudster. ✔ Establish a safe word that only your inner circle knows to confirm the identity of someone claiming to be a colleague, family member, or friend. ✔ Use strong passwords. Enable multifactor authentication (MFA) on all company devices and accounts whenever possible. And don’t forget to report AI deepfakes to law enforcement and any relevant social media channels, websites, and other platforms where the encounter took place. All of these tips ALSO work for individuals too because hackers like causing havoc with anyone they can. The question isn't whether AI deepfakes will target your organization. It's whether your organization will be ready when it does. Food for thought as we kick off Cybersecurity Awareness Month. ♻ Share our infographic to help companies combat AI deepfakes.
-
I woke up this morning to a flurry of (legitimate) text messages from Amazon asking me to confirm a login attempt to my Amazon account overnight, which was allegedly made by a (presumably) malicious actor trying to gain access to my account. While the malicious actors' attempts were unsuccessful, it has triggered a review of my Amazon account this morning, including a password reset and a change of #multifactor access using an authenticator app and not text message/email address (which are inherently less secure). I encourage you to exercise extreme caution with #blackfriday and #cybermonday. Steps you can take: 1) Don't click on email or SMS links or access sales offers. Phishing skyrockets during sales periods. If you see a deal, go directly to the retailer’s official website by typing it into your browser manually, or, if you're a shopaholic, use a saved and trusted browser favourite/bookmark instead. 2) Switch on Multi-factor Authentication on any retailer website where you are storing payment details, and in fact on any website that has the functionality. These include popular platforms such as Amazon and eBay, but most reputable retailers also offer this functionality. 3) Stick to trusted retailers: If you’ve never heard of the site, and the price looks unbelievable, it probably is. Check reviews, business details such as ABN's and ACN's, and whether the site has proper contact details. 4) Use strong, unique passwords (and a password manager): Password reuse is a goldmine for attackers. A password manager makes this effortless. 5) Beware “too good to be true” deals: If it’s 80% off and only available for 'the next 5 minutes', then it's probably a bait. High-pressure countdowns are commonly used in scam pages. 6) Use secure payment methods: Credit cards, PayPal, and Apple/Google Pay provide fraud protection. Avoid direct bank transfers and debit card payments for online purchases. 7) Check the site security: Look for https:// (with the 's', not just 'http'). Remember, though, that HTTPS alone doesn’t mean a site is legit; however, it is one signal that helps. 8) Keep your device updated: Make sure your phone and laptop have the latest #patches. Old software means easy exploits. 9) Avoid public Wi-Fi: Free Wi-Fi is often a gift to attackers, because if you connect to it, it provides a #cybercriminal the means to be between you and a legitimate site, and they gain access to any traffic in between. Use a mobile hotspot from your phone if you have to. 10) Monitor your bank accounts: Check your statements and email notifications for unusual activity. A few years ago, my bank accounts showed a plethora of luxury purchases which, for a change, weren't my partner's or mine (I'm kidding, we shop at Kmart). The bank reversed them the same day. The earlier you catch fraud, the easier it is to stop. https://lnkd.in/gfG_QGBn Novera
-
Scammers see tax season as open hunting season Don't be their easy prey 7 things nobody tells you about staying safe from phishing during tax season: 1. Be Skeptical of Unexpected Emails → Even if it looks like it’s from your CPA, trust your gut. → Unexpected emails? Delete them immediately. 2. Generic Senders Are Risky → Addresses like donotreply@domain.com are a scammer’s favorite disguise. → Always verify directly with your provider’s online portal. 3. Never Click Unverified Links → Don’t shortcut security by clicking links in emails. → Log in directly via your browser to avoid phishing traps. 4. Upgrade Your Email Security → Free email services lack robust phishing protection. → Consider upgrading to paid plans with built-in security features. 5. Don’t Ignore Email Settings → Even premium platforms like Google Workspace need periodic reviews. → Verify your settings to ensure optimal protection. 6. Scammers Target E-Signature Platforms → The rise of e-signatures has made them prime phishing targets. → Authenticate every document before signing or opening. 7. Think Before You Open Emails → Got an unexpected tax document? Call your provider directly. → No shortcuts, no stress, no scams. PS) Scammers are clever, but they’re also lazy. Make them work harder than it’s worth.
-
7 steps to follow if you're unsure about an email, SMS, or link. Stop. Think. Don’t click yet! If it feels off, it’s time to report it before it's too late. Common examples? - An email offering free Amazon vouchers - Your CEO asking you to transfer money to his account - Your colleague messaging he cannot take your call but needs money And many more.... Here's what you should do! 1) Pause: Take a moment. Don’t rush into clicking links or opening attachments. 2) Check the sender’s email or number: Is it from a trusted source? Double-check the details carefully. 3) Look for urgency cues: Words like “limited offer” or “urgent action” should raise a red flag. 4) Don’t click, just hover: Hover your mouse over links to see where they really lead. Does the URL seem legit? Right click on the link, copy it and paste it on notepad to inspect it. 5) If it's Googleable, do it (e.g. public offers): Search for the offer or sender. If it’s real, you’ll find information on official channels. 6) Ask your IT team: Your IT team will know if it’s safe. Don’t hesitate to ask! 7) Report actions: If you've clicked a link & are now in 2 minds, report it to your IT team. They’ll take it from there. Building a reporting culture means: - There's no shame in asking - There's no shame in accepting - There's no shame in being proven wrong Small timely steps can prevent bigger issues later! P.S. Ever had a close call with a suspicious link? What did you do? ---- Hi! I’m Rajeev Mamidanna. I help CISOs strengthen their Cybersecurity Strategies + Build Authority on LinkedIn
-
The Spam in My Pocket: A Recruiter’s Take on the Rise of Scammy Job Texts This morning, I woke up to another unsolicited job text. “Hi, I’m Lily from KLARNA…” it began—offering $500 a day for 90 minutes of remote work, “free training,” and a suspiciously vague task involving “visibility and bookings.” Here’s the thing: I’m a recruiter. I live and breathe this industry. And even I had to blink twice. These kinds of messages are everywhere now. Dressed in language meant to sound official, generous, and urgent—while hiding the fact they’re likely scams trying to bait job seekers into giving up personal info or worse. I get the appeal. People are looking for flexible work. They’re burned out, underpaid, and trying to make it all work. And yes—legitimate recruiters DO use text messaging to reach out to talent. But here’s the problem: scam texts are flooding the zone, making it harder for real opportunities to break through the noise. It creates mistrust. It makes people skeptical of even real offers. And it pollutes the very channels recruiters use to do good, honest work. So, here are a few real-world tips to spot a fake job text before it wastes your time (or compromises your data): 1. Too good to be true? It probably is. $500/day for 90 minutes of remote work? Sounds amazing. Too amazing. Most jobs that pay that much require a lot more than a resume forwarded by “online agencies.” 2. Check the company’s official channels. If Klarna—or any company—has 20 urgent remote openings, you’ll see it on their Careers page. You won’t only hear about it via a 7:10 AM iMessage. 3. No professional email, no deal. If a recruiter’s reaching out, they should have a verifiable email, LinkedIn profile, and some kind of online presence tied to the company or agency they represent. 4. Watch for vague roles. “Helping merchants update data” and “increasing bookings” without any mention of the actual job function? That’s a smoke signal. 5. Ask questions. A legitimate recruiter won’t panic if you ask who they report to, what department they’re in, or how they got your information. A scammer will. We’re in a weird moment in recruiting. AI-generated messages, offshore text blasts, and predatory scams are muddying the waters. If you’re job searching, stay sharp—but don’t get jaded. There are still real people doing real recruiting with care, integrity, and transparency. You just have to know how to separate the signal from the noise. And recruiters? Let’s take back the credibility of our craft. — Want help spotting shady outreach? Drop a comment or DM me. We’re in this together. #recruiting #jobsearch #scamalert #talentacquisition
-
🚨 Scam Texts. Spam Emails. Shady Links. We all get them sometimes daily. A friend recently messaged me and said: “I keep receiving weird messages with sketchy-looking links. I usually ignore them, but a refresher on what to watch out for especially with phone security would be really helpful.” And they’re absolutely right. These threats are everywhere. And as cybercriminals evolve, even tech-savvy people can fall for well-crafted traps. The truth? ✅ It only takes one click to compromise your phone. ✅ And most scams look legitimate at first glance. So here’s a quick refresher you can use (and share) to stay alert and stay safe 👇 🔐 1. Suspicious Links • Avoid clicking links from unknown or unexpected sources. • Even if it looks legit, always verify before clicking. ⚠️ 2. Urgent or Alarming Messages • Messages that create panic are often scams. • Take a moment to breathe and verify the sender. 👀 3. Misspelled Domains or Lookalikes • Fake sites often use small changes like “amaz0n.com”. • Always check the full URL and sender’s email. 📎 4. Random Attachments • Don’t open unexpected .ZIP, Word, or PDF files. • These can carry malware or phishing tools. 🔐 5. Requests for Personal Info • Legit companies never ask for passwords or bank details. • Ignore and report such messages immediately. 📲 6. Outdated Devices = Easy Targets • Older systems miss important security updates. • Keep your phone and apps up to date. 🧠 7. Trust Your Gut • If it feels off it probably is. • Listen to your instinct before you click, open, or respond. 🔒 How to Protect Yourself: • Enable Two-Factor Authentication on your accounts. • Install a reputable security app to scan for threats. • Use strong, unique passwords and update them regularly. • Back up your data in case you need to reset your device. • Keep software updated to patch security vulnerabilities. ✅ Save this post. ✅ Share it with your team or network. ✅ And remember it’s not about being paranoid, it’s about being prepared.
-
The FBI recently issued a stark warning: AI-generated voice deepfakes are now being used in highly targeted vishing attacks against senior officials and executives. Cybercriminals are combining deepfake audio with smishing (SMS phishing) to convincingly impersonate trusted contacts, tricking victims into sharing sensitive information or transferring funds. This isn’t science fiction. It is happening today. Recent high-profile breaches, such as the Marks & Spencer ransomware attack via a third-party contractor, show how AI-powered social engineering is outpacing traditional defenses. Attackers no longer need to rely on generic phishing emails; they can craft personalized, real-time audio messages that sound just like your colleagues or leaders. How can you protect yourself and your organization? - Pause Before You Act: If you receive an urgent call or message (even if the voice sounds familiar) take a moment to verify the request through a separate communication channel. - Don’t Trust Caller ID Alone: Attackers can spoof phone numbers and voices. Always confirm sensitive requests, especially those involving money or credentials. - Educate and Train: Regularly update your team on the latest social engineering tactics. If your organization is highly targeted, simulated phishing and vishing exercises can help build a culture of skepticism and vigilance. - Use Multi-Factor Authentication (MFA): Even if attackers gain some information, MFA adds an extra layer of protection. - Report Suspicious Activity: Encourage a “see something, say something” culture. Quick reporting can prevent a single incident from escalating into a major breach. AI is transforming the cyber threat landscape. Staying informed, alert, and proactive is our best defense. #Cybersecurity #AI #Deepfakes #SocialEngineering #Vishing #Infosec #Leadership #SecurityAwareness
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development