• Trg mladosti 6, 3320 Velenje
  • info@racunalniske-resitve.si

Phishing attacks on our mail server: caution is the best defence

Phishing has become an increasingly widespread and sophisticated way to steal sensitive data and gain access to user accounts. We have recently detected several such attacks on our mail server. Although their content varies, they use similar tactics to exploit our trust and lapses in attention. In this article, we look at some of the examples we have encountered and explain how you can protect yourself against these malicious attempts.

Parcel delivery notification

One common type of phishing attack we have detected involves emails notifying users about a parcel. The email usually claims that your parcel has arrived and is awaiting collection, or that delivery failed because of an incorrect address. It normally contains a link to a website where you can supposedly track the parcel, but the site is actually fraudulent and attempts to obtain your personal data or install malicious software on your computer.

System breach

Another type of phishing attack we have detected involves emails claiming that your account or system has been breached. The email warns you about suspicious activity and urges you to act immediately to protect your data. Such messages may contain links to fraudulent websites designed to obtain your username and password, or ask you to download malicious software. To keep your data secure, we recommend that you do not click links in suspicious emails or send cryptocurrency, such as bitcoin, to unknown recipients.

Password reset

Phishing attacks that demand a password reset are another common form of attack we have encountered. In these cases, you receive an email claiming that your password has expired or that a security incident requires you to change it immediately. The message contains a link to a fraudulent website where the attackers try to persuade you to enter your current password and create a new one. Once you do so, they gain access to your account.

How to protect yourself against phishing attacks

Although phishing attacks are becoming increasingly sophisticated, there are several ways to protect yourself:

  • Check the sender: Before opening an email or following a link, check the sender's email address. If the address looks suspicious or does not match the organisation it claims to represent, treat this as a warning sign of a possible phishing attack.
  • Check the link URL: Before clicking a link in an email, make sure that its destination is genuine. Hover over the link without clicking it. The displayed address should be appropriate and secure (it should begin with "https://"). Pay close attention to the domain as well, because fraudulent domains often look very similar at first glance.
  • Do not share personal data: Never share personal information such as passwords, credit card numbers or bank account details by email. Genuine companies will never ask you to do this.
  • Use two-factor authentication: Two-factor authentication adds another layer of security to your account. Even if attackers obtain your username and password, they will also need access to your phone or another device before they can access your account.
  • Keep your software up to date: Regularly update your operating system, browser and antivirus software to help protect your computer against malicious software.
  • Stay informed: Keep up to date with new types of phishing attacks and the tactics attackers use. This will help you recognise potentially malicious emails and websites.

Phishing attacks are a threat that must be taken seriously. Understanding the different types of attack and the tactics they use is essential for protecting your personal data and accounts. Follow the advice above to recognise and protect yourself against potential phishing attacks that may appear in your inbox.

We will assess free of charge whether your organisation could withstand this type of attack. Send us an enquiry and we will arrange a brief security audit. Enquire now