Example 1: a fake bank security email
We detected a sign-in to your online banking from an unrecognised device. For your protection, access will be restricted unless you confirm your identity.
Please using the secure link below.
Northbridge Bank Customer Security Team
- 01Sender domain is not the bank's. "northbridge-secure-login.com" is a lookalike. A real bank sends from its own domain, and even that can be faked, so the domain alone never proves anything.
- 02Generic greeting. Your bank knows your name. "Valued Customer" means the same message went to thousands of people.
- 03Manufactured urgency. A 24-hour deadline and "URGENT" in capitals are there to stop you thinking.
- 04Asks for your password and memorable word. No bank asks you to type these into a link from an email. This is the entire point of the message.
- 05The link text does not match the real destination. The button says northbridge.com, but hovering (or long-pressing on a phone) shows a different address on someone else's hosting.
- 06Tells you not to check with anyone. Isolation is a classic scam move. A genuine bank would be glad you called your branch.