Don’t get hooked. Stay ahead of phishing scams this Cybersecurity Awareness Month.

7 October 2025

This Cybersecurity Awareness Month, we’re taking the opportunity to remind everyone about the importance of good cyber security practices and the need to remain vigilant to phishing attempts.

What is phishing?

Phishing is when cybercriminals attempt to trick you into giving away information. This usually occurs via email but cybercriminals will use other methods as well including text messages, messaging apps, phone, letter, or through social media.

The information they ask for might let them gain access to bank accounts, install malware, or steal data.

Typically, the communication is ‘spoofed’ so as to make it appear it comes from a genuine email address, and may be branded to look like it has come from a particular organisation.

What is malware?

One of the possible outcomes of falling victim to phishing is that malware is deposited onto your IT systems. Malware is the term given to all pieces of malicious software that are designed to damage, disrupt, steal, or allow unauthorised access to computer systems and networks. Once a piece of malware is in the system, they will usually execute a harmful action such as stealing or destroying data. The number of different types of malwares is ever-expanding as cybercriminals develop new methods of attack, but in general you are more likely to hear people talk about the four below.

  • Virus – These are usually hidden within another seemingly harmless piece of software and spread when the user runs the infected software.
  • Worm – These are standalone pieces of malware that transmit themselves over a network to infect other systems and computers.
  • Trojans – Like the ancient Greek myth these are disguised as trusted software and execute their actions when run by the user.
  • Ransomware – These encrypt data or restrict the user’s access to it and request payment in order for the data to be released.

Veritau’s 5 steps to take if you receive a suspicious email:

1. Do not open attachments or click links

What to do: Avoid clicking on any links or downloading attachments in the email. These could contain malware or lead to phishing websites.

Why it matters: Opening malicious content can compromise systems, potentially giving attackers access to sensitive data.

2. Verify the sender and check the email

What to do: Check the sender’s email address carefully. Look for misspellings or slight variations.

If you have other contact details for the apparent sender, you can contact them directly and ask them if they have sent the email.

Also look at the content of the email and check for grammar, spelling or formatting errors. Check the language used and what the email is asking you to do.

Why it matters: Scammers often impersonate trusted organisations or individuals using fake email addresses. They may try to use authoritative language, claim to be from someone important or rush you into making a decision.

3. Report the email immediately

What to do: Forward the suspicious email your IT team or provider, along with a brief explanation of your concerns.

Why it matters: Prompt reporting allows IT staff to investigate and act as necessary.

4. Do not reply or engage

What to do: Avoid replying to the email, even if you suspect it is fake. Never provide personal information or other sensitive data.

Why it matters: Responding can confirm to attackers that your email address is active, increasing the risk of further attacks.

5. Delete the email (after reporting)

What to do: Once you have reported the email, delete it permanently from your inbox and empty your deleted items folder.

Why it matters: Removing the email reduces the risk of accidental interaction with its contents in the future.

Remember…
  • Never assume that a request is safe purely because it is branded correctly, or a colleague trusts the source.
  • Do not allow yourself to be pressured into bypassing agreed verification processes or internal controls.
  • Never click on any links or attachments contained in a suspicious email, or from an unknown sender.

If a staff member does click on a link, gives their details, or opens an attachment, they should change their password and report it to your IT team immediately.

If you are a Veritau client, please also let us know so we can help you assess whether there has been a data breach.

Downloads
Download

Download our poster

Download our Cybersecurity Awareness Month 2025 Poster

File type: pdf

File size: 124KB

Download this file
Contact us

If your organisation doesn’t currently receive DPO or counter fraud services from Veritau, please contact us for more information. Veritau’s team of experts can support you with prevention, through providing policies, frameworks and fraud awareness training – or we can investigate matters as they arise.