What you need to know
Treat phishing as a reporting and response workflow—not a quiz. Learn observable warning signs, preserve a safe report, avoid interacting with the message, and escalate immediately if a link, attachment, credential prompt, payment request, or MFA approval was used.
Potentially affected
Email, text, messaging, and phone users; managers; finance teams; and support personnel receiving suspicious communications.
DSE recommendation
Use the organization’s approved reporting method without clicking or forwarding active content, and call the support path immediately after any interaction.
Phishing can arrive by email, text, collaboration app, social message, QR code, or phone call. The goal may be credential theft, malware delivery, fraudulent payment, sensitive-data collection, or an MFA approval. Staff do not need to prove that a message is malicious before reporting it.
What the official source says
Source fact: CISA’s action guide describes phishing as a tactic that can use email, text, social messages, or phone calls to persuade people to open harmful links or attachments, disclose information, or infect devices. CISA advises suspected targets not to click links or attachments and to report the message.
Pause and inspect without interacting
Warning signs can include unexpected urgency, emotional pressure, unusual payment or secrecy requests, a sender address that does not match the claimed organization, unexpected attachments, shortened links, unfamiliar sign-in pages, and an MFA prompt the user did not initiate. A polished logo, familiar writing style, prior conversation content, or a known sender name does not prove legitimacy; accounts and conversation threads can be compromised.
DSE recommendation: do not click, scan a QR code, open an attachment, reply, call a number in the message, approve an MFA prompt, or use the message’s unsubscribe link. Verify unusual requests using a known contact method obtained independently, such as an existing directory entry or previously confirmed number.
Report safely
- Use the organization’s approved phishing-report button or support workflow.
- If the method is unclear, contact the helpdesk through a known DSE or company address—not through the suspicious message.
- Include the time received, delivery channel, claimed sender, and whether anyone interacted.
- Avoid broadly forwarding live suspicious content. Follow support instructions for preserving headers or attachments.
If someone interacted
DSE recommendation: report immediately and state exactly what occurred: link opened, file opened, credentials entered, MFA prompt approved, information sent, payment initiated, software installed, or device behavior changed. Do not hide the interaction and do not wait for obvious symptoms.
Stop additional work involving the suspicious content. Keep the device powered on unless the organization’s responder directs otherwise; however, if destructive activity is visibly spreading and support cannot be reached, follow the organization’s approved isolation procedure. Use another known-safe device or phone to contact support. Finance-related requests also require the organization’s established payment-fraud and bank-contact procedure.
What not to conclude
A warning sign does not prove malicious intent, and the absence of warning signs does not prove safety. Automated filtering also cannot guarantee that every harmful message is blocked. The responder should evaluate the message in the context of account activity, endpoint signals, mail-system data, and the organization’s procedures.
Practical next step: make sure every employee can find the reporting method without opening a suspicious message. Test the route with a harmless simulation and correct any confusion about whom to call after an interaction.
Review the official source
CISA Personal Security Considerations: Action Guide for Critical Infrastructure Workers · Published June 7, 2024
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE