We are excited to share that we are set to begin a new chapter with Dropbox, Inc. Dropbox is acquiring our IP technology to embed natively into the Dropbox product, bringing end-to-end, zero-knowledge encryption to millions of business customers around the world. Check out our blog to find out more!

Here's a checklist that helps you detect phishing emails

Lisa Figas | Marketing Manager


Phishing – Do Not Enter Login Details Anywhere Flippantly

Treble, telescopic rod, fishing chair - if the equipment fits, you only need to find the right waters and the fish will eventually come by. For anyone who lures a bait on the Internet everything is even simpler – after a successful catch the virtual angler does not even have to remove an intestinal tract. Quite the opposite: the victim of an Internet fraudster often does not even realize that he or she is on the hook...

What is Phishing?

Phishing is Internet fraud. It is about acquiring sensitive data under false pretense. In many cases of phishing scams the attackers try to use fake emails to get user data.

For example, this is how it works: An email with a subject that causes a stir appears in the email inbox. This could be something like: "Your account has been locked for security reasons!" Or "Automatic check of your online banking". Often, these are alleged messages from banks asking for verification. Fake PayPal emails are also very common. The goal of the scammers is to get the recipient of the email to visit a website and provide their login information.

Often, these emails, and also the web pages to be visited, look very similar to the real offer of the alleged sender. That is the tricky thing about it and it is exactly how the scammers went about in the current case of Netflix phishing. With fake emails, users were lured to replicate pages. The aim of the fraud was the tapping of credit card data.

If a recipient has fallen for such a phishing email and has typed any data into the space provided, the fraudsters will have access to his or her online banking or PayPal account (or whatever has been tapped). Anyone who uses online banking or PayPal can imagine that this can cause a lot of damage.

Additionally, there are phishing emails that contain a virus or other malware. Most of the time, the malware is hidden in the attachment. Therefore, you should be as careful when opening email attachments as you are when you click on links that are sent to you unexpectedly.

How Do You Recognize Phishing Emails?

Christian Olbrich, developer and software security advisor at Boxcryptor, has put together a checklist that helps you detect phishing emails:

Recognize phishing emails:

  1. Pay attention to the sender. If it looks strange, you should be careful. But attention: senders can easily be forged. A well-known sender is therefore no guarantee that the email in question is harmless.
  2. Do not click on links that were sent to you without you expecting them. If in doubt, you can access the mentioned website via the browser (without clicking the link). If the company actually emailed a warning, this topic should also be posted on the website.
  3. Make sure that the email in question is really addressed to you as the recipient. For emails without personal address, you should be suspicious. A positive sign would be if the email contains information that only the sender can know, for example, your username or recent actions.
  4. Large companies, such as PayPal, usually send emails with correct spelling and grammar. Hackers often do not. Bad English is an important clue to phishing. By the way, banks usually do not send emails at all. And if so, then only on behalf of your personal bank consultant.
  5. Ignore emails coming from banks where you do not have an account. The same applies to PayPal, Amazon and Facebook: Services you do not use cannot (and may not) email you.

If you have checked the points above and have decided that you can trust the sender, there is another relevant aspect: Can you carry out the requested action by navigating the website manually? If so, great. Then it probably was a legitimate mail.

Here are some additional tips to protect your information online:

  • Make sure the https protocol is used (it indicates that the connection between the computer and the server is encrypted).
  • Make sure the domain in the URL is actually the legitimate website (and not a similar-sounding / looking one).
  • Make sure that the website is "SSL verified" (green lock in the address bar of the browser).
  • Major IT companies and companies offering their services on the Internet have a support team that cares exclusively about the needs of the customers. It is a perfectly legitimate strategy to check back with a company’s support team, to make sure if the email is legitimate and was really sent out by the company.

In conclusion, always be aware of what you are doing online. Many dangers on the Internet can be recognized when you are sensitized to the most common threats. This makes us very different from the poor, unsuspecting fish that no one has ever warned about bait.

Compartir este artículo

Artículos relacionados


Our New Chapter with Dropbox: What Boxcryptor Users Need to Know

Last week we already announced that we sold important technology assets to Dropbox. What our customers need to know now, we explain in detail here.


A letter from our Founders: We’re joining Dropbox!

Almost 12 years ago, we set out to make complex security solutions easy to use. Now we are excited to share that we are set to begin a new chapter with Dropbox, Inc.

Dummies Book Cover and Back

CLOSED We Celebrate Our Book Release: Your Chance to Win

We have published our first book to get even more people excited about the cloud and data security. Celebrating the official launch, you can win printes copies and Boxcryptor licenses in our raffle. Read about the details in our blog post.