If you looked at this email fast, you’d swear it came from Microsoft. Same logo, layout, tone - everything checks out. Except for one thing: The sender’s domain was rnicrosoft(.)com instead of microsoft(.)com That tiny swap of “rn” instead of “m” is what’s called typosquatting. Attackers register near-identical domains to catch people who skim their inbox too fast. What makes this effective is how subtle it is. On mobile, you barely see the full address. On desktop, your brain autocorrects it. It feels right and that’s all they need. These kinds of tricks are showing up more often in credential phishing, vendor invoice scams, even internal HR impersonations. How to handle these cleanly (real, practical steps): - Expand the full sender address every time before you click. - Hover the link to view the real href, or long-press the link on mobile to reveal the URL. - Check the Reply-To header -- scammers often route replies elsewhere. - If it’s a password reset you didn’t request, open a new tab and log in from the official site rather than clicking the email. - Forward the phish to your security team or report it (company phishing inbox / your provider’s report feature). Examples of look-alikes to watch for: swapped letters (rn → m), zero for o (micros0ft), added hyphens or extra subdomains (microsoft-support[.]com). Small habit change, big payoff. Teams that rehearse these scenarios stop reflexively clicking.
Email Security Features
Explore top LinkedIn content from expert professionals.
-
-
The CFO was furious. He had just wired $65,000 to a scammer because he thought he was paying a trusted vendor. It wasn’t a hack. No one broke a firewall. No one cracked a password. It was a classic Business Email Compromise (BEC). The attackers simply asked for the money, and because they looked legitimate, he sent it. His first reaction? "We need better software to stop this." I had to tell him the hard truth: Software can't fix a broken process. Technology alone cannot stop a human from being manipulated. If you rely solely on tools, you are bringing a firewall to a confidence game. We didn't solve this problem by buying an expensive new security appliance. We solved it by rewriting the company's Standard Operating Procedure (SOP). We implemented a simple, non-technical rule: Any request for a wire transfer received via email or text must be verbally verified by a second authorized signer. That one process change (which cost $0 in software licensing) did more to secure their finances than any tool on the market could have. 👇 I've attached the exact SOP template we use. Swipe through to see the specific language you can add to your finance policies today. In my book, Fire Doesn't Innovate, I share tools like this because cyber resilience is about People, Process, and Technology; not just Technology. #BusinessEmailCompromise #CFO #RiskManagement #FireDoesntInnovate #SOP
-
Attackers can send emails that look like they’re from your company without ever touching your systems. They spoof your domain, impersonate your executives, and target your customers. This can turn into real financial loss. Customers pay fake invoices. Vendors update payment details based on a fraudulent message. Employees get pulled into credential or payment scams that look legitimate. For a small business, that can mean lost revenue, recovery costs, and operational disruption. Email authentication helps reduce this risk. SPF and DKIM verify sending systems. DMARC ties it together and tells receiving servers how to handle messages that fail checks. When configured and enforced, many spoofed emails can be filtered or blocked before they reach inboxes. It also gives you visibility into who is trying to use your domain. It’s worth checking where you stand: Ask your MSP or IT team if SPF, DKIM, and DMARC are configured and actively monitored. Confirm your DMARC policy is enforced, not just set to monitor. Make sure you can review and act on DMARC reports. This is basic protection that’s easy to put in place, inexpensive to maintain, and can make a meaningful difference, especially given how much business communication and payments still rely on email. Learn more here: ➢ FTC: "How to Stop a Would-Be Business Impersonator" https://lnkd.in/gfjq6eEu ➢ FTC: "Email Authentication" https://lnkd.in/gmZuyxFj #Cybersecurity #EmailSecurity #EmailAuthentication #SmallBusiness #BusinessRisk
-
“Do you have UPI?” That’s all the email said. The sender name looked like my cofounder’s. The email landed in a teammate’s inbox at 1:48 PM. For a second, she almost replied. This is how scams actually start. Just four words that feel ordinary enough to make you click. And it’s not just us. In 2024, over 36 lakh cyber-fraud complaints were filed in India and citizens reported losses of ₹22,845 crore. UPI fraud incidents nearly doubled year-on-year in FY24 to about 13.4 lakh cases. The patterns repeat across email, SMS and WhatsApp: - Fake emails that copy your boss’s or cofounder’s name. - Urgent asks: “Do you have UPI?”, “KYC expiring today”, “Refund waiting.” - One wrong click and money gone in seconds. What saved us? Our teammate paused. She expanded the sender, and checked the “From” and “Reply-To”. The address was off by one letter. Spoofed. Here’s what you should do the next time this lands in your inbox: 1. Expand the sender. Check the full address, the domain, and the Reply-To. 2. Never share an OTP anywhere. Never share your UPI PIN. Never approve unknown “collect” requests. 3. If money moves, call 1930 and file at cybercrime.gov.in, then alert your bank. The first hour is critical for freezing funds. One careless “yes” can empty your account. But one careful pause can save a crore. The difference between the two is less than five seconds.
-
Bob just gave $70,000 to a complete stranger who provided zero value. Actually, it wasn’t just a stranger, it was a thief posing as a vendor. They sent an email saying, “Pay now, get a 5% discount.” Bob was busy, running a million miles an hour, and thought he’d snag a quick win for the bottom line. He sent the wire. By the time he realized it was a scam, the money was gone. Most contractors think cybercriminals are only targeting the big guys. They aren't. They’re targeting mid-sized construction shops because you move high-dollar amounts for materials every day, and your internal controls usually aren't as tight as a tech giant's. Unfortunately, Bob is screwed. You don't have to be. Unless you have the right coverage, you’re eating that loss. When you’re looking at your cyber or crime policy, look specifically for Social Engineering or Funds Transfer Fraud. You need to ensure it covers "Voluntary Parting." Most people think of "hacking" as someone breaking into a vault. In this case, the thief didn’t break in, they tricked you into opening the door and handing them the bag. But look, a policy is just a safety net. The goal is to never fall off the tightrope in the first place. If a vendor sends an email with new wire instructions, a "special discount," or a sudden sense of urgency, stop. Pick up the phone. Don’t call the number in the signature of that email, call the number you’ve had in your system for five years. Verification takes seven minutes. Replacing $70,000 of net profit takes a heckuva lot longer. Implement an SOP where no wire goes out without a voice on the other end of the line. Share this with your office manager today. It’s a lot cheaper than the alternative.
-
70% of staff at this £18Bn IT giant were clicking on phishing links. 12 months later, we cut it down to 20%. I led the transformation as CISO. Here's exactly how we did it step by step: We had a workforce of 300,000 people across 150+ countries in 2021. Different cultures, different languages, different inbox habits, but one common problem: Inbox fatigue. Hundreds of emails a day meant people stopped thinking. If it hit their inbox, they opened it. And when it looked remotely legitimate? They clicked. Even the most senior execs — the ones with the most sensitive data — were falling for the bait. As CISO, I wanted to help fix this laissez-faire view without humiliating anyone. Here's how: Step 1: Awareness Training We launched 5-10 minute micro-learning modules that dove into • why phishing exists • what criminals get out of it • the tell-tale signs (bad grammar, lookalike domains, letter swaps in emails, etc.) The lessons were practical and related to life at business and at home. People finished the module knowing exactly what to check before clicking. Step 2: Realistic & Layered Phishing Simulations Now it was time to test everyone. We started with easy simulations and built complexity over time: → Simple: obvious scams like “Nigerian prince” emails → Intermediate: fake brand offers from Apple or similar → Advanced: MS login pages so convincing they fooled seasoned IT staff Every “fail” on the simulation triggered an instant education page showing exactly what they missed. We sent them in waves over 14 hours, with multiple variations so colleagues couldn’t tip each other off. We used the local language in each country and avoided dirty tricks like fake bonus announcements. Step 3: Tracking the Data We built in features in each email that helped us track: • link clicks • email opens • data entered (and whether it was real or spoof) • reports (via a “report phishing” button) This helped us see where someone stopped in the chain and reward them for correct reporting. Step 4: Analyzing & Reporting Findings We analysed the data above by country, seniority, and cultural trends. Key Findings: • Colleagues in some cultures were more likely to open emails 'just in case' it was from a boss. • Some countries will not allow phishing simulations at all. • Execs were the WORST offenders. With this info, we moved onto: Step 5: Education & Implementing Solutions On top of the built-in education pages, we hosted workshops with repeat offenders to • dissect the email together • point out red flags they missed For the top-level execs who were still clicking after a year, we held direct coaching sessions — explaining that with their access came the highest stakes. –– By the end of the programme: • Click rate: 70% → 20% • Dramatic increase in phishing reports • A cultural shift where questioning suspicious emails became the norm (post continued in the comments below)
-
A friend got a LinkedIn message recently about a $95K remote position. It looked perfect. Professional company logo. Detailed job description. Even offered to start the interview process immediately. 🚨 One problem: it was completely fake. Here's what gave it away: 🔵 Sent from a Gmail account, not a company domain 🔵 Asked for $250 for "background check processing" 🔵 Promised immediate hire after one video interview 🔵 Required bank account info before any formal offer Job scams have exploded. Reports to the FTC tripled from 2020 to 2024, with losses jumping from $90 million to over $501 million. Think about that. Half a billion dollars stolen from people just trying to find work. These scams are getting sophisticated. Scammers create fake company websites, copy real job postings, use AI to generate professional-looking materials, and even impersonate recruiters on LinkedIn with polished profiles. The most common types: Remote work scams asking for equipment fees upfront. Mystery shopper jobs requiring certification payments. Data entry positions promising six figures but demanding training costs. Government job postings charging application fees (real government jobs never charge). Task-based work asking you to complete sets of activities for commission that never comes. All of them follow the same playbook: look legitimate, create urgency, and get your money or personal information before you realize what's happening. 💰 Red flags to watch for: Generic emails from recruiters you never applied to. Requests for Social Security numbers, bank details, or credit card info before you're hired. Any job asking for money upfront for training, equipment, background checks, or processing. Interview processes that skip normal steps and rush to hire. Vague job descriptions with unrealistic pay for minimal work. Payment requests via gift cards, crypto, wire transfers, or Venmo. How to protect yourself: Verify the company exists and has an actual online presence. Check if the recruiter has a legitimate company email domain. Never pay for a job opportunity. Research the company on glassdoor and other review sites. If contacted out of nowhere, call the company directly using a number from their official website. Trust your gut. If it feels too good to be true, it probably is. At Sardine, we're tracking these fraud patterns across our network. Job scams are skyrocketing because they work. Scammers prey on people who are desperate for income, under financial pressure, or simply excited about a good opportunity. If you're in HR, recruiting, or hiring, make sure your team knows how to spot imposters using your company name. If you're job searching, stay alert. Question for my network: have you seen fake job postings targeting your company or industry? What are the most common tactics you're seeing?
-
Stop training your employees to look for “hackers”. Start training them to verify their vendors. We picture business email compromise as a shadowy figure typing furiously in a dark room. A technical mastermind breaching firewalls. Cracking code. Breaking in. But that’s not the threat draining millions from businesses every year, and it’s not the threat sitting quietly in your inbox right now. BECs are not a computer hacking problem. They're a human hacking problem. The attack doesn’t start with a spoofed domain. It starts long before that. Attackers compromise an employee or vendor account and then do something far more dangerous than “send phishing emails”. They observe. They study. They wait. They learn who moves the money. They learn the tone your team uses. They learn when invoices are due. They wait for the perfect moment. Then they strike. Not with malware. With context. A reply to an existing thread. A perfectly timed request. A simple line: “Please update our banking information for this payment.” No red flags. No typos. No urgency. Just familiarity with your operations that feels legitimate because it is legitimate until the money is gone. If your training focuses on bad grammar, fake logos, or hovering over links, you are preparing for scams from 2014. Not 2025. You cannot “spot” a social engineer who knows your invoice workflow better than your AP team. The Fix. Process over perception Stop relying on instinct. Build systems that force verification. 1️⃣ Out-of-band authentication. If bank details change, call the vendor using the number you already have on file. 2️⃣ Zero trust for payment updates. Treat every change request as a breach until verified. 3️⃣ Scrutinize timing. Criminals strike at peak workload, when your team is most likely to comply automatically. The goal is not to stop the email from landing in the inbox. The goal is to stop the money from leaving the bank. Is your organization still teaching employees to “spot phishing”, or are you actually preparing them for compromised vendor attacks? If you want to shift from generic “security awareness” to a true human-defense strategy, send me a DM. Let’s secure your payment processes before criminals do. #Stopthescam before it starts! Fraud Hero #businessemailcompromise #socialengineering #phishing #scam #fraud #PauseThinkVerify
-
Continuing our "I.T. Security With a Hammer" series, although this one is more like a rubber mallet. I attended a meeting on corporate email security. One very simple, zero cost, but potentially effective suggestion made during the meeting is to create two Microsoft Exchange Email Transport Rules: 1) Create a conditional transport rule that says if the email is from outside of the organization, prepend the subject line of the email with [EXTERNAL], [NOT INTERNAL], or some other form of indication that the sender's email address is not on your internal domain. This can also be accompanied by a footer message reminding users not to click on links or open attachments until they verify the sender's email address and that it is from a trusted source. 2) Create a conditional transport rule that says if the email is from inside of the organization, prepend the subject line of the email with [INTERNAL], [ORGANIZATION NAME], or some similar indicator that shows that the email originated from within the internal domain. A simple footer message can also be added to help indicate and verify internal emails. While a hacker could attempt to "spoof" these messages to try and trick users, they can't eliminate the fact that the message subject line will always add a code even if they try to make it appear as if it is internal. Anyway, we all agreed in the meeting that this is a simple, zero cost, and potentially effective way to help try to better identify phishing, spear phishing, whaling, and other forms of email fakery. Looking forward to the feedback in the comments.