Spam or Phish? And do we care?
Stop, Look, and Think! before you click on any link in an email or open an attachment!
By Kerry Leblanc, IT Security Engineer
The difference between spam and phishing is that, while they both may be inbox-clogging nuisances, only one (phishing) is actively aiming to steal login credentials and other sensitive data. Spam is a tactic for hawking goods and services by sending unsolicited emails to bulk lists. While annoying, spamming is not nearly as dangerous as phishing, which tries to trick a user in divulging sensitive information.
What is spam? No need to report or submit these.
Spam is called junk mail for good reason. It’s existed for almost as long as the internet itself as a means of selling products or services to a larger market of buyers than have ever expressed interest in those products or services. After obtaining the email addresses of a huge number of individuals, spammers bulk send their offers hundreds or thousands at a time.
Common types of spam include prayer chain forwards, coupons, adult content, donation solicitations, and unwanted newsletters. They are usually commercial in nature and not expressly malicious.
What is phishing? These should be submitted using Phish Alert Button
Whereas spam is simply unwanted, phishing is expressly designed by a malignant actor to harm a company or individual by obtaining sensitive information. It often takes the form of a seemingly legitimate-looking message from a trusted sender. Phishing emails target banking credentials, passwords, cash advances, or other information of value. Identity theft often results.
Signs of phishing email include:
- Misspelled words
- Discrepancies between the language of links and the URLs they direct to
- Requests for personal information
- Forms within emails
- Highly emotional or charged language
You can protect yourself and the company against phishing attempts by:
- Knowing common signs of phishing scams
- Not providing personal information via email. If you’re unsure if an email is legitimate, always refer to the sender’s website.
- Not opening messages from unknown senders
- Varying passwords
Remember, you are the last line of defense against these emails. When in doubt, verify with the sender or report to [email protected] for verification.
It is up to you to – STOP, LOOK and THINK!
