Phishing attacks target you directly — your email, your phone, your judgment. Technical security systems catch most of them, but not all. Understanding how phishing works and what to look for gives you the best chance of avoiding the attacks that get through.
This guide is written for NZ employees, not IT professionals. No technical background required.
What Is a Phishing Attack?
A phishing attack is an attempt to trick you into doing something that gives an attacker access they should not have. The most common goals are:
- Getting you to enter your username and password on a fake login page
- Getting you to open a file that installs malware on your computer
- Getting you to approve a payment or transfer funds to a fraudulent account
- Getting you to give out sensitive information (your password, a verification code, personal details)
Phishing arrives most commonly by email, but also by text message (called smishing), phone call (vishing), and increasingly through Microsoft Teams, WhatsApp, and other messaging platforms.
Why Phishing Is Harder to Spot in 2026
The old advice — look for bad spelling and awkward phrasing — is no longer reliable. AI tools allow attackers to generate fluent, grammatically correct phishing messages in natural New Zealand English. Fake login pages are visually identical to the real thing. Display names in email can be set to anything, so an email appearing to be from your CEO or your bank may not be.
What you are looking for instead are behavioural signals — things the email is trying to make you do — rather than quality signals.
Warning Signs to Look For
Urgency and pressure. Phishing emails frequently create a sense of emergency: "Your account will be suspended in 24 hours," "Action required immediately," "Unusual activity detected." Urgency is designed to make you act before you think. Any email demanding immediate action on something financial or credential-related should be treated with suspicion.
Requests for credentials or verification codes. Legitimate services will not ask you to reply to an email with your password, or to provide a verification code sent to your phone. If you receive a code you did not request, do not share it with anyone — including someone claiming to be from IT support or your bank.
Mismatched sender addresses. The display name of an email (what appears in your inbox) can be set to anything. The actual sender address is what matters. In most email clients you can see the actual address by hovering over or clicking the sender name. A display name of "Microsoft Support" with an actual address of "support@microsoft-helpdesk247.com" is a phishing email.
Unexpected requests from known contacts. If a colleague, supplier, or executive sends you an unexpected request — particularly involving payment, credentials, or installing something — contact them through a different channel (phone, Teams message if the request came by email) to verify before acting.
Links that do not go where they should. Before clicking any link in an email, hover your mouse over it to see the actual destination URL. If an email appears to be from your bank but the link goes to a different domain, do not click it. On mobile, press and hold the link to preview the destination.
What to Do When Something Looks Suspicious
- Do not click, do not reply, do not download. If something feels wrong, trust that instinct.
- Report it. Use whatever reporting process your organisation has — a report button in Outlook or Gmail, a message to IT, a specific email address. Reporting suspicious emails helps your IT team track what is targeting the business and improve filters.
- If you did click something, say so immediately. The worst outcome is clicking a phishing link and saying nothing. If you clicked a link, entered credentials on a site you are not sure about, or opened an attachment that behaved unexpectedly, tell your IT team or manager straight away. Acting within the first hour after a phishing click can contain the damage significantly.
- If you received a suspicious call or text, hang up or do not respond. You can always call back on a number you look up independently.
The Habits That Keep You Safe
Use a different password for every account. If a password is stolen from one site, it cannot be used to access another. A password manager makes this practical — you only need to remember one master password.
Never share verification codes. A one-time code sent to your phone is a second factor for authentication. Once you share it, whoever has it can authenticate as you. No legitimate organisation will ask for it over the phone or by email.
Lock your screen when you step away. Physical access to an unlocked computer is a form of attack too — and phishing is not always remote.
Keep your work devices updated. Software updates patch the vulnerabilities that malware delivered through phishing exploits.
When in doubt, check. It takes thirty seconds to call a colleague to verify an unusual request. It can take months to recover from acting on a phishing email without checking.
Your employer can train the whole team with SecureAZ phishing simulations and awareness modules