
In a perfect world, your email inbox would only contain emails from friends and
companies you do business with. Unfortunately, your email inbox is a virtual
playground for people looking to do more harm than good.
There has long been a problem with hackers trying to get your financial info and
passwords by pretending to be someone you do business with — often a bank, a
credit card company, or a retailer you've made purchases from. But there's also
a growing problem with scammers pretending to be someone you interact with in a
work context — either a work colleague or someone from a company your employer
does business with. These scammers can then trick you into either downloading
malware onto your computer or divulging confidential information about your
work.
These types of email scams are known as phishing. A 2019 report by PhishLabs, a
company that monitors and mitigates hacking threats, found that phishing
attempts in 2018 increased by more than 40% compared to the previous year. And
with more people working from home, phishing attempts are on the rise2 for
2020.
But what is phishing exactly, and how can you protect yourself?

Did you know? Scammers
try to appeal to your emotional side by spoofing the name of a person or company
you know so that you feel a sense of trust.
Phishing is when someone sends fraudulent emails in an attempt to access your
personal information — or to manipulate you into giving them your personal
information directly. And these emails typically look very credible. Here are a
few examples of phishing emails:
Phishing's effectiveness relies on what cybersecurity experts call "human
fallibility." In other words, it's not a weakness of a particular hardware or
software configuration that makes people vulnerable; instead, it's human nature.
With phishing, scammers try to appeal to your emotional side by spoofing the
name of a person or company you know so that you feel a sense of trust. Or
they'll try to bring out your inner curiosity by dangling a link to a Google Doc
or Dropbox file, leaving you wondering what it contains.
Another common tool for these scammers is urgency. The email you receive might
say that your account has already been compromised and you need to act quickly,
or that a co-worker needs something immediately before you both get fired.
Whatever the context, the goal is to get you to act without thinking.
Everyone who uses email is potentially at risk of falling victim to a phishing
attempt. But people who work from home are somewhat more at risk because of the
nature of their workday. In an office setting, it's easy enough to drop by your
coworker's cube to ask about that unexpected file they sent — or that urgent
request that required emailing some of your company's financial information. At
home, you may grow accustomed to just responding to those emails from colleagues
and outside vendors — and responding promptly.
Additionally, the average person's home computer and network is typically not
set up as securely as it would be in the office. And this makes people
vulnerable to malware and ransomware attacks if they open a malicious file or
click on a malicious link.
5 Tips for spotting a phishing email

Scammers have no shortage of tricks they'll use to try to get your money, your
steal information, or gain access to your email account. One set of strategies
is called phishing,
a clever play on words to describe the act of virtually fishing for a victim.
Unfortunately, phishing attempts are on the rise. A 2019 report by PhishLabs, a
company that monitors and mitigates hacking threats, found that phishing
attempts in 2018 increased by more than 40% compared
to the previous year. And with increasing numbers of people working from home,
experts suggest phishing
attempts will continue to rise.
While scammers are getting more creative, these tips can help you weed out a
legitimate email from a phishing attempt — whether it's in your personal inbox
or your professional one.

Did you know? Scammers try to appeal to your emotional side by spoofing the name
of a person or company you know so that you feel a sense of trust.
1. Look at the sender's email address
If an email you receive seems suspicious, the first place to look is at the top
of the page, where you'll find the sender's email address. Most scammers attempt
to closely mirror a known email address to trick you into thinking you're
getting that email from a trusted source. However, there will typically be
subtle differences.
For example, your financial institution usually sends customer emails from
“customerservice@bankname.com." A spammer may mimic an official email address by
adding to the web address or by changing the name of the sender, such as
“customerservice@bankname.admin.com" or "adminservice@bankname.home.com."
While you should never click on links or attachments if the email address itself
is suspicious, don't assume you can always trust every email coming from a known
email address — even if it's from someone you trust. Hackers can gain access to
someone's email account and then send you an email from that account. That's why
you need to be alert to other hints of fraud as well.
2. Pay attention to the greeting
The email's greeting can also be a tip off. See if it matches greetings you've
received from the same company or person in the past. For example, any
colleagues or companies you do business already know your name and would address
an email to you by your name. Greetings like “Dear sir/madam" or “Dear valued
customer" can be a giveaway that it's a scammer. If your name is misspelled,
that's another red flag.
3. Dust off your proofreading skills
Typically, phishing emails contain at least one — and sometimes several —
spelling and grammar mistakes. In some cases, those errors could be intentional,
as a way to get past your email server's spam filter. In some cases, the email
may have been translated from another language, leading
to errors in common terms and sentence structure. Whatever
the case may be, catching those errors — and not clicking on anything in the
email — can keep you and your inbox safe.
4. Hover before you click
As a rule, make a point to never click on hyperlinks in any email without
examining them first. Simply hover your mouse pointer over the hyperlink to
reveal what web address the link is directing to. Often, this can be an easy way
to spot a phishing attempt since scammers rely on fake websites. Look for these
clues:
For example, “yourbankname.com" is more trustworthy than “your1bank2name3.com,"
but you should also be on the look out for more subtle differences like
"yourbankname.com.net."
With more people working from home and phishing on the rise, be careful too if
you receive a link that seems to be coming from a colleague's email address.
It's not impossible that their email was hacked. If you weren't expecting the
link and there's no specific context about why they sent it, confirm with the
supposed sender that they intended to send you the link.
5. Be wary of attachments
Attachments are a common phishing tool. They're designed to pique your curiosity
and make you rush to open them. Be careful with any attachments you receive,
including ones to cloud storage sites like Dropbox and Google Docs. Before
clicking any attachment, ask yourself if the sender would likely send that to
you. For example, if you suddenly receive an email from a colleague who never
emails you and the email asks you to download an attachment, that's a red flag.
Another potential read flag: You receive an unexpected attachment from a
colleague or a person you do business with — but it's lacking specific context
that explains why they are sending it to you. If you have any doubts, call,
text, or email the supposed sender to confirm that they did, in fact, send the
attachment.
If you think an email you received might be a phishing attempt, don't click any
links, don't download any attachments, and don't reply. Instead, call the
company or person who sent you the email directly. If you find that the email
isn't legit, report it as a phishing attempt to your email provider. Most
providers give you the option to report phishing attempts directly from the
suspicious email. If you're not familiar with your provider's protocol, an
Internet search for your email provider plus "report phishing" is a good way to
find instructions.
What to expect from your bank
It's important to know that your bank will never ask you to share personal or
private information by email. For example, while Synovus does send emails
occasionally with content about our products and services, we never ask our
customers to share any sensitive information by email.
If you receive an email from your bank that asks you to share any confidential
information, such as your bank account number or Social Security number — or if
the email provides a link where you should update your bank account number or
Social Security number — don't click on it. It's likely a phishing attempt.
Instead, call your bank directly or access your account online through your
bank's secure website. And be sure to report that phishing attempt to your bank.

Smishing isn't a new dance craze or cooking technique — it's a type of
cyberattack. But with so many similar-sounding scam names floating around, it's
hard to keep up with what each one means.
Here we'll explain what smishing is and how it works. More importantly, we'll
outline how you can protect yourself from smishing attacks — and what to do if
you think you've been targeted.
The term smishing is a mashup of the acronym SMS, which stands for short message
service (the industry lingo for text messaging), and phishing, a type of
internet fraud1 that
involves tricking you into responding to a fake email.
So, smishing is a type of phishing that uses text messages to try to dupe you
into sharing personal financial information like your password, bank account, or
credit card number.

Did
you know? Smishing
scammers play on your fears and your trust.
You get a text message that looks like it's coming from some sort of official
source. For example:
Smishing scammers play on fear
— whether it's fear of losing money, fear of getting into trouble, or fear of
missing out. They're also counting on you to trust a text message sent to your
personal cell phone number and not think twice about responding.
Even if a text looks like it's coming from a trusted source, you should still be
wary if it asks for passwords, authentication codes, or other personal
information. The reason: spoofing. That's when a scammer makes it look like a
phone call or text is coming from a number other than where it's really coming
from. Again, the best course of action is to refrain from responding by text and
instead call the company directly using the customer service number listed on
their website.
Due to the recent increase in smishing attacks, some banks opt not to use text
messages at all with their customers. Check to see if your bank has a written
policy on text messaging. Even if your bank does use text messaging, it will not
ask for personal financial information via text. If your bank does send text
messages, make sure you find out directly from the bank itself what phone number
it uses to do so.
If you have any doubt about whether a text message is real, contact your alleged
sender's customer service department using the number listed on the company's
official website or materials.
Whatever you do, don't call the number provided in the text message, and don't
click on any link embedded in the message. Clicking on a link could cause your
mobile phone to become infested with malicious software and allow cyber
criminals to steal your personal information.
If you realize you've been on the receiving end of a smishing attack, report it
to your cell phone company and file a complaint with the Federal
Trade Commission.
You can also report smishing scams to any government agency, retailer, or other
organization that the hacker was impersonating.
Terms like smishing may sound silly, but the financial harm that can result from
smishing and other cyberattacks is quite serious. Shield yourself with a healthy
dose of skepticism when seemingly official sources are sending you text messages
and asking too many questions.
Vishing

Here's another term to add to your glossary of financial fraud: vishing. The
term is a blend of voice and phishing (that is, scammers trying to get personal
info from you via email). With vishing, the main tool fraudsters use is the
phone.
What is vishing?
Vishing is a type of fraud that relies on getting you to trust the person at the
other end of a phone call. The initial contact might be a phone call to you, but
the scheme can also start with an email message or text asking you to call a
number. Either way, the goal of vishing is to get you to reveal your personal
data, account numbers, or security codes by phone so that cyber thieves can use
that information to access your cash or credit.
Vishing can be hard to spot, because scammers have gotten so clever and
resourceful about fooling their targets. For example, you might receive a call
from a number that matches one used by a familiar organization, such as a bank,
credit union, retailer, or government agency. Since the number seems to be
credible, you probably answer the call and aren't suspicious.
The problem: Scammers are using readily available services that enable them
to spoof (that
is, fake) the number that shows up on your caller ID, while hiding the real
origin of the call.

Scammers often "spoof" phone numbers that look like they're coming from a
company you trust so that you'll answer their call.
Pretexts for vishing calls
Let's say you answer or return a call from a number that looks legitimate. The
person on the other end, pretending to represent your bank, tells you some
suspicious charges have been made using your debit card. They will cancel your
card and issue you a new one, but first they need your PIN, your security code,
and the answer to your security question for “verification."
Another version involves a recorded call that instructs you to enter your PIN or
other information to be connected to someone regarding a problem with your
account. Cybersecurity reporter Brian Krebs shared the story of a cybersecurity
professional who was targeted for such an automated vishing attack with a
message from someone claiming to represent AT&T. No detail was spared to make
the setup seem real, right down to a sound effect mimicking the
telecommunication company's four-note jingle.
Other variations of vishing bait include solicitations of charitable donations
(often after natural disasters), offers of free vacations and other prizes,
pitches for investments and foreign lotteries, and emailed messages for you to
call the number of a service to remove a virus that's infected your computer.
Red flags
Why working from home may put you at more risk
Many people don't tend to answer their cell phone while at work — unless it's
from someone they know and they suspect it might be urgent (say, a spouse, a
parent, or a child's school). And it's a common practice to let all unknown
numbers go right to voicemail.
But when you move to working at home, all of this changes. Some people may begin
to answer every call that comes through, even if they don't recognize the phone
number. And if they think the call could have any connection to work, they
continue to talk, even if they don't know the person who is calling — or don't
quite understand why they're getting the call.
One way to protect yourself: If it's not a phone call from someone you know — or
it's not a phone call you were specifically expecting (say, someone calling from
your office to help you with your work from home setup) — hang up. If you think
there's even a small chance the call may be real, first get the caller's name,
their company name, and their department. Then you can either call or email them
back or using information you find on a website or a company directory.
How to report vishing
If you've been targeted with vishing, report the incident to the Federal
Trade Commission. Just
select a category and use the FTC's Complaint Assistant to fill out a report
online. The agency doesn't resolve individual complaints, but it will share your
report with law enforcement authorities and provide information you can use to
seek a remedy.