Knowledge base

Cyber security awareness for users

Security awareness for users: recognise phishing red flags such as fake domain names, altered account numbers and fake login pages.

Need support? +31 45 303 0003 Advice or a quote? +31 45 303 0232

Available across the EU, delivered remotely.

We receive signals from various sources of people who receive an email from someone they know, containing a link to a Microsoft 365 document. This lures them to a fake login site, where their login details and multi-factor authentication code are stolen. This gives criminals access to company data, and they then try to persuade contacts to change bank account numbers.

Red flags: when should all the alarm bells go off?

“Our bank account number has changed!”

Does someone ask you to change a bank account number? Always verify this by phone. Emailing is pointless: if the email account has been hacked, it’s the cybercriminal who confirms that the number has changed. So always verify by phone, using a number you already had.

Fake domain names

Always check the domain name of the site you’re logging in to very carefully. Login sites are perfectly replicated, making it increasingly difficult to spot this. Sometimes a domain name contains very small typos, such as microsoft.corn instead of microsoft.com (where the r and n together resemble an m), or login.microsoftonlline.com with a double l instead of login.microsoftonline.com. A domain name such as abnamro.nl.com, with two extensions in a row, is also a red flag.

Do you need to log in? Open the login portal yourself rather than clicking a link in Outlook or Teams.

Dutch domain names and websites

Dutch companies usually have a .nl or .eu domain name. Be extra alert if a Dutch company suddenly uses a different extension.

Websites are perfectly replicated

Sometimes entire websites are replicated, making it seem as though you’re on the company’s site. If in doubt, look up the company via a search engine such as Google or Bing and check the domain name there.

Someone you know asks you something from a different number

With AI technology, a few seconds of voice recording is enough to make someone say anything they never actually said. Be alert to unusual requests from people you know and always verify this in person.

Don’t get caught: understanding and preventing phishing scams

Imagine starting your day with a cup of coffee, ready to tackle your to-do list, when an email from a trusted partner appears in your inbox. It looks legitimate, but it contains a phishing trap set up by cybercriminals.

This scenario is becoming increasingly common, at both large and small companies.

Phishing scams are evolving and becoming more sophisticated every day. As a decision-maker, it’s crucial to understand these threats and dispel common myths, so you can protect your business effectively.

Many people think phishing scams are easy to spot, through poor grammar, suspicious links or obvious requests for personal information.

That is far from the truth. Modern phishing attacks are highly sophisticated and therefore difficult to recognise. Cybercriminals use advanced techniques such as AI to create emails, websites and messages that closely resemble legitimate communication from trusted sources.

Most phishing attempts now look authentic, with logos, house style and language from well-known companies or people. As a result, even well-trained people can fall victim to a cleverly disguised phishing attempt.

Different types of phishing scams

Phishing scams come in various forms, each exploiting a different vulnerability. Knowing the most common types helps you protect your business better:

  1. Email phishing: the most common type. Cybercriminals send emails that appear to come from legitimate sources, such as banks or well-known companies. These emails often contain links to fake websites used to steal sensitive information.
  2. Spear phishing: targets specific individuals or organisations. Attackers gather information about their target to create personalised and convincing messages. This makes it particularly dangerous, as it can bypass traditional security measures.
  3. Whaling: a form of spear phishing aimed at high-ranking individuals, such as directors and executives. The goal is to get them to disclose sensitive information or approve financial transactions.
  4. Smishing: phishing messages via text message or other text-based messages. These messages often contain links to malicious websites or ask the recipient to call a phone number and provide personal information there.
  5. Vishing: phone calls from attackers posing as a trusted party, such as a bank or technical support, asking for sensitive information.
  6. Clone phishing: attackers copy a legitimate email you previously received and replace the links or attachments with malicious ones. This tactic exploits trust, making a fake email hard to distinguish from genuine communication.
  7. QR-code phishing: cybercriminals use QR codes to direct victims to malicious websites. These codes often appear on flyers, posters or in email attachments. Scanning the code leads to a phishing site.

Frequently asked questions

How do I know whether an email with a login link is trustworthy?

It's wise never to log in via a link in an email, even if it seems to come from someone familiar. It's better to open the login portal yourself in your browser rather than clicking a link in Outlook or Teams. This prevents you from ending up on a fake login site where your details are stolen.

What should I do if someone asks to change a bank account number?

Always verify such a request by phone, using a number you already had, not by email. If the sender's email account has been hacked, it's the cybercriminal who confirms that the number has changed. Phone verification is therefore the only reliable way to check this.

How do I recognise a fake domain name?

Watch closely for small typos, such as microsoft.corn instead of microsoft.com, or extra letters like login.microsoftonlline.com. A domain name with two extensions in a row, such as abnamro.nl.com, is also a sign that something is wrong. If in doubt, look up the company via a search engine and check the correct domain name there.

Can phishing emails still be recognised by poor language or odd links?

No, that idea no longer holds true. Modern phishing attacks are highly sophisticated and use logos, house style and language that closely resemble genuine communication from trusted companies or people. As a result, even well-trained people can fall victim to a cleverly disguised phishing attempt.

What forms of phishing exist besides email phishing?

Besides email phishing, there is also spear phishing, aimed at specific individuals, and whaling, which targets directors and executives. There is also smishing via text message, vishing via phone calls, clone phishing with copied emails, and QR-code phishing via malicious QR codes. Each type exploits a different vulnerability, which is why it's important to know the most common forms.

Getting acquainted · which step suits your organisation?

You will be speaking with Ralph Dykstra

Founder and owner of B/Focused

A conversation of about 30 minutes in which we get to know your organisation and look at the challenges, risks and opportunities in your IT environment.

Advice or a quote? Sales
+31 45 303 0232
Need support? Service desk
+31 45 303 0003