Cybersecurity

Phishing Red Flags: How to Spot Fake Emails Before They Cost You

Phishing Red Flags: How to Spot Fake Emails Before They Cost You

The 2022 Scam-Message Surge Has Reached Your Inbox

Your phone has buzzed more this month than in almost any month you can remember — promos you never signed up for, texts from unknown numbers, emails from "banks" you do not even bank with. Mixed into that noise are messages engineered to steal your password, your payroll, or your GCash balance, which is why every Philippine business owner should learn how to spot phishing emails before somebody on the team clicks one. Scammers are betting on a busy week and a distracted staff.

This is not a vague worry. Globe says it blocked 1.15 billion scam and spam messages in 2021, along with roughly 7,000 scam-linked mobile numbers and about 2,000 fake social media accounts and phishing sites (Globe Telecom Newsroom). The National Privacy Commission (NPC) and the National Telecommunications Commission (NTC) have been chasing it since late 2021.

The policy fix many hoped for is not coming. The SIM Card Registration bill was vetoed in mid-April 2022 (reported April 15), over the free-speech implications of its social-media provisions (Philstar). No registration law means senders stay anonymous, so the last line of defense is the person reading the message.

Phishing is a fake message impersonating someone you trust — your bank, a courier, a supplier, even your boss — to make you hand over credentials or money. Here are seven red flags anyone can check in under a minute.

How to Spot Phishing Emails: 7 Red Flags to Check Before You Click

None of these checks need special software — just thirty seconds of suspicion. It is the checklist we walk client staff through when we begin cybersecurity services for Philippine businesses. Phishing is a numbers game: the sender needs one hurried person, and a five-person online shop is a softer target than a bank because nobody there is paid to review the inbox.

1. The Sender's Address Doesn't Match the Name

The pattern: the display name reads like your bank or a courier, but the address behind it is a free Gmail account or a lookalike domain — bd0-notice.com, with a zero where a letter should be. On a phone, tap the display name to reveal the real address.

Legitimate businesses send from a domain they own — one reason why your business needs a professional email address. The version we see most this year: a "delivery fee" notice for a parcel, sent from [email protected].

2. Urgent Threats and Deadline Pressure

The pattern: "Your account will be suspended within 24 hours." "Verify now or lose access." Urgency is engineered to make you skip every other check. Real institutions give you time, and none will penalize you for using their official app instead of their link. If a message insists you have minutes, open the app instead.

3. Generic Greetings and Sloppy Details

The pattern: "Dear Valued Customer." A branch that does not exist, an off-brand logo, awkward Taglish, a misspelled subject line. Blasts are generic because the sender does not know who you are — someone bought a list and hit send. A message that knows nothing about you yet claims you won something is doubly suspect.

The pattern: the visible text says yourbank.com.ph while the link underneath goes somewhere else. Hover to read the real address on desktop, long-press to preview on mobile, be wary of shortened links. The padlock only means the connection is encrypted — criminals get certificates too.

In March, the Bangko Sentral ng Pilipinas directed banks and e-money issuers to strengthen their guard against phishing — removing clickable links from emails and texts to retail clients, notifying customers of credential changes, and adopting multi-factor authentication (BusinessWorld). As banks comply, an email "from your bank" with a login link is suspicious by default. Type the address yourself or use the app.

5. Attachments You Weren't Expecting

The pattern: an invoice you never ordered, a "receipt" for a purchase nobody made, a resume nobody applied with. Zip archives, stray .html files, and macro-enabled Office documents are the classic carriers. House rule: an unexpected attachment gets confirmed with the sender through another channel — a call, a Viber message — before anyone opens it.

6. Anyone Asking for Your OTP, Password, or Card Number

The pattern: someone on the phone or in an email needs your one-time PIN (OTP) "to verify your identity." No bank, e-wallet, or telco will ever ask for it. The OTP request is the scam.

That is why the BSP push toward multi-factor authentication — MFA, a second proof of identity on top of your password — matters: the OTP is the lock criminals must talk you into opening. The same rule covers your own office: an "email from the boss" ordering an urgent transfer deserves a call to the actual boss.

7. Too-Good-to-Be-True Jobs, Prizes, and Rewards

The pattern: easy work-from-home income, a raffle you never joined, a free load reward, a cash "package" waiting on a claim fee. This is the bait the NPC flagged when it warned the public against smishing — SMS phishing — amid the flood of texts offering fake jobs and prizes (Philstar). Employers do not recruit strangers by mass text.

It's Not Just Email: The Same Scams Hit SMS, Viber, and Messenger

Smishing is phishing by text, and here it is the louder channel. In a memorandum dated November 19, 2021, NTC Commissioner Gamaliel Cordoba ordered Globe, Smart, DITO, and Digital Mobile Philippines to text-blast warnings to subscribers; telcos traced the wave to senders hosted overseas (GMA News).

The NPC's probe pointed to an organized global syndicate, and found no direct evidence the numbers came from COVID-19 contact-tracing forms (SunStar). That is industrialized crime, not a one-time leak. Apply all seven red flags wherever your team communicates — Messenger, Marketplace threads, your Shopee or Lazada seller inbox.

What One Wrong Click Can Cost

In March, hackers stole roughly $615 million in ETH and USDC from the Ronin network behind Axie Infinity; the breach was disclosed on March 29 (CNBC). Filipino players felt that one personally. Strip away the crypto talk and it is the oldest story in security: someone got access they should not have had, and real money left the building.

Scale it down and the shapes are familiar: a hijacked inbox that redirects a supplier payment, an e-wallet drained over a weekend, locked files. What lingers longest is the customer who saw a scam post on your Facebook page and stopped ordering. The scammer risks a template email; you risk payroll week.

  1. Disconnect and scan. Take the device off Wi-Fi and run a full antivirus scan.
  2. Change the exposed password, email first. Your email account can reset every other account you own.
  3. Turn on two-factor authentication. Use an authenticator app rather than SMS where possible.
  4. Call your bank on the official hotline — the number on your card or inside the app, never one from the message.
  5. Tell your team. One compromised inbox is used to phish coworkers and clients next.

Then report it: inform your bank, report to the NPC, and forward scam texts to your telco's official reporting channel.

Your Best Firewall Is a Trained Team

Filtering works — Globe's billion-plus blocked messages prove it at scale. But whatever slips through lands in front of a human answering forty things at once. Ten minutes of red-flag review in your next staff meeting beats an annual seminar everybody forgets by March.

Layer the basics around it. Pair the training with the work-from-home security habits every Filipino employee needs, and give off-site staff a safe way in — we covered setting up a secure VPN for your hybrid team earlier this year.

Most SMEs cannot justify a full-time security officer, and they do not have to. That is the case for managed IT support that watches your inboxes and patches for you — filtering, monitoring, and updates handled in the background, so knowing how to spot phishing emails is your team's backup plan, not your only plan.

Not sure your team would catch all seven? Book a free call and we will walk through your email setup, spam filtering, and a quick phishing drill for your staff — plain answers, no obligation.

Empowering Businesses with Customized Software Solutions

Tell us what you need — we typically reply within the day. Let’s build something that drives your business forward.