Saltar al contenido principal
Cybersecurity

Phishing at work: how to spot a fake email and what to do if someone takes the bait

7 min readiDeo Networks technical team

Phishing today is spotted through context, not bad spelling: it creates urgency, changes bank details, asks for credentials or arrives exactly when you were expecting something. If someone has already taken the bait, the first steps are disconnecting the device, changing passwords from another machine and alerting whoever handles IT: every minute counts.

What phishing looks like now

The misspelled email with odd accents is gone. Today’s phishing mimics the design of a real supplier, arrives inside a legitimate email thread (because the recipient’s mailbox was already compromised) and uses domains almost identical to the original: one letter changed, an extra hyphen, a different country extension.

The most expensive campaigns are not after loose passwords: they impersonate a director requesting an urgent transfer, or a supplier announcing a change of bank account. There is no suspicious link or attachment: there is a perfectly reasonable request, addressed by name.

  • Urgency and secrecy: "do it now and don’t mention it yet"
  • A change of bank account on an invoice you were already expecting
  • It asks for credentials, verification codes or payment details
  • The link does not match the sender’s domain
  • An attachment nobody told you was coming

What to do in the first minutes after someone takes the bait

If an employee has entered credentials, opened an attachment or started a payment, the order of the first steps matters more than the polish of each one:

  • Disconnect the device from the network (unplug the cable or switch off Wi-Fi) without powering it down completely
  • Do not delete the email or the traces: they show the scope of the incident
  • Change the affected passwords from a different, clean device
  • Alert whoever handles IT or your maintenance provider
  • Check the mailbox for forwarding rules and auto-replies created without consent
  • If a payment went out: contact the bank immediately and request a recall

The costliest mistake: believing antivirus is enough

Antivirus stops last year’s malicious file; today’s phishing is one person persuading another. That is why companies that suffer an incident almost always tell the same story: "we had antivirus". They did. And the email sailed past every filter, because there was nothing technical to filter.

Real defence has layers: email filtering that verifies the sending domain (SPF, DKIM and DMARC), multi-factor authentication on every access, tight permissions so one compromised account cannot roam freely, and verified backups so you never have to negotiate with a data hijacker.

And the team? Training that actually works

Anti-phishing training is not an annual video everyone clicks through at double speed. What works is what gets practised: regular simulations, visible warnings on external email, and above all one cultural rule repeated until it sticks: if an email asks for money, data or haste, verify it through another channel. A thirty-second phone call prevents the overwhelming majority of cases.

And nobody should feel they must hide that they clicked: the employee who reports within two minutes is the best detection system a company can have. The one who fears punishment stays quiet until there is nothing left to do.

How we approach this at iDeo Networks

Within iDeo Shield we manage security for companies across Spain, including the Canary Islands, the Balearic Islands, Ceuta and Melilla: email configuration and domain verification, multi-factor authentication, 24/7 monitoring, incident response and periodic reviews with a clear report, no jargon and ordered priorities.

If you have just been through an incident, we handle containment first and then, calmly, whatever needs closing so it does not happen again.

Related services

Received a suspicious email, or has someone just taken the bait?

Tell us now: if there is still time, the reaction in the first minutes makes all the difference.

Talk to a technician

More articles