Gone Phishing: Five Signs That Identify Scam Email Messages

A significant danger to businesses today is phishing—the act of forging email to fool someone into revealing login credentials, credit card numbers, or other sensitive information. Of course, phishing is a problem for individuals too, but attackers more frequently target businesses for the same reason as bank robber Willie Sutton’s apocryphal quote about why he robbed banks: “Because that’s where the money is.”

The other reason that businesses are hit more often is that they have multiple points of entry—an attacker doesn’t need to go after a technically savvy CEO when they can get in by fooling a low-level employee in accounting. So company-wide training in identifying phishing attempts is absolutely essential.

Here are some tips you can share about how to identify fraudulent email messages. If you’d like us to put together a comprehensive training plan for your company’s employees, get in touch.

Beware of email asking you to reveal information, click a link, or sign a document

The number one thing to watch out for is any email that asks you to do something that could reveal personal information, expose your login credentials, get you to sign a document online, or open an attachment that could install malware. Anytime you receive such a message out of the blue, get suspicious.

If you think the message might be legitimate, confirm the request “out of band,” which means using another form of communication. For instance, if an email message asks you to log in to your bank account “for verification,” call the bank using a phone number you get from its Web site, not one that’s in the email message, and ask to speak to an account manager or someone in security.

Beware of email from a sender you’ve never heard of before

This is the email equivalent of “stranger danger.” If you don’t know the sender of an email that’s asking you do something out of the ordinary, treat it with suspicion (and don’t do whatever it’s asking!). Of course, that doesn’t mean you should be entirely paranoid—business involves contact with unknown people who might become customers or partners, after all—but people who are new to you shouldn’t be asking for anything unusual.

Beware of email from large companies for whom you’re an anonymous customer

Attackers often forge email so it appears to come from a big company like Apple, Google, or PayPal. These companies are fully aware of the problem, and they never send email asking you to log in to your account, update your credit card information, or the like. (If a company did need you to do something along these lines, it would provide manual instructions so you could be sure you weren’t working on a forged Web site designed to steal your password.)

Since sample email from large companies is easy to come by, these phishing attacks can look a lot like legitimate email. Aside from the unusual call to action, though, they often aren’t quite right. If something seems off in an email from a big company, it probably is.

Beware of email from a trusted source that asks for sensitive information

The most dangerous form of this sort of attack is spear phishing, where an attacker targets you personally. A spear phishing attack involves email forged to look like it’s from a trusted source—your boss, a co-worker, your bank, or a big customer. (The attacker might even have taken over the sender’s account.) The email then requests that you do something that reveals sensitive information or worse. In one famous spear-phishing incident, employees of networking firm Ubiquiti Networks were fooled into wiring $46.7 million to accounts controlled by the attackers.

Beware of email that has numerous spelling and grammar mistakes

Many phishing attacks come from overseas, and attackers from other countries seldom write English correctly. So no matter who a message purports to come from, or what it’s asking you to do, if its spelling, grammar, and capitalization are atrocious, it’s probably fraudulent. (This is yet another reason why it’s important to write carefully when sending important email—if you’re sloppy, the recipient might think the message is fake.)

One of the best ways to train employees about the dangers of phishing is with security awareness testing, which involves sending your own phishing messages to employees and seeing who, if anyone, falls for it. Again, if you need help doing this, let us know.

Ignore Unsolicited Calls and Texts from Apple and Other Tech Companies

We don’t want to belabor the point, but multinational tech companies like Apple, Facebook, and Google will never call or text you personally out of the blue. So if you get a call or text purporting to be from such a company, it’s 99.9% likely to be a scam, and you should ignore it regardless of whether the caller ID seems legitimate. If you’re still worried, look up the company’s tech support phone number separately—never respond directly to such a call or tap a link in a text—and discuss the situation with the support reps. Or contact us, and we’ll talk it through with you.

Did You Know You Can Use Your Mac Laptop Closed with an External Screen and Keyboard?

Those of you who use a Mac laptop—a MacBook, MacBook Air, or MacBook Pro—probably know you can connect it to a large external display for more screen space. But sometimes it’s not convenient to have your Mac open on your desk next to the big screen. If you’d like to close your Mac’s screen and just use the external display, you can! The trick to enabling closed-display mode is that your Mac must be plugged into an AC outlet and you must connect an external keyboard and mouse or trackpad—either USB or Bluetooth. (If you’re using any Bluetooth devices, go to System Preferences > Bluetooth > Advanced and make sure “Allow Bluetooth devices to wake this computer” is selected.)

iCloud Services Being Wonky? Check Apple’s System Status Page

Many Apple users rely on mac.com, me.com, or icloud.com email addresses, along with plenty of other iCloud-related services. So if you can’t send or receive email, if photos aren’t transferring via iCloud Photo Library, or if some other iCloud-related service isn’t responding, the first thing to do is check Apple’s System Status page. It’s updated every minute, and if it shows that the associated Apple service is having problems, you know to sit tight until things come back up. If everything is green, you’ll have to look elsewhere for a solution—or get in touch with us.

Troubles with Messages? Read On for Ten Possible Solutions

Apple’s Messages app for iOS and macOS generally works well, but when it doesn’t, figuring out what’s wrong and how to fix it can take some doing. Here are a few of the most common solutions we’ve come across for problems with sending and receiving messages.

Help Android-switcher friends turn off iMessage

Do you have a friend who previously used an iPhone but later switched to an Android phone? People like that can confuse your copy of Messages, which doesn’t know if it should send to them via iMessage (no) or SMS (yes). If you text with someone in this situation, get them to deregister from iMessage.

Check device connectivity

If messages aren’t flowing when you think they should be, the first “is it plugged in?” thing to check is connectivity. Make sure that your iPhone has at least cellular service (for SMS) and cellular data (for iMessage) and that your iOS device isn’t in Airplane mode. In the case of a Mac, make sure it’s connected to your network.

Relaunch the Messages app

Force-quitting in iOS isn’t something you should do willy-nilly, since it slows down your device and hurts battery life, but it’s worth trying if Messages isn’t sending or receiving messages correctly. Double-press the Home button on Touch ID devices or swipe up and to the right from the bottom of the screen on Face ID devices, then swipe up on the Messages app thumbnail to force-quit it. On the Mac, just quit and relaunch Messages.

Toggle iMessage off and back on

Here’s an easy one. In iOS, go to Settings > Messages and turn the iMessage switch at the top off and back on. iMessage may take a minute or two to reactivate. On the Mac, go to Messages > Preferences > iMessage > Settings, uncheck Enable This Account, and then log in again.

Toggle Messages in iCloud off and back on

With the new Messages in iCloud feature, Apple syncs conversations through your iCloud account. If messages from one device aren’t showing up properly on another device, in iOS, go to Settings > Your Name > iCloud and turn Messages off and back on. On the Mac, go to Messages > Preferences > iMessage > Settings and uncheck and recheck Enable Messages in iCloud.

Verify your phone number and email addresses are correct in Messages settings

SMS relies on a phone number, and you can be contacted via iMessage via a phone number or email address. Make sure you can be reached at all the appropriate ones. In iOS, go to Settings > Messages > Send & Receive to check. On the Mac, look in Message > Preferences > iMessage > Settings.

If they’re not right, fix them in iOS in Settings > Passwords & Accounts > iCloud > Your Name > Contact Information, by tapping Edit in the Reachable At section. On the Mac, you add these addresses with the plus button in System Preferences > iCloud > Account Details > Contact.

Verify that SMS fallback is enabled

When you’re in an area with sketchy cell service, there may not be enough of a data connection for iMessage to work. In such a situation, SMS text messages are more likely to get through, but Messages will try to send to iMessage users via SMS only if you turn on Send as SMS in Settings > Messages.

Check text message forwarding settings

If you’re receiving SMS messages on your iPhone but not any of your other devices, make sure Text Message Forwarding is enabled for the relevant devices (they need to be signed in to the same iCloud account). On your iPhone, look in Settings > Messages > Text Message Forwarding.

When in doubt, restart

Restarting can resolve all manner of problems, so it’s always worth a try if all the settings and accounts are correct. On the Mac, of course, just choose Apple > Restart. For iOS devices with Touch ID, press and hold the top button until the Slide to Power Off slider appears. For those with Face ID, press and hold the side (iPhone) or top (iPad) button and one of the volume buttons until the slider appears.

Reset network settings in iOS

Finally, the most voodoo of the fixes we’ve seen work is to reset network settings in iOS. You don’t want to start with this option because doing so also resets Wi-Fi networks and passwords, cellular settings, and VPN settings. But if all else fails, go to Settings > General > Reset > Reset Network Settings.

If none of these techniques fix your problem, let us know and we’ll see what we can do to help!