Free Resource

How to Recognize and Report Phishing

A practical guide for employees and business owners.

Phishing is the starting point for over 90% of data breaches. This guide covers how to spot it, what to do if you clicked, and exactly where to report it.

What Is Phishing?

Phishing is a social engineering attack where an attacker impersonates a trusted person or organization to trick you into revealing credentials, transferring money, or installing malware.

Modern phishing is highly sophisticated. Attackers research your organization, spoof legitimate domains, copy real email templates pixel-for-pixel, and use urgency and authority to bypass your critical thinking. It is not a sign of low intelligence to be targeted — it is a sign that attackers consider your organization worth attacking.

Common variants include spear phishing (targeted at a specific individual), whaling (targeted at executives), smishing (via SMS), and vishing (via phone call).

Warning Signs in an Email

No single indicator is definitive — sophisticated phishing often gets most of these right. The more boxes that check, the higher the risk.

Unexpected urgency
Phrases like "Act now," "Your account will be suspended," or "Immediate action required" are designed to bypass critical thinking.
Sender address doesn't match the display name
The name says "Microsoft Support" but the email is from support@microsofft-help.com. Always check the actual address, not just the display name.
Generic greeting
"Dear Customer" or "Dear User" instead of your name suggests a mass phishing campaign, not a legitimate communication.
Mismatched or suspicious links
Hover over links before clicking. The visible text may say paypal.com but the actual URL goes somewhere else.
Unexpected attachment
Unsolicited PDFs, Word documents, or ZIP files can contain macros or malware. Don't open attachments you weren't expecting.
Request for credentials or payment
Legitimate companies don't ask for passwords, wire transfers, or gift card payments by email.
Poor spelling or grammar
While sophisticated phishing is now often grammatically correct, errors remain a common indicator — especially in mass campaigns.
Looks almost right
A logo that's slightly off, spacing that's wrong, or colors that don't match — phishing pages are copies, not originals. Trust your instincts if something feels "off."

If You Clicked or Interacted

Speed matters. The faster you act, the more damage can be contained.

1
Don't panic
Clicking a link doesn't automatically mean you're compromised. The risk increases significantly if you entered credentials or downloaded a file.
2
Don't enter any credentials
If you clicked through to a login page, close it immediately without entering anything.
3
Disconnect from the network if you downloaded anything
If you opened an attachment or downloaded a file, disconnect from Wi-Fi and your corporate network immediately to limit potential spread.
4
Change your password
If you entered credentials on a suspicious site, change that password immediately from a different device. Use a unique password and enable MFA if not already on.
5
Report it to your IT team immediately
Time matters. Your IT team can check logs, block the domain, and assess whether other employees were targeted before more damage is done.
6
Don't forward the email to coworkers
Forwarding "to warn others" spreads the phishing link further. Let your IT team handle notification.

Where to Report

Report whether or not you interacted — even a well-caught phishing attempt is worth logging so your IT team can block the sender and alert others.

First

Your IT or Security Team

This is always the first call. Forward the email as an attachment (not inline), include the headers if possible, and describe what actions you took. Most organizations have an abuse@ or security@ email address.

Second

Your Email Provider

In Gmail: open the email → three-dot menu → "Report phishing." In Outlook: select the email → "Report" → "Report Phishing." This helps block the sender for all users.

Optional

US-CERT / CISA

Report to the Cybersecurity and Infrastructure Security Agency at us-cert.cisa.gov. Especially important for attacks targeting critical infrastructure or government contractors.

Optional

FTC

Report phishing to the Federal Trade Commission at reportfraud.ftc.gov. Important if financial fraud was involved or credentials were stolen.

Optional

Anti-Phishing Working Group (APWG)

Forward phishing emails to reportphishing@apwg.org. APWG aggregates reports to help shut down phishing infrastructure globally.

Train Your Team Before an Attack Does

Anchor runs phishing simulations that show you exactly how susceptible your organization is — and trains employees on what to do differently.