Support Support

Fraudulent emails are becoming harder to detect

We are currently seeing a clear increase in targeted fraudulent emails aimed at businesses. At the same time, attackers are refining their methods and making these messages increasingly convincing. As a result, checking the sender’s name or email address is no longer always enough.

In many cases, an attacker gains access to a legitimate business email account. They then use that account to contact customers, suppliers or business partners.

The email may therefore come from an address you recognise, appear in an existing email thread and look completely legitimate. Even so, someone else may be behind the message.

A familiar sender does not always mean the email is safe

Spelling mistakes, unusual sender addresses and suspicious links have traditionally been clear warning signs. These are still important to look out for. However, they are no longer enough to identify every type of fraud.

If an attacker has taken over an email account, they can send messages from the genuine address. In addition, the account owner may not even be aware that someone else has gained access.

That is why you should pay extra attention whenever an email contains something that differs from the usual routine. This is especially important if the sender asks you to make a payment, open a document or sign in to a service.

Always verify changes to payment details

Fraudsters often try to redirect payments to accounts they control. Therefore, you should be particularly cautious if you suddenly receive new bank or payment details.

Also look out for invoices with changed account information, unusually urgent payment requests or other unexpected changes to an established payment process.

If you receive new payment details, always verify them by phone. Use a number that you already have for the person or company. Do not use a new phone number provided in the email itself.

This reduces the risk of the attacker controlling both the email communication and the contact details used to verify the change.

Do not sign in through links in emails

Attackers also use fake login pages to obtain passwords and gain access to user accounts.

For example, you may receive an email containing a link to a document or file. When you click the link, you are taken to a page asking you to sign in.

Avoid signing in through links in emails. Instead, go directly to the relevant service by typing the web address yourself or using a bookmark you already trust.

Do not approve unexpected sign-in requests

If you receive a request in, for example, Microsoft Authenticator without having tried to sign in yourself, do not approve it.

Reject the request instead. Then contact your IT provider if you are unsure why it appeared.

An unexpected authentication request may indicate that someone already has your password and is attempting to gain access to your account.

Already entered your password? Act quickly

Sometimes you only realise afterwards that a website or email was not genuine.

If you suspect that you have entered your password on a fake website, contact us as soon as possible. The sooner we know what has happened, the faster we can take the appropriate action.

Do not wait to see what happens. Fraud attempts can affect anyone, and today’s methods are often both professional and highly convincing.

Suspect something is not right?

Have you clicked a suspicious link, entered your password somewhere you are unsure about, or received a sign-in request you do not recognise? Do not wait to act.

Contact evolvit straight away and we will help you assess the situation and take the appropriate next steps.

Contact evolvit
Drift röd