publishing date icon
February 6, 2024
read time icon
5 min. read

“A Friendly Warning”: Phishing Emails Posing as Alerts

Post hero image

Table of contents

Reduce your human cyber risk
Hoxhunt's adaptive security training dramatically increases engagement and security resilience.
Learn more

Cybercriminals are at it again with a clever new tactic to trick people into giving up their information. In an unexpected twist, they're sending emails warning you about phishing attacks.

What's the story behind this sneaky approach? How can you ensure that you don't get caught in the net?

This new tactic might trick even those familiar with phishing strategies

We're used to getting phishing emails that attempt to steal our personal information. How about getting an email that looks legitimate and warns you about the dangers of phishing?

The message may seem helpful, telling you to protect your account or check your information to stay safe from malicious actors. But here’s the catch: this email is part of a phishing campaign.

This method is clever because it's so simple. It appears to be a friendly warning from a source you can trust. This new, subtle tactic could trick even people familiar with common phishing strategies. Occasionally, these campaigns are clone phishes that use duplicates of legitimate emails from trusted companies to increase credibility.

Nordea clone phish warning users of phishing scams

Protecting yourself from fake phishing alerts

These misleading phishing alerts may appear to come from real, trustworthy companies. It’s important to stay vigilant with emails, even when they seem to be from sources you recognize.

Here's our three tips for protecting yourself:

1) Pay close attention to the sender’s email address and try to spot any anomalies

For instance, would you notice the difference between dhl.com and dhI.com? When it comes to phishing, the devil’s often in the details!

2) Do a little detective work before clicking

Hover your mouse over the link to reveal the real URL it leads to—but remember, no clicking!

3) Genuine organizations rarely ask for your personal information, like passwords or social security numbers, over email.

Keeping up with the sly moves of cyber attackers is a crucial part of staying cyber-safe. To learn more about the latest threats and how to spot them, subscribe to Hoxhunt’s weekly Threat Feed below.

Sign up for our weekly Threat Feed to receive a summary of the week's live phishing threats to your email, every Friday.‍

Subscribe to All Things Human Risk

Subscribe to our newsletter for a curated digest of the latest news, articles, and resources on human risk and the ever-changing landscape of phishing threats.

We're committed to your privacy. Hoxhunt uses the information you provide to us to contact you about our content, products, and services. You may unsubscribe from these communications at anytime. For more information, check out our Privacy Policy.