phishing

How to spot phishing emails at work

AA
Aurum Avis Labs Author
6 min read

How to spot phishing emails

You spot phishing emails by checking whether the story matches how your company really works: unexpected parcels, tax messages, bank alerts, or Microsoft 365 sign-in warnings that push you to act in minutes. Look at the sender address, the link destination (hover without clicking), and whether anyone inside the firm already announced the same theme. In Swiss offices, imitations of postal services, rail tickets, cantonal e-tax, banks, and Microsoft 365 are routine.

52 %

NCSC (BACS) half-year report 2025/2: share of fraud among voluntary reports in the second half of 2025. Not our survey.

This guide is for employees and team leads in a Swiss SME with 20 to 250 staff. It leaves out what to do after a click. Payment fraud with a changed IBAN follows a different playbook, described in invoice fraud with a changed IBAN.

  • Does the sender domain match the organisation it claims to be?
  • Does the link go to the real site when you hover?
  • Is the tone unusually urgent or personal for your role?
  • Would this process normally arrive by app, letter, or a known portal?

The visible name in Outlook or Apple Mail may say “Swiss Post” while the address behind it reads @post-ch-customs.net. Read the domain from the right: login-microsoft-secure.ch belongs to whoever registered it, not to Microsoft. Short links and QR codes in a mail hide the destination in the same way.

On a laptop, hover over the link without clicking. On a phone, long-press the link and read the URL, or open the official app instead of the message. If the mail asks for a password on a website you otherwise never use, stop, even when the layout looks familiar.

Swiss-looking themes that appear often

Parcel and delivery notes. A message claims customs fees or a failed delivery and offers a link to “reschedule”. Real carriers usually contact you through the channel you chose at purchase. A button in an unexpected mail is not that channel.

Rail and mobility. Fake refund or ticket-problem mails are common around the travel seasons. Check your tickets in the SBB app or at sbb.ch, never through the link in the mail.

Cantonal e-tax and e-government. Tax offices use fixed portals and do not ask for your banking password by email. If your canton moves you to eTax, it announces that through official channels you already use with the administration.

Banking and TWINT. Your bank may send alerts, but you log in through the banking app or a bookmark you set yourself. TWINT warnings appear in the TWINT app, never as a link from an unfamiliar domain.

Microsoft 365 and shared documents. Links to a “shared invoice” or a “voice message” are frequent in business inboxes. Open documents from the OneDrive or Teams interface you already use, or ask the colleague in a Teams chat.

  • Finance and admin

    A mail “from the CEO” demands an urgent transfer or a new IBAN. Stop rule: never change payment details on the strength of a mail alone. Call back on a number you already know.

  • Reception and shared mailboxes

    ”Parcel could not be delivered” with a payment link. Stop rule: track shipments only in the shop or carrier the customer chose at purchase.

A made-up example

A made-up example: on a Monday morning a mail arrives at the info@ address of an accountancy firm in Lucerne. The sender is “Microsoft Security”, the message says “account locked in 24 hours”. The receptionist does not click the link. She forwards the mail to IT and flags it as phishing. IT sees that three colleagues received the same template, blocks the domain in the filter and warns everyone on Teams. Nobody clicked. The firm is invented; the pattern is typical.

What is no longer proof on its own

A spelling mistake alone does not prove a fake. Legitimate marketing can also come from unfamiliar domains. Context decides: would finance really change a supplier’s bank details by email alone? That overlap with invoice fraud is why finance and admin need their own rules.

Attachments and internal forwards

Report attachments with macros or an “enable content” prompt instead of opening them or saving them to a shared drive. If a PDF asks for a password “to view the invoice”, treat it like any other unexpected attachment. Loading remote images can tell the sender that the address is active. That is a reason to report the mail, not to reply.

Internal mailing lists sometimes forward genuine alerts from IT. Ask once a year whether your IT team ever sends links, or whether it always tells you to open the admin portal yourself. Once you know that pattern, you get fewer false alarms and fakes stand out.

Who should not rely on this page alone

IT administrators who tune spam filters need technical documentation, and this article is too basic for them. Private individuals can use the consumer advice from the police and BACS. Here the focus is a shared company mailbox and an IT partner.

Report instead of debating

When unsure, forward the mail to your internal phishing mailbox or IT partner, following the process your employer has defined. Early reports help block the same mail for your colleagues. External reporting to BACS has its own how-to article.

Managers should take reports seriously and thank the person who sent one. Deloitte’s 2026 cyber study of firms under 250 employees found that 86 % consider cyber training helpful. In that survey, 65 % of small and 82 % of medium firms report regular training, and phishing is still among the most frequent attacks. Spotting mail is a skill you refresh, not a one-off memo.

May I forward the mail to warn colleagues?

Only through the internal channel IT defines. An ad-hoc forward puts a live phishing link into more inboxes.

Does the spam filter catch everything?

No. New domains and compromised senders still get through. Human checks and reporting remain necessary.

What if I already clicked?

Report it internally at once, change your password if you entered credentials, and follow your IT incident steps. A separate article covers the first minutes after a click.

Training for everyday mail

Security awareness training takes your team through Swiss examples, reporting paths and payment fraud patterns in a live session of one to two hours. Afterwards, reception and finance work with the same stop rules.

phishing email awareness switzerland
AA

Written by

Aurum Avis Labs

Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.

Customize your cookie preferences. Essential cookies cannot be disabled as they are required for the website to function properly.

Essential Cookies

Required for basic website functionality, security, user authentication, and error tracking.

Always active

Analytics Cookies

Help us understand how visitors interact with our website to improve user experience. Includes Google Analytics and Microsoft Clarity session recordings.

Marketing Cookies

Used to track visitors across websites to display relevant and engaging advertisements.