How to Spot Phishing: Email, Teams and Fake IT Support

Phishing is any message built to look legitimate so you will hand over a password, wire money, or open something that installs malware. It usually arrives by email — and increasingly it does not. The single most important thing to understand is this: you cannot judge a phishing attempt by how professional it looks. Attackers now write clean, well-formatted, personalized email, spoof real brands convincingly, and often send it from an account that genuinely belongs to someone you know. What still gives them away is the request — and a handful of checks anyone can learn in a few minutes.

This guide covers how to spot phishing in every form it now takes: the classic phishing email, the fake IT support message in Microsoft Teams, the follow-up phone call, the sudden flood of spam that turns out to be a setup, and the counterfeit Microsoft sign-in page that defeats multi-factor authentication. It is written for the people in your business who actually receive these things. Read it, share the link with your team, and bookmark it for onboarding. If you would rather not rely on human judgment alone, skip ahead to managed email security and browser protection — the layers that catch what training misses.

On This Page

How to Spot Phishing in 30 Seconds

If you remember nothing else, remember these six steps. Run them on any email, chat message or call that asks you to do something.

  1. Read the domain after the @ symbol — not the display name. The name is decoration; the domain is the fact.
  2. Ask whether you were expecting this. Unsolicited, plus money, credentials or an attachment, means stop.
  3. Look for pressure. Deadlines, threats, secrecy and urgency are the most reliable phishing signal left.
  4. Preview the link before you click it. Hover on a computer; press and hold on a phone.
  5. Approve nothing you did not personally start — no multi-factor prompts, no app permission requests.
  6. Verify by phone, using a number you already have. Never verify by replying to the email.

If any one of these fails, stop and report it. You do not need to be certain an email is malicious. You only need to be unsure. Reporting a legitimate email by mistake costs a minute of someone’s time. The other mistake costs considerably more.

The same six checks apply to a Teams message, a text or a phone call. One of the most effective attacks running right now arrives that way instead — see fake IT support and Teams phishing below.

Why Spam Filters Don’t Catch Phishing

People are often surprised that a phishing email reached them at all. The reason is that there is frequently nothing technically wrong with it. Anyone can register an address like [email protected] and send a link or a file, and no filter can reliably distinguish that from a colleague sending a funny link from [email protected]. The message is well-formed, the sending domain is real, the link may point to a page that was harmless when the email was delivered. The malice lives in the intent, and intent is not a header value.

This is why the most damaging attacks — the ones that redirect a wire transfer or drain a payroll run — frequently contain no link and no attachment at all. Just a sentence in an email from a real account. Basic filtering was never designed to catch that, which is exactly the gap dedicated email security is built to close.

Step 1: Check the Sender

Look past the display name

Anyone can put any name they like on an email account. Nobody can fake the domain after the @ symbol on a real, uncompromised account. Consider these two senders:

They display an identical name. Only one of them is actually coming from Microsoft. On a phone, many mail apps show only the display name by default — tap it to expand the full address before you act on anything.

Watch for lookalike domains

Attackers register domains built to survive a glance and fail a second look:

  • Character substitution: micros0ft.com, with a zero standing in for the letter O.
  • Letter pairs that look like one letter: rnicrosoft.com, where rn reads as m at normal font size.
  • Added words: microsoft-support.net, microsoft-billing.com — real-looking, entirely unrelated domains.
  • Subdomain tricks: microsoft.com.secure-verify.com. This is not Microsoft. It is secure-verify.com. What counts is the last portion before the top-level domain, not what appears first.

The habit worth building is reading a domain backwards — find the .com or .net, then read the word immediately to its left. That is the organization you are actually dealing with.

A familiar domain is not proof of safety

This is the point most training programs undersell. An email can come from the genuine, correctly spelled domain of a client, vendor or coworker and still be an attack — because that person’s account has been compromised. Compromised-account phishing is among the hardest kinds to detect precisely because every technical signal checks out.

When in doubt, don’t ask by email — call

If a request does not make sense, do not reply to the email to ask whether it is legitimate. If the account is compromised, the attacker controls the reply and will simply tell you yes, that is really me. Instead, call a phone number you already have for that person or company — from your own records, a signed contract, or the company’s website that you navigated to yourself. Never use a phone number supplied in the suspicious email. If you cannot reach anyone, do nothing: don’t reply, don’t click, don’t open the attachment.

Be suspicious of unsolicited contact

Phishing is often sent to people who have never done business with the sender. Treat outreach from unfamiliar companies and contacts with extra caution, especially when it involves money, credentials or a file.

Verifying an email sender domain before clicking a link, a core phishing prevention habit for Colorado businesses

Step 2: Check the Content

  • Generic greetings are a red flag. A company you already do business with generally knows your name. Dear Customer and Dear User remain common phishing patterns.
  • Contentless emails are a red flag too. A message that says only Please see attached proposal — no names, no context, no specifics, no reference to any conversation you actually had — should raise suspicion on its own.
  • Urgency and fear are the strongest remaining signal. Your account will be suspended in 24 hours. Invoice past due, pay immediately. Legal action pending. Manufactured panic and artificial deadlines are the most consistent tactic across nearly all phishing and fraud. Legitimate organizations rarely demand instant action by email.
  • Secrecy is a serious warning sign. Any request to keep something between us, to skip normal approval, or to avoid mentioning it to a colleague is a fraud indicator, not a confidentiality requirement.
  • Be wary of requests for personal information. Legitimate companies will not ask you to send a password, a full credit card number or a Social Security number by email.
  • Watch for a changed reply-to address. A message can display a familiar sender while routing your response somewhere else entirely. If you hit reply and an unfamiliar address appears, stop.

Two old rules that no longer hold

Bad grammar is no longer a reliable indicator. Poor spelling and awkward phrasing used to be one of the best tells available. AI writing tools have ended that. Attackers now produce flawless, professional, correctly localized email at scale. Grammar mistakes are still worth noticing when present, but their absence tells you nothing at all. Do not rely on this one.

Microsoft does send security emails. The old advice that Microsoft never emails you about your account is out of date — legitimate notices about password expiration, mailbox storage and sign-in activity are routine. The better test is this: a legitimate Microsoft email will never contain a link that takes you straight to a page asking for your password. Whenever you need to act on one, open a browser yourself and sign in at an address you typed or bookmarked. Never through the link in the email.

  • Hover over links on a computer. Rest your mouse on a link without clicking and the true destination appears in the corner of your browser or mail client. If it does not match where the link claims to go, don’t click.
  • Press and hold on mobile. Hovering does not exist on a phone. Press and hold a link to preview its destination rather than tapping it. Phones show less of the address, less of the sender and less of the context — when in doubt, wait and verify from a computer.
  • Treat QR codes like unverified links. QR codes in emails and PDFs — known as quishing — are increasingly used to route you to a fake login page. Because there is no clickable link in the message, many email security tools cannot read or evaluate the destination, and scanning it moves you onto a personal phone that your company may not protect. An unexpected QR code deserves exactly the suspicion an unexpected link does.
  • Watch for unusual attachment types. Malicious attachments are no longer mostly .exe files. Password-protected .zip archives, .iso and .img disk images, .html files, and files with a second extension such as invoice.pdf.htm are all used specifically because they slip past scanning. An unexpected file in any of those formats deserves extra suspicion.
  • Don’t open attachments from unknown senders. If you don’t know the sender and weren’t expecting a file, don’t open it. Some malicious files act the moment they are opened.
  • Be careful with shared-document notifications. A convincing message that someone shared a file with you, leading to a real cloud-storage page that hosts a fake sign-in form, is one of the most successful patterns in use. The hosting service is genuine; the login page is not.

Newer Attack Patterns Worth Knowing

Most phishing awareness material still describes attacks from a decade ago. These are the patterns actually costing Colorado businesses money right now.

Business email compromise and wire fraud

Business email compromise (BEC) frequently involves no link and no attachment. It is a spoofed or genuinely compromised account — an executive, a vendor, a title company, a lender — asking someone in accounting to send a payment, change banking details, or buy gift cards, urgently. The FBI’s Internet Crime Complaint Center consistently reports BEC among the costliest categories of cybercrime, far exceeding ransomware in dollars lost, because a successful one moves real money in a single transaction.

The defense is procedural, not technical: verify every unusual or changed payment instruction by phone, on a number you already had, before acting. No exceptions for urgency, and no exceptions for the CEO. Build it into your accounting process so nobody has to make a judgment call under pressure.

MFA fatigue and push bombing

If you receive repeated multi-factor approval prompts you did not trigger, that is somebody attempting to log in with your stolen password, hoping you will tap Approve out of annoyance, confusion or habit. Never approve a prompt you did not personally start, and report it immediately — a burst of prompts means your password is already known to an attacker and needs to change.

OAuth consent phishing

Instead of stealing your password, this attack asks you to sign in with Microsoft or Google and then grant a third-party app permission to read your mail and files. The sign-in screen is genuine. Your password is never captured. But the app keeps standing access to your mailbox — and because no password was stolen, changing your password does not revoke it. Be deliberate about granting permissions to any app you do not recognize, and have your IT provider restrict which apps users can authorize.

Conversation and thread hijacking

An attacker inside a compromised mailbox replies within a real, ongoing email thread — correct history, correct participants, correct subject line, appropriate tone — and attaches the malicious file or changed invoice there. Everything about the context is authentic, which is why this pattern succeeds so often. The only reliable check is the request itself: does this payment, this file, this change actually make sense?

Smishing, vishing and voice cloning

The same tactics arrive by text message (smishing) and phone call (vishing), and increasingly in combination: an email that prompts you to call a number, or a text that follows up on a fake invoice. AI voice cloning now makes a short call from a familiar-sounding executive plausible. Treat urgent voice and text requests with the same skepticism, and verify through a channel you initiated.

Fake IT Support: Microsoft Teams Phishing and Help Desk Impersonation

This one deserves its own section, because it is currently among the most successful attacks in circulation and because it defeats almost everything traditional phishing training teaches. There is no suspicious link to hover over. There is no attachment. Frequently there is no email at all. It arrives as a Microsoft Teams message or call from someone presenting themselves as your IT help desk — and they are not threatening you. They are offering to help.

How the attack actually runs

  1. Your inbox is deliberately flooded. Thousands of newsletter confirmations, subscription notices and mailing-list signups arrive within minutes. Nothing in them is malicious. The flood is not the attack — it is the pretext, and it is designed to make you desperate for help.
  2. A Teams message or call arrives, apparently from IT. The display name reads Help Desk, IT Support, Technical Support Team or something similar. The timing is perfect, because they caused the problem they are calling about. Some campaigns skip the flood and simply open with a routine-sounding request about a security update or a mailbox migration.
  3. They build rapport by being useful. Calm, competent, unhurried, apologetic about the inconvenience. This is the part employees are completely unprepared for.
  4. They ask for remote access. Launch a built-in Windows remote assistance feature, install a legitimate remote support tool, accept a screen-sharing or remote-control request inside the chat, or read out a code shown on your screen. Every tool involved is genuine software, which is exactly why antivirus does not object.
  5. Once they are in, the real work starts. Credential harvesting, persistence so they can return later, mapping your network, and in many cases staging ransomware. Some campaigns also walk the user through approving a multi-factor prompt or entering credentials on a page shared during the session.

Why it works better than email phishing

Nearly all phishing awareness training is built around one emotion: fear. Watch for threats. Watch for deadlines. Watch for pressure. This attack inverts that entirely. Nobody is threatening you, nothing is being suspended, and the person on the other end is solving a problem you genuinely have. Relief is a far more disarming emotion than panic, and no amount of link-hovering practice prepares someone for it.

It also borrows credibility from the platform. Teams is an internal tool, so a message inside it feels internal by default — most people have no mental model for the fact that an outside organization can message them there at all. And because everything the attacker uses is legitimate software operated by a consenting user, endpoint protection sees an employee installing a support tool and getting help. Which is precisely what it looks like.

The tells your team should know

  • Teams marks external senders. Look for the external or guest label on the chat, and expand the sender to see the actual organization. An unfamiliar tenant name, or an address ending in .onmicrosoft.com, is not your IT department.
  • The display name is a role, not a person. Your help desk has names. Attackers use titles, because titles carry authority without being checkable.
  • They contacted you first, about a problem you never reported. This is the single strongest signal. Legitimate support responds to tickets far more often than it cold-calls about an issue you have not mentioned.
  • A sudden flood of spam is an incident, not an annoyance. If your mailbox fills with junk signups, treat it as a warning that a call is coming and report it immediately — before anyone contacts you.
  • The ask is always the same four things. Remote control, installing something, reading a code aloud, or approving a prompt. Any one of those, from someone who contacted you unprompted, ends the conversation.

The one rule that stops it

Close the chat, hang up the call, and reach IT yourself using the contact method you already have. Not a number or link they gave you, not a reply in the same conversation, and not a callback you agreed to. Your own path, initiated by you.

That rule only works if the path is obvious and everyone knows it, which is why we establish it with clients up front: how North Star will contact you, how you reach us, and the standing commitment that we will never object to being verified. Any real support technician will wait while you check. Anyone who pushes back on verification has told you what they are.

What we lock down so the question never reaches your staff

Training is the last line here, not the first. Most of this attack can be removed as an option through configuration your users never see:

  • Restrict external chat in Teams. Open federation with the entire world is the default in many tenants and is rarely needed. We disable external chat initiation, or allow-list only the partner domains you actually collaborate with, so an unknown tenant cannot message your staff at all.
  • Block unapproved remote access tools by policy. Application control that prevents unsanctioned remote support and screen-sharing software from installing or running means a fully convinced employee still cannot complete the handover.
  • Alert on the email-bombing pattern. A sudden inbound volume spike to a single mailbox is a detectable precursor. Catching it gives us a window to warn that user before the call arrives.
  • Phishing-resistant MFA and conditional access, so a code read aloud or a prompt approved under social pressure is not enough on its own.
  • Monitoring that watches for what comes next. Remote tool execution, script activity, new persistence and credential access are all visible to managed detection and response even when the initial access looked consensual.
  • A published, single verified support path plus this scenario built into simulation and training, so the correct response is a habit rather than a judgment call made while a stranger waits on the line.

The Teams settings and application control described here are configured and maintained as part of our managed Microsoft 365 services and managed security services. If you are not certain whether outside organizations can currently message your staff in Teams, that is a five-minute check and worth making today.

What to Do If You Already Clicked

Speed matters far more than embarrassment. Almost every serious incident we respond to was made worse by a delay caused by someone hoping it was nothing.

  1. Report it immediately to your IT team or provider. Minutes matter. Nobody will be angry with you.
  2. If you entered a password, change it now — and change it anywhere else you reused it. Tell IT so active sessions can be revoked, since an attacker with a valid session may not need the password again.
  3. Approve nothing further. Deny any multi-factor prompts that follow.
  4. If you granted someone remote access, disconnect the device from the network immediately and report it as a live incident, not a mistake. Assume everything typed or stored on that machine is compromised, including saved passwords. Do not simply end the session and carry on — attackers install ways back in within the first few minutes.
  5. If you opened an attachment, disconnect the device from the network but leave it powered on, and don’t try to clean it yourself. Evidence in memory helps determine what actually happened.
  6. If money moved, call your bank immediately and ask about a wire recall, then file a report with the FBI’s Internet Crime Complaint Center at ic3.gov. Recovery odds fall sharply after the first 24 to 72 hours.
  7. Don’t delete the email. It is evidence, and it helps identify everyone else who received the same campaign.
  8. Tell your coworkers. Phishing campaigns rarely target one person.

One more thing that catches Colorado businesses off guard: if personal information was exposed, Colorado law (C.R.S. § 6-1-716) requires notifying affected residents within 30 days of determining a breach occurred, with notice to the Attorney General when 500 or more residents are involved. That is half the time HIPAA allows, and it is nearly impossible to meet without logging already in place — you cannot notify accurately if you cannot determine whose data was reached. This is one reason a single clicked link becomes a legal timeline, not just an IT ticket.

Habits That Lower Your Risk

  • Keep software updated. Updates close the specific holes that malicious attachments and drive-by pages are built to exploit.
  • Use modern endpoint protection and keep it current. Traditional antivirus recognizes known threats; behavior-based detection catches the new ones.
  • Use multi-factor authentication everywhere — and where it matters most, use phishing-resistant methods rather than codes that can be typed into a fake page.
  • Stop reusing passwords. A password manager makes unique credentials realistic instead of aspirational.
  • Be careful what you share publicly. Attackers build convincing, personalized email from LinkedIn profiles, staff pages, press releases and social posts. Announcing that your controller is on vacation is useful information to the wrong person.
  • Make reporting frictionless. If reporting a suspicious email is harder than deleting it, people will delete it — and you will lose the warning that the same message went to eleven other employees.

Managed Email Security: Catching What Training Misses

Everything above makes your team meaningfully harder to fool. None of it makes them perfect, and it is not reasonable to expect it to. A well-trained employee reading a hijacked thread from a real vendor account, at 4:45 on a Friday, on a phone, is going to be wrong sometimes. The purpose of email security is to make being wrong survivable.

North Star deploys and manages advanced email security for businesses across the Denver metro area, Colorado Springs and Fort Collins. We describe it here by capability rather than by product name, because what protects your business is what the controls actually do — not whose logo is on them.

Protection inside the mailbox, not just at the gateway

Traditional email filtering inspects mail at the perimeter, before delivery, and stops there. We add inspection that operates inside your mail platform, after native filtering has had its turn. That matters for three reasons: it catches what the built-in filters passed, it can inspect internal messages sent from one compromised colleague to another, and it can act on mail that has already landed in an inbox.

Impersonation and business email compromise detection

The attacks that cost the most contain no malicious payload to scan for. Detection instead models normal communication — who emails whom, in what tone, about what, with what banking details — and flags the message that breaks the pattern: a first-time sender requesting a payment, a vendor whose account details changed, an executive’s display name paired with an unfamiliar address, a reply routed somewhere new. This is the layer that stops wire fraud, and it is precisely the layer standard filtering does not have.

Link protection evaluated at click time

A common evasion is to send a link that is harmless on arrival and weaponized hours later, after scanning has passed. We rewrite and re-evaluate URLs at the moment someone clicks, so the destination is checked against its current state rather than its state at delivery — and blocked with a warning page if it has turned.

Attachment sandboxing and file sanitization

Unknown attachments are opened in an isolated environment and observed for malicious behavior instead of being matched against a list of known-bad signatures. Where speed matters, a sanitized copy — active content stripped out — can be delivered immediately while the original completes analysis, so nobody waits on a legitimate contract.

QR code and embedded-image analysis

Because a QR code is an image rather than a link, most filtering cannot see where it points. We extract the encoded destination from images and PDF attachments and evaluate it the same way a link is evaluated, closing the quishing gap that has grown quickly for exactly that reason.

Post-delivery remediation

When a campaign is identified after delivery, matching messages are removed from every affected inbox automatically — including the ones already read. This single capability changes an incident’s shape: instead of an urgent all-staff warning and a race against whoever clicks first, the mail is simply gone.

Account takeover detection

Compromised accounts announce themselves if anyone is watching: a sign-in from an impossible location, a newly created rule that forwards or hides mail, an unusual sending burst, a mailbox suddenly searching for the word invoice. We monitor for those behaviors and can disable an account and revoke its sessions before it is used to attack your clients and vendors — which is how reputational damage usually happens.

Domain authentication so nobody can send as you

SPF, DKIM and DMARC records, correctly configured and then actually monitored, prevent outsiders from sending email that appears to come from your domain. Most organizations we assess have these partially implemented, in permissive mode, or quietly broken by a marketing platform added years ago. Fixing it protects your clients from being phished in your name, and it improves the deliverability of your legitimate mail as a side effect.

Coverage beyond email, and outbound protection

Attackers follow the conversation, so protection extends to chat, file sharing and cloud storage rather than stopping at the inbox. Outbound data loss prevention watches the other direction, catching sensitive information leaving by mistake — the wrong recipient, an unencrypted attachment of client records, a spreadsheet that should never have left the building.

Simulation, training and a one-click report button

We run realistic phishing simulations, deliver short targeted training to the people who need it, and track whether risk is actually falling over time — useful for insurers and auditors as well as for you. A report button in your mail client sends suspicious messages straight to our analysts for review, so employees get a clear answer instead of a guess, and we get early warning of a campaign in progress.

Layered with everything else

Email security is one layer of several. It works alongside phishing-resistant multi-factor authentication and conditional access through our managed Microsoft 365 services, continuous monitoring through managed threat protection and MDR, identity-based access control through our SASE and Zero Trust solutions, and tested, immutable cloud backup so a bad outcome is a restore rather than a negotiation. The whole program is described on our managed security services and cyber security pages, and delivered as part of managed IT services. For organizations that need documented policy and an audit trail behind all of it, our vCISO and compliance-as-a-service program supplies the governance. For organizations that need to close the adversary-in-the-middle gap specifically, we also offer an optional phishing-resistant browser layer, described in the next section.

Layered email security protecting Colorado businesses against phishing, business email compromise and account takeover

Optional Layer: Phishing-Resistant Browser Protection

Everything described so far happens before a page loads. This layer covers what happens after — and it exists because of one specific attack that has become the endgame for serious credential theft: the adversary-in-the-middle attack, sometimes called man-in-the-middle or AiTM phishing. It is the technique that defeats multi-factor authentication, and it is the reason “we have MFA” is no longer a complete answer to “are we protected against phishing.”

The attack that gets past multi-factor authentication

You click a link and a Microsoft sign-in page appears. It is not a counterfeit. It is the real page, being relayed to you through a server the attacker controls, sitting invisibly between you and the genuine service. Here is what happens next:

  1. You enter your password. The attacker’s server captures it and passes it through to the real service.
  2. The real service asks for your second factor. You approve the prompt or type the code — and it works, because the request is legitimate. You initiated it.
  3. The service issues a session token confirming you are signed in. That token passes back through the attacker, who keeps a copy.
  4. You land in your mailbox. Nothing looks wrong, because nothing went wrong from your side. Meanwhile the attacker now holds an authenticated session and does not need your password or your second factor again.

Two things make this worse than it first sounds. Changing your password does not evict them — a stolen session stays valid until it is explicitly revoked, which someone has to know to do. And the toolkits that run this attack are packaged and resold, so it requires no real skill to operate. It is no longer an advanced technique.

Why email security alone cannot close this gap

Email security is very good at the mail it inspects. The problem is that the link to an adversary-in-the-middle page frequently never travels through email at all. It arrives in a Microsoft Teams chat, a text message, a scanned QR code, a search advertisement, a social media message, or from a legitimate website that has been compromised. None of those pass through your mail platform, so none of them are inspected.

And even when the link does come by email, the decisive moment has moved. The browser is where the page renders, where the password is typed and where the session token is issued. That is the point of loss — and on most networks it is the one place nothing is watching. It is also the layer that still applies when someone is working from a personal laptop or phone that your company does not manage, which is exactly where a lot of quiet compromises begin.

North Star can add a browser security layer that moves the decision point to where the risk actually lives — a managed add-on inside the browser itself, which spots a counterfeit Microsoft sign-in page and stops the user from entering credentials on it.

It recognizes a fake Microsoft login page — and will not let you type your password into it

This is the capability worth understanding before any of the others, because it addresses the exact moment everything is lost. The protection is a managed add-on that runs inside the browser your staff already use — any browser, on any device — and it inspects the sign-in page itself rather than trusting the address bar. When it determines that a page impersonating a Microsoft sign-in is not genuinely Microsoft, it blocks credential entry outright. The password cannot be typed or submitted, and the user gets a clear warning instead of a silent mistake.

Think about what that removes. Every other control on this page asks a person to make a correct judgment call — read the domain backwards, notice the lookalike character, question the urgency. This one does not. An employee can be fully convinced, at the end of a long day, looking at a pixel-perfect copy of the Microsoft sign-in page or a live relay of the real one, and the browser simply refuses to hand over the credential. The judgment call is taken off the employee’s plate and handled at the point of loss.

It matters that this happens in the browser rather than in the mail platform, for two reasons. First, it works no matter how the link arrived — email, Teams, text message, scanned QR code, search advertisement, or a colleague pasting it into a chat. Second, because it is a managed browser add-on rather than a full system agent, it can be deployed and policy-controlled centrally across managed workstations, personal laptops, contractor machines and BYOD alike. That last group is normally invisible to security tooling, and it is where a great many quiet compromises begin.

What else the browser layer adds

Around that core function sit several supporting capabilities. Described by capability, as always:

  • Work credentials restricted to sanctioned destinations. Beyond blocking known-fake sign-in pages, company credentials can be prevented from being entered anywhere that is not an approved identity provider — which also catches employees quietly reusing their work password on personal sites.
  • Every destination evaluated at navigation, whatever the source. Email, Teams, text message, scanned QR code, search result, advertisement, a link pasted by a colleague — all of it is assessed at the moment the browser goes there, which closes the coverage gap left by inspecting only one channel.
  • Relay and proxy sign-in pages detected and blocked. The specific defense against adversary-in-the-middle: recognizing that a login page is being served through an intermediary and stopping the credential from being submitted to it.
  • Newly registered and lookalike domains treated as untrusted. Phishing infrastructure is usually days or hours old. Domains with no history get restricted or isolated rather than trusted by default.
  • Isolation for anything uncertain. Rather than a binary allow-or-block, a questionable site can be opened in a restricted or read-only session where scripts cannot reach the device and nothing can be submitted. The employee still gets to see the page and get on with their day, which is what keeps people from working around the control.
  • Session protection. Hardening the browser session so a token stolen in transit is materially harder to replay elsewhere.
  • Data controls on the way out. Blocking downloads from untrusted pages and preventing sensitive information from being pasted into unsanctioned sites — increasingly relevant for public AI tools, which we cover under secure AI adoption.
  • Coverage on devices you do not own. Because it is a managed browser add-on rather than a full system agent, it extends to personal laptops, contractor machines and BYOD — the population that is normally invisible to security tooling.
  • Visibility fed into monitoring, so a blocked credential-entry attempt becomes an alert we investigate rather than a silent near-miss nobody hears about.

Why we present this as optional

Because it genuinely is. This is an additional layer at additional cost, and plenty of organizations are adequately covered by hardened identity, managed email security and monitoring. We would rather tell you that than sell you everything. It becomes clearly worth the money when one or more of the following is true:

  • Your business effectively lives in web applications, so an account is the whole prize.
  • Staff, contractors or clinicians work from devices you do not manage.
  • You handle regulated data where a hijacked session becomes a reportable breach on a 30-day clock.
  • You move money by wire, or hold client funds and closing information.
  • You have already had a credential incident, or an insurer or client is asking what you do about MFA bypass.
  • Turnover is high enough that training never fully lands before people move on.

One honest qualification. The strongest single defense against adversary-in-the-middle attacks is phishing-resistant multi-factor authentication — hardware security keys and passkeys, which are cryptographically bound to the real site and cannot be relayed — paired with conditional access policies that reject unfamiliar devices and locations. We deploy that through our managed Microsoft 365 services, and it should be in place first. Browser protection complements it and covers the accounts, applications and unmanaged devices that phishing-resistant MFA cannot always reach. Anyone selling you the browser layer as a substitute for fixing identity has the order backwards.

Phishing Terms, Defined

A quick reference for the vocabulary you will encounter in security training, insurance questionnaires and incident reports.

TermWhat it means
PhishingA message impersonating a trusted source to obtain credentials, money or system access.
Spear phishingPhishing tailored to a specific person using researched details about their role, employer and relationships.
WhalingSpear phishing aimed at executives and other high-authority targets.
Business email compromise (BEC)Fraud using a spoofed or compromised business account to redirect payments or data, usually with no link or attachment involved.
QuishingPhishing delivered through a QR code, which most filters cannot read because it is an image.
SmishingPhishing delivered by SMS or text message.
Help desk / IT support impersonationAn attacker posing as internal or outsourced IT support, usually by chat or phone, to talk a user into granting remote access or approving a login.
Teams phishingPhishing delivered through Microsoft Teams chat or calls, typically from an external tenant using a role-based display name such as Help Desk.
Email bombingDeliberately flooding a mailbox with thousands of harmless signup confirmations to create a pretext for a fake IT support call.
Remote access tool abuseUsing legitimate remote support or screen-sharing software, installed by a deceived user, to gain hands-on control of a machine without triggering antivirus.
VishingPhishing conducted by phone call, increasingly assisted by AI voice cloning.
Thread hijackingReplying inside a genuine, ongoing email conversation from a compromised mailbox so the attack inherits real context.
MFA fatigue / push bombingFlooding a user with repeated multi-factor approval prompts until one is accepted out of annoyance or habit.
OAuth consent phishingTricking a user into granting a malicious app standing permission to their mailbox and files, without ever stealing a password.
Adversary-in-the-middle (AiTM)Also called man-in-the-middle phishing. A relay server sits between the victim and the real sign-in page, capturing the password, passing the multi-factor challenge through, and stealing the resulting session token — bypassing MFA entirely.
Session hijacking / token theftUsing a stolen session token to act as an already-signed-in user. A password change does not revoke it; the session must be explicitly terminated.
Phishing-resistant MFAAuthentication using hardware security keys or passkeys, cryptographically bound to the genuine site so it cannot be relayed through an attacker.
Browser isolationOpening an untrusted page in a restricted or read-only session so scripts cannot reach the device and credentials cannot be submitted.
Credential harvestingCapturing usernames and passwords through a counterfeit sign-in page.
Account takeover (ATO)An attacker operating a legitimate user account as if it were their own.
Lookalike / typosquatted domainA registered domain designed to resemble a real one closely enough to pass a glance.
Display name spoofingPutting a trusted person’s name on an account whose actual address is unrelated.
Payload-less attackAn attack carried entirely by text, with nothing to scan — the reason content and context analysis is necessary.
Post-delivery remediationAutomatically removing a malicious message from inboxes after it has already been delivered.
SPF, DKIM, DMARCEmail authentication records that let receiving systems verify mail genuinely came from your domain.

Serving Businesses Across the Front Range

North Star provides email security, phishing defense, security awareness training and complete managed IT for organizations of 5 to 300 endpoints across Colorado’s Front Range — Denver, Aurora, Lakewood, Arvada, Westminster, Thornton, Northglenn, Broomfield, Commerce City, Brighton, Centennial, Greenwood Village, Englewood, Littleton, Highlands Ranch, Parker, Castle Rock, Golden, Wheat Ridge, Colorado Springs, Monument, Fort Collins, Loveland, Windsor, Greeley and Longmont, along with the surrounding communities.

Phishing risk looks different by industry, and the money moves through different doors. We tailor email security for the sectors where a single redirected payment or exposed record does the most damage — including law firms, financial services firms such as accounting and tax practices and investment advisors, healthcare and medical practices, real estate, property management and HOA firms facing closing wire fraud, construction firms and contractors, manufacturers, nonprofits, special districts and local government, dealerships and automotive businesses, and defense contractors pursuing CMMC compliance. Every program we run is listed on our industries page.

Frequently Asked Questions

How can I tell if an email is a phishing email?

Check the domain after the @ symbol rather than the display name, ask whether you were expecting the message, look for urgency or secrecy in the request, preview any link before clicking it, and never approve a multi-factor prompt or app permission you did not personally start. If a request involves money, credentials or a banking change, verify it by phone on a number you already have. You do not have to be certain an email is malicious to report it — being unsure is reason enough.

Can a phishing email harm me if I only opened it and didn’t click anything?

Simply opening and reading an email is very rarely harmful on its own with a modern, updated mail client. Risk begins when you click a link, open an attachment, enter credentials, approve a prompt or reply. Remote images in an email can confirm to the sender that your address is live and being read, which typically means more targeted attempts. Opening one is not a crisis, but it is worth reporting.

Doesn’t Microsoft 365 already stop phishing emails?

Built-in filtering catches high-volume spam and known-bad senders, and it is a genuine baseline. It is weakest against exactly the attacks that cost the most: a payload-less request from a real, compromised account; a link weaponized after delivery; a QR code it cannot read; internal mail from one compromised colleague to another. Dedicated email security adds inspection inside the mailbox, impersonation and BEC detection, click-time link evaluation, attachment sandboxing and the ability to pull malicious mail back out of inboxes after delivery.

Is bad grammar still a reliable sign of phishing?

No, and this is one of the most important updates to make to older training. AI writing tools let attackers produce flawless, professional, correctly localized email at scale. Grammar mistakes are still worth noticing when they appear, but their absence tells you nothing. Judge the request and the sender domain instead of the prose.

What should I do if I clicked a phishing link or entered my password?

Report it to your IT team or provider immediately — speed matters more than embarrassment. Change the password from a different device and change it anywhere you reused it, and have active sessions revoked, because an attacker holding a valid session may not need the password again. Deny any multi-factor prompts that follow. If you opened an attachment, disconnect the device from the network but leave it powered on. If money moved, call your bank about a wire recall and file a report at ic3.gov, because recovery odds drop sharply after the first 24 to 72 hours. Don’t delete the email; it is evidence.

What is business email compromise, and how is it different from phishing?

Business email compromise is a targeted fraud that uses a spoofed or genuinely compromised business account to redirect money or data, and it usually contains no link and no attachment at all — just a plausible request to wire funds, change banking details or buy gift cards. That absence of a payload is what makes it so hard for conventional filtering to catch, and why it consistently ranks among the costliest categories of cybercrime. The most effective control is a firm rule that unusual or changed payment instructions are verified by phone, on a known number, before anything is sent.

Are QR codes in emails safe to scan?

Treat an unexpected QR code exactly like an unverified link. Because a QR code is an image rather than clickable text, many email security tools cannot read or evaluate where it leads, and scanning it moves you onto a personal phone that your company may not protect. Attackers have adopted them heavily for that reason. If you did not expect it, don’t scan it — navigate to the site yourself instead.

Why do I keep getting multi-factor approval requests I didn’t ask for?

Because someone already has your password and is trying to log in, hoping you will eventually tap Approve out of annoyance or habit. This is called MFA fatigue or push bombing. Never approve a prompt you did not start, and report it right away — the password needs to be changed and the account reviewed, and stronger, phishing-resistant authentication methods should replace simple approval prompts on accounts that matter.

Does security awareness training actually reduce phishing risk?

Yes, meaningfully — particularly training paired with realistic simulations and a frictionless way to report suspicious mail. It does not get you to zero, and no honest provider will claim otherwise. The point of training is to reduce how often people are fooled; the point of technical email security is to make it survivable when they are. Programs that rely on only one of the two are the ones that produce expensive surprises.

Someone messaged me in Teams saying they’re from IT support. Is that legitimate?

Be very skeptical, particularly if they contacted you first about a problem you never reported. A widespread attack uses Microsoft Teams messages and calls from external organizations, with display names like Help Desk or IT Support, to talk employees into granting remote access to their computer. Check whether Teams has labeled the sender as external and expand it to see the actual organization — an unfamiliar tenant name or an address ending in .onmicrosoft.com is not your IT department. Then close the chat and reach your IT provider through the contact method you already have. A real technician will always wait while you verify.

My inbox suddenly filled with thousands of spam signup emails. What does that mean?

Treat it as a security incident and report it right away, before anyone contacts you. Attackers deliberately flood a mailbox with harmless newsletter and subscription confirmations to manufacture a problem, then follow up by phone or Microsoft Teams posing as IT support offering to fix it. The flood is the setup; the call is the attack. If someone reaches out about it and asks to remote into your machine, install software, read a code aloud or approve a login prompt, end the conversation and contact IT yourself.

Can outside organizations message our staff in Microsoft Teams?

By default, in many tenants, yes — external chat and calling is often left open to any other organization, and most businesses have no idea it is enabled. That setting is what makes help desk impersonation in Teams possible in the first place. It can be disabled outright, or restricted to an allow-list of the partner domains you genuinely collaborate with, which removes the attack path without affecting legitimate work. We check and configure this as part of managing Microsoft 365, and it is worth verifying today if nobody has looked.

We have MFA. Doesn’t that stop phishing?

It stops a lot of it, and it remains one of the highest-value controls you can have — but no, not entirely. Adversary-in-the-middle attacks, also called man-in-the-middle phishing, defeat most forms of MFA. The attacker relays the real sign-in page through a server they control, so your password is captured, your multi-factor challenge is passed through and completed legitimately, and the session token issued at the end is stolen in transit. The attacker then holds an authenticated session and needs neither your password nor your second factor again. Changing your password does not evict them; the session has to be explicitly revoked. The defenses that do work are phishing-resistant MFA using hardware keys or passkeys, conditional access, and browser-level protection that blocks credential entry on a relayed page.

What is a man-in-the-middle phishing attack?

It is a phishing page that acts as a live relay in front of the genuine login page rather than a static counterfeit. Because you are looking at the real page, nothing appears wrong: the branding is correct, the URL may be close enough to pass, and your multi-factor prompt works normally. Behind it, the attacker records your password and copies the session token the service issues once you authenticate. Ready-made toolkits have made this commodity rather than advanced, and it is now the standard endgame for credential theft against organizations that have MFA enabled.

How can browser protection stop phishing that email security misses?

Because it evaluates the destination at the moment the browser navigates there, regardless of how the link arrived. Email security only inspects email — it cannot see a link sent in a Microsoft Teams chat, a text message, a scanned QR code, a search advertisement or a compromised legitimate website. Browser-level protection also sits at the point where the loss actually occurs: the page render, the password entry and the session token. It can refuse to let work credentials be typed into any site that is not a sanctioned sign-in destination, isolate pages on newly registered domains, and detect a relayed login page. It also covers personal and unmanaged devices, where no corporate mail client is involved at all.

If a phishing attack exposes data, does a Colorado business have to notify anyone?

Often, yes. Colorado breach-notification law (C.R.S. § 6-1-716) requires notifying affected Colorado residents within 30 days of determining a breach occurred, with notice to the Attorney General when 500 or more residents are affected — half the time HIPAA allows. Industry rules may add obligations on top, including HIPAA for healthcare, GLBA and the FTC Safeguards Rule for financial services, and DFARS reporting for defense contractors. This is general information rather than legal advice; confirm your specific obligations with counsel. North Star handles the technical and documentation side, including the logging that makes accurate notification possible in the first place.

Make Security a Priority

Send this page to your team — it is written to be shared, and it is a reasonable part of onboarding. Then let’s talk about the layer underneath it. North Star will review how mail actually reaches your organization, test whether your domain can be spoofed, show you what your current filtering is and is not catching, and put managed email security in place alongside the rest of a layered managed security program.

Bottom line: trust no email until you have verified it. Contact North Star to make sure the ones that get through can’t cost you.