One of my readers lost $50,000 in Bitcoin to an email that was, in every technical sense, real. Here is the forensic breakdown, and the one concept that would have saved them.
Their first mistake was clicking a link in an email. At all. The only acceptable links to click on in an email are, say, from a Substack post.
You never do that for companies you do business with - not even Amazon.
You go to the company home page on the Web in your browser from a link you have in your browser or, better, the link you have in your on device password manager.
Thus you access the REAL home page of the company. You login using their login page - following whatever protocol they require - and then you do whatever business is needed.
This whole scam would have failed if this obvious approach had been taken. Phishing only works if you don't do this habitually.
Their first mistake was clicking a link in an email. At all. The only acceptable links to click on in an email are, say, from a Substack post.
You never do that for companies you do business with - not even Amazon.
You go to the company home page on the Web in your browser from a link you have in your browser or, better, the link you have in your on device password manager.
Thus you access the REAL home page of the company. You login using their login page - following whatever protocol they require - and then you do whatever business is needed.
This whole scam would have failed if this obvious approach had been taken. Phishing only works if you don't do this habitually.
Well said! Agree 100%.