C1.1Not started

Recognising phishing in 30 seconds

Reading depth

What you'll learn

Slow down. Domain, link target, urgency, ask — check all four.

  • Four checks: sender domain · urgency · link target · credential ask.
  • Hover before you click; type domains by hand if uncertain.
  • Wire-transfer / gift-card / MFA-code asks → call the person on a known number.

Most phishing fails one of four checks: the sender domain doesn't match the brand (e.g. it claims to be from your bank but the domain is bank-secure-portal.com); the urgency is artificial ("act in the next 4 hours"); the link target on hover doesn't match the visible text; or the request asks for credentials, payment details, or to forward an MFA code.

Run the 30-second triage: (1) check the sender domain character-by-character; (2) hover the link and read the actual target; (3) ask yourself whether the email pressures you to skip verification. If any of the three fails, do not click and do not reply.

Spear-phishing — the targeted variant — gets the sender domain right by spoofing or compromising a real account. The remaining tells are: unexpected channel for the topic (CFO asking for gift cards via email is the canonical example), and any "please don't loop in finance/legal" preamble.

Key points

  • Four checks: sender domain · urgency · link target · credential ask.
  • Hover before you click; type domains by hand if uncertain.
  • Wire-transfer / gift-card / MFA-code asks → call the person on a known number.

Pitfalls

  • Clicking 'unsubscribe' on a phishing email — it confirms your address is live.
  • Replying with 'Is this legit?' — same problem.

Ask your security team

In a real Adept rollout this routes to your company's security Claude project; in the demo it opens a fresh Claude chat.