← Back to SGS UniversityAwareness CoursePhishing Awareness
Learn how phishing works, how to spot warning signs, and what to do before a fake message becomes a serious incident.
Course Overview
Phishing is a method attackers use to trick people into giving away passwords, payment details, business information, or access to systems. It often arrives by email, text message, social media, or messaging apps.
The goal of this course is to help users pause, inspect, and verify before clicking or responding.
AdvertisementAuto Ads may use this space after approval.
What You Will Learn
- How phishing messages create pressure.
- Common red flags in fake emails and links.
- How fake login pages steal passwords.
- What to do after a suspicious click.
- How organizations can reduce phishing risk.
Lesson 1: Phishing Uses Emotion
Attackers often use fear, urgency, reward, curiosity, or authority. A message may claim your account will close, a payment is overdue, a package is waiting, or a senior manager needs urgent action.
Lesson 2: Check the Sender and Link
Look carefully at the sender address, spelling, domain name, and link destination. A message can look official while sending users to a fake or lookalike website.
Lesson 3: Fake Login Pages
A common phishing trick is to send users to a login page that looks real. Once the user enters a password, the attacker captures it. MFA can help, but users should still verify links before logging in.
Lesson 4: Attachments Can Be Dangerous
Unexpected invoices, forms, reports, or zip files may carry malware or lead to credential theft. Open attachments only when the source and purpose are verified.
Lesson 5: Report Quickly
If someone clicks a suspicious link or enters credentials, quick reporting matters. Change passwords, revoke sessions, check MFA settings, and alert the appropriate support contact.
Practical Checklist
- Pause before responding to urgent requests.
- Verify payment or password requests through another channel.
- Do not enter passwords from unexpected links.
- Report suspicious messages instead of forwarding them widely.
- Use MFA on email and administrator accounts.
Quick Quiz
1. Name two emotions phishing messages often use.
2. What should you check before entering a password?
3. What should you do after entering credentials on a suspicious page?
Scan Your Website