SEPTEMBER 2026 · THE TOOL DESKPractical technology. No theatre.

Practical guide · verified against the real thing

The phishing drill: five real lures and the one tell that gives each away

In one line: Run the same ten-second check on every message and most lures collapse. Here are the five most common shapes, and the specific tell that breaks each one.

Phishing works by borrowing trust - your bank's logo, a colleague's name, a delivery you were half-expecting. You cannot defend against it by feeling; you defend against it with one mechanical check, applied every time. The check is: who is the message actually from, and where does the action actually lead? Everything below is that check applied to the five lures you will actually meet.

1. The urgent delivery problem

"Your parcel could not be delivered; pay a small fee." The tell: the sender domain and the link domain disagree with the courier's real one. Hover or long-press the link and read the address, not the blue text. A courier you never used is a certainty, not a suspicion. The mechanics of reading the address are covered in how to spot a suspicious link.

2. The account problem that needs you now

"Unusual sign-in; confirm your password." The tell: legitimate services ask you to sign in on their site; they never need your password inside a message or a linked form. The fix is to never follow the link - type the address you already know, or use a bookmark, and check for the alert there. If it is real, it will be waiting for you.

3. The colleague in a hurry

A short, slightly-off request from a familiar name - a gift-card or transfer ask. The tell: a new or lookalike address, and pressure that discourages a second channel. The defence is not cryptographic, it is social: confirm over a channel the message did not arrive on. Ten seconds of "did you send this?" ends the attack.

4. The document or invoice you weren't expecting

An attachment or shared file with a plausible name. The tell: you did not expect it, and the sender is vague. Unexpected attachments from real contacts usually mean their account is already compromised - so the message is being sent by someone you know, without them knowing. When in doubt, open nothing and ask them directly.

5. The refund that owes you money

"We owe you a refund; enter your card to receive it." The tell is inverted from the others: instead of fear it uses greed, and it asks for card details to give you money, which no real refund ever requires. Refunds go back to the card you paid with; nobody legitimate needs new card numbers to send you your own money.

The one habit that covers all five

Slow down exactly when the message tries to speed you up. Urgency is the payload; the link is just delivery. Keep the checklist handy, and treat two-factor as the seatbelt for the lure that still gets through: it turns a stolen password into a failed login.

Sources

Next

Related on this desk.