Phishing (cybersecurity)

Cybersecurity Awareness Fact Sheet

For public distribution – Updated April 2024

Phishing is when threat actors use fake emails, phone calls (vishing), or text messages (smishing) to lure you into clicking on malicious links, sharing your personal information, or installing malware on your device. Phishing remains one of the top cybersecurity threats to both personal and professional systems.

Phishing Red Flags

Phishing messages have become very sophisticated and often look legitimate, so you must look closely to spot suspicious characteristics including:

  • Unknown sender, potentially disguised as a more familiar sender
  • “From” email address with a slight variation on a familiar address. For example, an address that ends in state.com instead of state.gov: security@state.com
  • Sense of urgency, particularly with regards to compensation, benefits, job opportunities, or unusual requests appearing to come from senior leadership
  • Impersonation of a legitimate account alert from a familiar brand such as Microsoft, both in layout and content
  • Hyperlinks that don’t match up with the URL that appears when hovering over the link
  • Unexpected attachments that have suspicious names or file endings

Tips & Best Practices

  • Carefully examine messages from unverified senders, especially if they contain links or attachments. AI tools can generate well-written phishing messages that sound natural, making them seem legitimate.
  • If a message seems suspicious, don’t click any links or attachments and don’t respond to the sender.
  • If you receive an unexpected message requesting sensitive personal information, contact the sender directly instead of replying or using the contact information listed in the message.
  • Enable multi-factor authentication (MFA) on online accounts when available for an extra layer of protection.
  • Make your passwords long and strong. Do not reuse passwords across accounts.
  • Install and regularly update anti-virus software, firewalls, and anti-spyware.

Questions? Refer to CISA’s phishing infographic.

Phishing Reporting

  • Report suspected phishing emails received on your work email to your organization’s appropriate security teams.
  • Report suspected phishing messages received on personal accounts to the platform and the Federal Trade Commission.

Diplomatic Security Service
U.S. Department of State