Skip to main content
All lessons
Lesson 2Social Engineering Defense pathway

Stop Phishing Before You Click

Verify the sender, check the link

Highlighted wordsare glossary terms — tap one for a plain-language definition.

is still the front door to most account takeovers, but it is also one of the most preventable attacks. Three habits cover almost every email scam: verify the sender through a channel you control, read the link before you click, and let a guard the sign-in. [1, 2, 3]

Verify the sender, not the display name

The name at the top of an email — and even the logo — costs a scammer nothing to fake. The FTC's guidance is unambiguous: legitimate companies don't ask for passwords, payment details, or personal data by email, and any message that creates urgency ("your account will be closed today") is a pressure tactic. When a message claims to be from a company you actually deal with, don't reply or call the number in the email — reach the company through the number on your card, your app, or the address you type yourself. [2, 3]

  • Expand the From details and compare the reply-to address with the sender's real domain.
  • Treat urgency, threats, and limited-time offers as red flags, not proof.
  • Verify any request to pay or update details using a phone number or website you look up yourself.
  • Unexpected attachments — even invoices — stay unopened until you confirm them.

Let a password manager be your gatekeeper

A password manager does more than remember logins — it quietly detects phishing. It saves each password against the exact site address, so it will only fill the form on the genuine domain. When a convincing 'bank' page appears and the manager offers nothing, that silence is the alarm. CISA recommends password managers as the easiest way to use strong, unique passwords everywhere, and NIST 800-63B backs the approach: length beats complexity tricks, so let the manager generate long random passwords and don't reuse or rotate them on a schedule. [1, 2, 4]

  • Use a reputable password manager to generate a long, unique password for every account.
  • Treat a manager that won't autofill on a familiar site as a phishing warning — stop and check the address.
  • Never copy and paste a saved password into a page you arrived at from an email or text.
  • Skip 'compose a clever password' rules — length and uniqueness are what matter.

Report it, then move on

Reporting makes everyone safer: your workplace's report button lets defenders pull the campaign before others click, and forwarding scam texts to 7726 (SPAM) helps carriers block the sender. If you did click and entered a password, act fast — change that password everywhere it was reused, sign out other sessions, and turn on . The full recovery sequence lives in the Security incident plan lesson. [1, 3]

  • Report suspicious email through your email provider's or workplace's report option, then delete it.
  • Forward scam texts to 7726 so your carrier can act.
  • Clicked and typed a password? Change it now, sign out other sessions, and enable MFA.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary