Think you're being hit by ransomware right now? Don't panic — start here →
Already a safemode IT client? Call our 24/7 Security Operations Center immediately: 512-761-7652, Option 1
PHISHING & SOCIAL ENGINEERING

Most ransomware starts with one click.

Phishing, spoofing, and their voice and text cousins are still the number one way attackers get in. Here's what to watch for, and exactly what to do if you already clicked.

RED FLAGS

Signs of a phishing attempt

!
Urgency or threats. "Act now or your account will be suspended."
!
Mismatched sender address. The display name says one thing, the actual email address says another.
!
Unexpected attachments or links. Especially invoices, shipping notices, or "shared documents" you didn't ask for.
!
A request to change payment or bank details. Always verify by phone, using a number you already had — not one in the message.
!
Generic greetings. "Dear Customer" instead of your name.
!
Look-alike domains. "safemodeit-support.com" instead of the real domain.
!
Too good to be true. Unexpected refunds, prizes, or windfalls.
!
Requests to bypass normal process. "Don't loop in accounting, just wire it today."
BEYOND EMAIL

The whole family of social engineering

Business Email Compromise (BEC)

An attacker impersonates an executive or vendor, usually to redirect a wire transfer or payment.

Smishing

Phishing by text message, often impersonating delivery services, banks, or even your own IT provider.

Vishing

Phone-based social engineering — increasingly using AI-cloned voices of real executives or family members.

Quishing

Malicious QR codes, often placed over legitimate ones on parking meters, menus, or flyers.

IF YOU CLICKED

Steps to take right away

1

Disconnect from the network

Unplug or disable Wi-Fi on the device you clicked from.

2

Don't enter any more information

If a fake login page is still open, close it without typing anything further.

3

Change your password from a different, clean device

Assume the password you entered is already compromised.

4

Confirm MFA is still yours

Check for any MFA method you don't recognize and remove it.

5

Tell IT or safemode IT immediately

The faster this is reported, the smaller the blast radius. See our full incident response guide.

6

Report it without fear of blame

Anyone can be fooled by a good phishing attempt. Fast reporting is a win, not a mistake.

REPORT IT

Where to send a phishing attempt

Forward it to the Anti-Phishing Working Group: reportphishing@apwg.org
Report fraud to the FTC: reportfraud.ftc.gov
Report financial loss to the FBI: ic3.gov
Always forward it to your own IT team or MSP so others can be warned.
WANT YOUR TEAM PHISHING-TESTED?

See how your team does against a real simulated phishing test.

We can run a baseline phishing simulation and turn the results into a short list of what to fix first.