Recognizing Phishing, Smishing and VishingUpdated: 2026
Identify the most common forms of digital fraud and know how to respond β before it's too late.
By the end of this module, you'll be able toβ¦
- Recognize the 5 visual clues of a fraudulent email
- Distinguish phishing, smishing and vishing
- Identify a BEC (CEO fraud) attempt
- Apply the verification method before clicking, replying or paying
Understanding phishing
Marie gets an email from "her bank" asking her to confirm her login details following "suspicious activity." The email looks professional. She clicks. Two hours later, her account is empty.
Phishing is a fraud technique where an attacker poses as a trusted entity β a bank, a government agency, an online service β to extract personal information, credentials or money from you.
Unlike viruses that exploit technical flaws, phishing exploits human psychology: trust, urgency, fear. That's why it's so effective β and so hard to spot at first glance.
In 2024, phishing accounts for over 80% of cyberattacks reported in Canada. A single click is enough to compromise an account or install malware.
Spotting a fraudulent email β the 5 clues
Every phishing email contains at least one of these 5 clues. Learn to spot them systematically.
β The 5 clues to check
- The sender address: hover over the address (not just the displayed name). support@bank-security.net β realbank.com
- The link URL: hover without clicking. The real domain is what comes right before the first "/" after "https://"
- Artificial urgency: "Your account will close in 24h" β real institutions don't threaten this way
- The unusual request: no legitimate bank asks for your PIN or password by email
- Errors and inconsistencies: blurry logo, spelling mistakes, odd formatting
Spear phishing β targeted attacks
Jean-FranΓ§ois, the CFO of an SMB, gets an email from his CEO (whose first name and writing style he knows) asking for a discreet $15,000 transfer for a confidential acquisition. The email comes from ceo-martin.gauthier@gmail.com β not the real account.
Spear phishing is targeted phishing: the attacker has researched your name, your role, your company β often on LinkedIn β to craft a hyper-personalized message that appears to come from someone you know.
These attacks are much harder to detect than generic phishing. The success rate is 3 times higher.
β Protecting yourself from spear phishing
- Check the sender's exact address β not just the displayed name
- For any transfer or urgent action: confirm by phone at the usual number
- Be wary of "confidential" or "urgent" requests even from a superior
- Limit the professional information you post on LinkedIn
Smishing β text message scams
Text received: "Canada Post: your package #CA928471 is held at customs. $2.95 fee required: canada-post-package.net/pay". The link leads to a fake site that steals banking information.
Smishing is phishing by text message. Attackers exploit the fact that we trust texts more than emails, and that we read them quickly on mobile without checking the details.
β Common mistakes with smishing
- Clicking the link "to check" β you could install malware
- Calling back the number in the text β it's a number controlled by the scammer
- Providing your card information to "settle the customs fee"
β Good reflexes
- Never click an unexpected text link β go directly to the official website
- Real delivery services don't require payment by text
- Report to 7726 (SPAM) to block the sender
Vishing β phone call scams
Incoming call: "Hello, this is Sergeant Tremblay from the RCMP. Your SIN is involved in a money-laundering case. To protect your money, you need to buy Google Play gift cards immediatelyβ¦"
Vishing uses a voice call to manipulate you. Techniques include: an authoritative voice, official-sounding jargon, extreme urgency, threats of legal consequences. Scammers can even spoof the displayed number to make it look official.
β Absolute rule
- Real governments and banks NEVER ask for gift cards
- Hang up without hesitation if you're being pressured or threatened
- Call back yourself using the official number you look up β never the number displayed
Business Email Compromise (BEC) β CEO fraud
Sophie, the finance director of an SMB, gets an email from the "CEO" asking for a $48,000 transfer for a confidential acquisition, to be handled "before tonight." The email address is presidentsmirnov@gmail.com β the real CEO doesn't have a Gmail account.
BEC specifically targets businesses. Attackers pose as an executive (CEO, GM) and request an urgent, confidential wire transfer. In 2023, BEC caused over $2.9 billion in losses in the US and Canada.
β Anti-BEC procedure
- Any out-of-process transfer request must be confirmed by a direct call (usual number)
- Set up a rule: 2 signatures for any transfer above a certain amount
- Be wary of "confidentiality" β it's a classic pressure tactic
- Train your finance team: a written procedure is the best protection
Fake tech support
You visit a site and a pop-up appears: "β οΈ VIRUS ALERT β Your computer is infected! Call 1-800-XXX-XXXX now!" This is scareware β fake tech support.
Scammers make you believe your device is compromised, then sell you a "cleanup" or get remote access to your computer to steal your data.
β Responding to fake support
- Close the window (or tab) β don't let the noise or flashing alerts intimidate you
- NEVER call a number displayed in a browser pop-up
- Never give remote access to your computer to someone who contacted you
- Microsoft and Apple don't proactively contact you about a technical problem
Gift card fraud and impersonation
Gift cards (iTunes, Google Play, Steam, Amazon) are scammers' preferred payment method: they're anonymous, untraceable and non-refundable. Absolute rule: no official organization (government, bank, public service) ever asks for payment in gift cards.
β Common scam scenarios
- "You owe money to the tax agency β pay in gift cards to avoid arrest"
- "Your son is in jail β send gift cards for his bail"
- "You won a contest β pay the fees with iTunes cards"
The STOP-CHECK method before clicking, replying or paying
Faced with any suspicious message, apply this 4-step method before acting.
STOP β Slow down
Urgency is a manipulation tool. Take 30 seconds before any action.
CHECK the sender
Verify the full address (not just the displayed name). Look for inconsistencies.
CONFIRM through another channel
Call the real organization at the official number β never the one given in the message.
REPORT if it's a scam
Canada: antifraudcentre.ca / 1-888-495-8501. Reporting protects other potential victims.
Email simulator β spot the clues
Simulated example for educational purposes β the brands mentioned are not affiliated with ObjectifCyber.
Click the highlighted zones to reveal the phishing clues in this simulated email.
Dear valued customer,
We have detected unusual activity on your account. To protect your access, you must confirm your identity immediately.
Click the link below: https://bank-verification-portal.com/confirm-identity
If you don't act within 24 hours, your account will be permanently suspended.
Sincerely,
The Bank Security Team
Module quiz
Test what you've learned with 4 questions.
See also