Phishing without secrets

Practical security training for everyone who uses email, a phone, messaging apps or company systems.

◎ Level: foundation↻ July 2026
01

What you will learn

  • recognise common signs of phishing;
  • inspect senders, links, attachments and QR codes;
  • verify requests involving money, data or sign-in;
  • respond to unexpected MFA prompts;
  • report an attack and limit damage after a mistake.
02

Why phishing works

Attackers try to make people reveal credentials, approve a sign-in, transfer money, open a file, scan a QR code or install software. AI makes polished and personalised messages easier to create, so perfect spelling is no proof of authenticity.

Email and SMSphishing and smishing
Calls and videovishing and AI media
QR and websitesquishing and fake sign-in
Messaging appsTeams, Slack and social media

Sources: ENISA Threat Landscape 2025 and CERT Polska, June 2026.

03

Emotions attackers exploit

⏱ Urgency⚠ Fear♛ Authority✦ Curiosity♥ Helpfulness⌁ Opportunity◐ Secrecy↻ Routine

Pressure + secrecy + an unusual request is a particularly strong warning.

04

Warning signs

Sender

  • inspect the full address, not the display name;
  • look for changed letters;
  • notice a sudden change in writing style.
anna@company.com
anna@cornpany.com

Message

  • threats, urgency or secrecy;
  • a changed bank account;
  • requests for passwords, MFA or remote access.

Link

  • preview it without clicking;
  • read the real domain from the right;
  • a padlock does not make a site honest.
microsoft.customer-help.example

Attachment and QR

  • do not enable macros or editing;
  • beware ZIP, HTML and executable files;
  • do not sign in through an unexpected QR.

MINI CHALLENGE

How many red flags can you spot?

From: CEO <board@sentlvaro-support.example>
Subject: CONFIDENTIAL — payment needed in 20 minutes

I am in a meeting. Do not call. Buy gift cards and send me the codes. Urgent.

Reveal the answer

At least six: a lookalike domain, urgency, secrecy, an unusual request, bypassing procedure and blocking independent verification.

STOP — CHECK — REPORT

01

STOP

Do not click, reply, scan the QR code or open the attachment.

02

CHECK

Call a known number, start a new message or open the official app. Never use contact details supplied in the suspicious message.

03

REPORT

Use your organisation’s reporting button or contact IT. Keep the message available for analysis.

05

Money, data and identity

Independently verify bank-detail changes, urgent payments, gift cards, cryptocurrency, customer lists and every request to bypass approval. Voice, video and writing style can be forged with AI.

  • call back using a number you already know;
  • apply the four-eyes principle;
  • follow formal approval even for an apparent executive request.
06

Passwords, passkeys and MFA

Use unique passwords and an approved password manager. Never enter credentials after following an unexpected message or share an MFA code. Phishing-resistant FIDO/WebAuthn, such as a passkey or security key, offers the strongest protection.

CISA guidance on MFA

07

What if you clicked?

I only opened the link

Close the page, download nothing and tell IT the time and device involved.

I entered credentials or an MFA code

Report it immediately, change the password through the official site, update reused passwords and sign out unknown sessions.

I opened a file or installed software

Stop using the device, preserve evidence and follow your IT team’s instructions.

I transferred money or shared card data

Contact the bank and your organisation immediately, preserve evidence and report suspected crime.

Silence is the worst response. A fast report can stop an attack. Mistakes should lead to support and learning, not blame.