Meerkat Alert

What’s a “phishing email”?

Imagine your gate intercom ‘dinged’ and, on peering out of the front window, you saw a man wearing a sparkly carnival mask standing on your pavement. There’s no way you would let him in, would you?

But what if he was driving a white bakkie, wearing branded overalls and said he’d come to check your overhead electricity lines because “We’ve been having trouble in this street since the storm hit last weekend.” You’d be much more likely to at least have a conversation with him, I’m sure.

And that’s exactly what hackers count on when they send you a phishing email… creating enough familiarity to give you a sense of safety.

For the sake of completeness: What’s a “phishing email”?

In face-to-face conversation, someone might be “fishing for information” by asking you slightly intrusive or inappropriate questions.

In the digital world of email conversations, a similar thing happens – but for nefarious purposes. “Phishing” is the word that security folks use to describe the technique of sending out masses of emails (to people who haven’t asked/given permission to be contacted) to gather personal information that will prove valuable in committing identity theft.

And what’s identity theft?

Identity theft is when someone gains enough of your personal data to pose as you credibly enough to carry out financial transactions. Accessing bank accounts or applying for loans, store cards or credit cards in your name are some of the common actions of identity thieves.

So now that you know the terminology, here’s the next chapter in this potential phishing story…

You’ve got an email in your Inbox, and initially it looks legitimate.

It’s familiar enough that it could come from a company that you do regular business with, because the sender name seems credible and the email has all the right logos in it.

There are just a couple of things that make you suspicious: the email says there’s a problem that needs your immediate attention, and asks you to click on a link to help the company rectify the problem for you.

Which TWO places can you look to allay (or confirm) suspicions about the email?

  • First, double-check the Sender: click on the drop-down arrow beside the sender name (on a PC) or directly on the sender name (on a Mac). This will reveal the actual email address of the sender (rather than the displayed name, which is just a label that they chose for themselves). Look for suspicious email addresses: sometimes they are obvious, but they can also be very similar to an actual company, just with an extra letter, number or other small difference that could look like a typo.
  • Second, hover (but don’t click) your mouse cursor over the link in the body of the email. When you do this, the actual address (called the URL) of the website, to which the link leads, will be revealed. Again, look carefully at the details of that URL, it may be leading you to a website that does NOT belong to a legitimate company.

What if using drop-down arrows and mouse-hovering makes you nervous?

Feeling unsettled by the thought of having to identify a dodgy email address or website name is totally understandable, and there are other ways of sidestepping potential threats.

The simplest one is this: don’t click on any link in an email.

If you need to access a company website, open your internet browser yourself and type in the company website name directly. That way you can be sure that you are going exactly where you want to go, and not being waylaid by scammers.

In short then:

  • If you get an email that asks you to take (urgent) action…
  • And that action involves clicking on a link and updating information of any sort…
  • You should be suspicious!
  • No matter how authentic the email looks, check it…
  • And if you don’t feel confident checking the sender and link URL yourself, open your internet browser and type in the correct company website address directly.
  • If in doubt, call the company fraud line (using the number from the actual company website, not from the suspicious email) and ask them for help.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Other Alerts

SARS texts – how to spot a counterfeit

Tax season 2026 opened on 1 July, so we are focusing on one important thing: how to outwit the fraudsters who impersonate SARS to try and relieve you of your precious financial resources. To wise up before this happens, let's use counterfeit bank note training as a...

Interaction “hooks” and how to avoid them

Here's a fresh episode of "Real Bank Scams of South Africa" to help you sharpen your analytical skills, because you’re wise enough to realise that it’s not a matter of IF  you’ll ever receive a fake message, but more a matter of WHEN. While the wording of fake...

Red Flags to Watch Out for

📲 Ah, smart phones! Super-convenient, right? Instant access to information, easy contact with your loved ones right across the globe and the added convenience of paying your bills without signing cheques or licking stamps while sitting at a desk. At this point your...

Spoofing and App Shenanigans

Back in the day, a spoof was a device used to entertain us in a humorous and/or satirised way. A bit of harmless fun, something to laugh at before moving on. Recently though, "spoofing" has taken on an additional and more sinister meaning. Here's what's currently...

Tax Season Trickery

It's Tax Season here in South Africa, so you are on the lookout for important and time-sensitive emails from your taxation service provider, and also from the South African Revenue Service (SARS). Stay on high alert for the fraudsters as well, because they are busy...

Same tip on repeat

Do you ever feel worn-down by the relentless fraud attempts? Given the pace of them, it would be understandable if you feel that eventually a scammer will catch you off-guard. This Meerkat Alert is rather disconcerting as it indicates just how deeply corruption and...

Investment Diversion Scam

This cyber-fraud story was reported in the local newspapers and it's a real nail-biter. A fellow Capetonian sold his business and retired. At 78 years old, after two decades of hard work, he suddenly had R10.6 million on hand and he developed an investment plan with...

Property Rental Scam Case Study

Anywhere that money changes hands, scammers will watch out for an opportunity. When there is a scarce supply, a sense of urgency makes it even easier for criminals to target you. Estate agents are reporting increasing levels of fraudulent impersonation, specifically...

Race Entry Case Study

Do you or any of your family or friends ever enter running or cycle races? If so, this Meerkat Tip is right on topic for you! Here are the details: "I encountered a fraudulent scheme while attempting to purchase an entry for last year's Knysna Forest Marathon.   After...

Facebook Ad Fraud Case Study

Valentine's Day has come and gone, but gift-purchasing happens year-round. As a result, this experience of a Netto Invest contact who got scammed buying a gift for her husband could easily happen to any of us. Here is the case study story, straight from the horse's...

Notify