Cybersecurity essentials · Lesson 3 of 5
Pause before the click
Phishing uses a message to push you toward an unsafe action. A familiar name or polished design is not proof that a request is trustworthy.
Read past the familiar name
Fictional email to a learner at acme.example.
- Display nameIT Support
A name or logo can be copied.
- Actual senderhelp@acme-reset.example
A different domain deserves scrutiny.
- PressureYour account closes in 15 minutes
Urgency pushes you to skip verification.
- Displayed destinationacme-reset.example/verify
Use the known portal instead. This example is not a link.
Read the visualWhere should you verify the request?
Use a known app, bookmark, or trusted IT contact. The suspicious message should not supply its own proof.
Look beyond the display name
Check the actual sender and destination, not just the logo or the words on a button.
Notice the pressure
Threats, urgency, and unexpected requests for sensitive information are reasons to slow down.
Verify independently
Open a known app or use a trusted contact method instead of a link or number supplied in the message.
Put it in context
A fictional message says your Acme account closes in 15 minutes. The destination shown is acme-reset.example, not your usual company portal. That is a reason to verify, not a reason to rush.
Pause, verify through a trusted route, and report suspicious messages.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.