ClearSecurity VISION
EN / RO
← All articles

Training · 6 July 2026 · 6 min read

How to spot a phishing attack before it's too late

Three signals that give away a phishing email — artificial urgency, look-alike domains, unusual requests — and what to do about them with your team.

ClearSecurity Vision

Year after year, phishing remains the most common way into an organization. Not because email filters or antivirus are missing, but because attackers target something no software can patch: the way people react when they are rushed, tired, or squeezed between two meetings.

The good news: the vast majority of phishing emails share the same handful of tells. Once you know them, you see them. And once your team knows them, an attack that would have cost weeks of cleanup ends with one email reported and deleted.

Here are the three signals that show up most often — and what to do about each.

Signal 1: artificial urgency

“Your account will be locked in 24 hours.” “This invoice is due today.” “The CEO needs this payment before noon.”

Time pressure is not an accident — it is the mechanism of the attack. The attacker knows that a person with time to think asks questions: why is my bank asking for this now? Why is this coming from that address? So they take your thinking time away. Any message that demands you act immediately, under threat of a consequence — a locked account, a penalty, a missed opportunity — deserves exactly the opposite reaction: slow down.

A simple reflex to build into your team: the harder an email insists it is urgent, the more it deserves a 30-second pause. Real institutions — banks, vendors, authorities — do not resolve serious matters through a single email with a countdown.

Signal 2: domains that look right but aren’t

microsoft-security.com is not Microsoft. netflix-account.net is not Netflix. The difference between the real domain and the fake one is often a hyphen, a doubled letter, or a swapped ending — precisely the kind of detail the eye skips when skimming on a phone.

What you can check in a few seconds:

  • The sender’s address, not the display name. Anyone can type “Microsoft Support” as a name; the actual address behind it is what matters.
  • The link, before you click. On a computer, hover over the link and look at the address that appears. On a phone, long-press the link to see the real destination.
  • Everything before the first ”/”. That is the real destination. microsoft.com.account-check.net takes you to account-check.net, not to Microsoft.

If you have even the slightest doubt, do not use the link in the email. Open your browser and go to the institution’s site the way you normally would — an address you typed, not one the message served you.

Signal 3: requests no legitimate party makes

No serious vendor asks for your password by email. No bank asks for your PIN or full card details “for verification”. No executive asks you, in a short and unusually polite message, to buy gift cards or wire money to a new account.

Unusual requests are the easiest signal to miss, because they arrive wrapped in plausible context: an invoice from a supplier you genuinely work with, but with an “updated” bank account; a message from “the CEO” on exactly the day the CEO is traveling. The rule that cuts through it: any request involving money, passwords, or access credentials gets verified on a different channel than the one it arrived on. A phone call to the number you already know — not the one in the email signature — settles in two minutes what a misdirected payment never settles at all.

What to do when in doubt

Three things, in this order:

  1. Don’t click, don’t download, don’t reply. Not even “unsubscribe” — it only confirms your address is live.
  2. Verify through another channel. Call the person or institution, or go directly to their website.
  3. Report it internally. Even if it turns out to be a false alarm. A suspicious email reported early can be exactly the warning that protects the rest of your colleagues — the same message rarely lands in just one inbox.

And if someone did click or enter a password: the sooner they say so, the easier the damage is to contain. A password changed within 10 minutes is an incident avoided; one changed after three days of silence is an investigation.

Internal simulations: measurement, not a blame hunt

The most effective way to find out how exposed your organization really is isn’t a questionnaire — it’s a phishing simulation: realistic test emails sent to your own employees in a controlled setting.

One condition is essential, though: the simulation measures the system, it does not punish the people. The moment those who click get sanctioned or exposed in front of colleagues, you have broken the only thing that truly matters — people’s willingness to report. Next time, the person who slips up will stay silent. And silence, not the click, is what turns a small incident into a large one.

Used properly, a simulation shows you where training is needed, which roles are targeted most (finance, assistants, leadership), and whether your awareness program actually changes behavior from one round to the next. Experience shows click rates drop measurably after a well-built training program — but the exact number depends on your organization, your starting point, and the quality of the program, not on a promise from a flyer.

What this has to do with NIS2

If your organization falls under NIS2 — transposed in Romania through OUG 155/2024, approved by Law 124/2025 — awareness is no longer optional. The security measures required by law include basic cyber hygiene and employee training, and management itself is required to undergo security training. In other words: a real anti-phishing training program isn’t just operational common sense — it’s a requirement DNSC can check.

The encouraging part is that the two goals overlap perfectly: the same program that reduces your real risk also satisfies the legal obligation. The reverse does not work — a PDF emailed once a year changes no behavior and convinces no auditor.


Spotting phishing is not an innate talent; it is a muscle you train: clear signals, realistic exercises, and a culture where reporting is praised, not penalized. If you want to build exactly that in your organization — role-based training, phishing simulations without a blame hunt, and measurable progress — see our security awareness training service or get in touch.

Want to see how fast you spot the signals? Try the “First 30 Days” game — 3 minutes, no account.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.