HomeBlog › Security

Technologies & IT Services · Montreux · Swiss Riviera

Phishing: spot a fake e-mail in ten seconds

A breakdown, a question?

Most SME hacks don’t start with a technical feat, but with a well-imitated email and someone in a hurry. Here is what to look at before you click.

Published on 8 September 2026 · 5 min
  • Written without jargon
  • A question we are often asked
  • Updated when the tools change
Eramis
FREN

Phishing (phishing) means pretending to be someone trustworthy in order to obtain a password, a payment or get an attachment opened. Today’s messages have no spelling mistakes, the right colours, and are sometimes written in your name. Yet they almost always give themselves away.

Six telltale signs

  • Urgency. “Your account will be closed in 24 hours”, “transfer to be made before noon”. A real supplier gives you time.
  • The sender’s address. Not the name displayed, the real address: a lookalike domain, with an extra letter or a hyphen.
  • The link. Hover over it without clicking: the address that appears is not that of the site it claims to be.
  • The unusual request. A password, a code received by text message, gift cards, a change of bank account for a supplier.
  • The unexpected attachment. An invoice you were not expecting, a compressed file, a document asking you to “enable content”.
  • The tone. Too formal, too familiar, or simply not that of the person supposedly writing.

CEO fraud

A message, apparently from the boss while travelling, asks the person who does the accounts for an urgent, confidential transfer. The defence isn’t technical: any unusual payment and any change of bank details is confirmed by phone, on a number you already know.

I clicked. What now?

No panic, and no shame: it happens to the most careful people. If you entered a password, change it straight away, everywhere you use it, and turn on two-factor authentication. If you opened an attachment, unplug the workstation from the network and call. The sooner it is said, the less serious it is.

Where to report it

In Switzerland, the Federal Office for Cybersecurity (NCSC) collects reports of fraudulent messages on its website. It only takes a minute and helps get fake sites shut down.

What really protects you

Two-factor authentication makes a stolen password useless. Email filtering stops a good share of messages before they arrive. And a team that has seen real examples, once a year, clicks far less. That is the purpose of our awareness workshop.

In short: urgency is the alarm bell. When a message rushes you, that is the moment to slow down and check through another channel.

Would your team click?

A day of IT security awareness training, for the whole team.

See the training