Humans are still our biggest cybersecurity weakness. Here's how to be smarter when it comes to avoiding scams through email and on your phone.
When dozens of celebrity Twitter accounts started promoting a Bitcoin scam one Friday in July, something was clearly going wrong down at Twitter HQ. By the end of the month, Twitter said certain employees had fallen for a scam and unwittingly helped hackers gain access to sensitive login credentials.
The hacker, allegedly a teenager in Florida who's now charged with 30 felonies, tapped the usernames and passwords to access an internal system at Twitter and take control of high-profile accounts. The breached accounts included those of Elon Musk, Bill Gates and Joe Biden.
In your work or personal life, chances are you have access to a system or account that hackers would like to breach. The prize could be customer data that would help identity thieves do their work, your company's intellectual property or even your personal income data, which could help someone steal your tax refund or file for unemployment benefits in your name.
That access means you, too, could be the target of spear-phishing, a juiced-up hacking technique that tries to trick you into handing over login credentials or download malicious software. Twitter says the attack targeted employees on their phones, which means the hackers could have used phone calls or text messages to mislead their targets.
Spear-phishing attacks also often take place over email. The attacks typically pair an urgent sounding message with credible-sounding information specific to you, like something that could have come from your own tax return. These scams are extra hard to avoid falling for, because they aim to override any red flags you might notice about the email with details that make the sender sound legitimate.Despite corporate training and stern warnings to be careful who you give your password to, people do fall for these tricks.
Another consequence of falling for a spear-phishing scam could be downloading malicious software, like ransomware. You could also be convinced to wire money to a cybercriminal's account. Still, you can avoid falling for these scams by taking these security habits to heart. Here's how to avoid a spear-phishing scam.
Know the basic signs of phishing scams
Phishing emails, texts and phone calls try to trick you into visiting a malicious website, handing over a password or downloading a file. This works in email attacks because people often spend the whole day at work clicking on links and downloading files as part of their jobs. Hackers know this and try to take advantage of your propensity to click without thinking.
So the No. 1 defense against phishing emails is to pause before clicking. First, check for signs the sender is who they claim to be:
- Look at the "from" field. Is the person or business's name spelled correctly, and does the email address actually match the name of the sender? Or are there a bunch of random characters in the email address instead?
- While we're at it, does the email address seem close, but a little off? Such as, Microsft.net, or Microsoft.co.
- Hover your mouse over any links in the email to see the true URLs they will send you to. Do they look legitimate? Remember not to click!
- Check the greeting. Does the sender address you by name? "Customer" or "Sir" would be red flags.
- Read the email closely. Is it generally free from spelling errors or odd grammar?
- Think about the tone of the message. Is it overly urgent or trying to get you to do something you normally wouldn't?
Don't fall for more advanced phishing emails that use these techniques

