PHISHING DETECTION & RESPONSE GUIDE

Modified on Tue, Sep 8 at 9:47 AM

ESSEX COUNTY 50SC

IT SECURITY ALERT

PHISHING DETECTION & RESPONSE GUIDE

Your vigilance protects our network. 

Use this quick checklist to spot and report suspicious emails immediately. If you are ever uncertain, do not click—report the email to IT right away.

⚠️ KEY INDICATORS TO OBSERVE

  • ? Suspicious Senders & Domain Discrepancies
    • The sender’s display name looks familiar, but the email address domain is strange or misspelled (e.g., invoice@wbmazon.com instead of @wbmason.com).
    • External sender warnings appear on messages claiming to be internal.
  •  Urgent, Threatening, or Fear-Based Language
    • Messages demanding immediate action (e.g., "Respond within 24 hours"), threatening penalties, or triggering sudden pop-up warnings.
  • ? Deceptive Links & Unexpected Attachments
    • Hyperlinks whose destination URL does not match the link text (always hover to preview links before clicking).
    • Unsolicited attachments, especially .pdf.zip.iso.html.xlsm (Excel add-ins), or OneNote files.
  • ? Unusual Requests & Generic Messaging
    • Requests for credentials, passwords, direct payments, or software installations outside established procedures.
    • Generic salutations, out-of-context purchase orders, or unusual replies inserted into old email threads ("thread hijacking").
    • Emails containing only an image or prompting you to call a support/callback phone number.

? RECENT EXAMPLES REPORTED AT ESSEX COUNTY

  • ? Holiday E-cards from unknown external senders.
  • ? Misrouted Purchase Orders sent to wrong departments (always verify with Fiscal).
  • ⚠️ Fake Compliance/Training Demands enforcing strict 24-hour deadlines.
  • ? Image-Only Callback Scams telling users to call a phone number for "Microsoft Assistance."
  • ? Credential Harvesting asking for your username/password to "view a report."

 

 

 

 RECOMMENDED RESPONSE ACTIONS

  1. PAUSE & DO NOT ENGAGE

Do not click links, open attachments, or call phone numbers listed in suspicious emails.

  1. REPORT IMMEDIATELY

Use Outlook’s "Report Suspicious" button or submit an IT support ticket with the full email attached.

  1. VERIFY OUT-OF-BAND

Confirm unusual business or financial requests through a known secondary channel (phone or Teams) using verified internal contact details.

  1. IF YOU CLICKED OR ENTERED CREDENTIALS:
    • Disconnect your device from the network (unplug Ethernet / turn off Wi-Fi).
    • Notify IT/Security immediately.
    • Change your password and ensure Multi-Factor Authentication (MFA) is enabled.

? NEED HELP OR NEED TO REPORT?

Contact the IT Help Desk immediately via your standard ticket portal or phone extension.





Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article