What are Phishing emails and what do I need to be aware of?
Phishing emails (derived from the English word ‘fishing’) are a particularly dangerous type of spam. They often occur in waves. This is due to the fact that so-called bot networks are regularly dismantled, as a result of which the volume of spam decreases. However, Internet fraudsters always manage to set up new networks quite quickly and continue sending spam.
In this FAQ, we would like to give you tips on how to avoid falling victim to this scam.
What are Phishing emails?
Phishing e-mails are fake e-mails sent by cyber criminals in the name of reputable providers such as STRATO in order to steal personal data from Internet users. These fake messages are used in an attempt to obtain personal data in order to commit identity theft. In many cases, the fraudsters use logos, fonts and layouts from companies. On the redirected pages, the websites of companies can also be imitated.
So-called phishers (fraudsters) try to obtain sensitive data in this way, for example:
- Usernames and passwords
- Bank account or credit card numbers
- PINs
- TANs and much more.
Please note: These emails are not from STRATO! They are e-mails with forged sender addresses and manipulated links that ask you to click on them:
- Submitting your personal data as an email response.
- Following a link, for example to a manipulated ‘strato-like’ website, in order to enter your personal data there.
- Downloading email attachments that contain malware and spy on your personal data.
How do I recognise Phishing emails?
- Check the spelling (Orthography)
A good indication that it is a Phishing email is the spelling of the text. This is often machine-translated from another language and therefore incorrect. - Check the sender
Take a close look at the sender. It may be forged, but it can also be a good way of recognising that it is a fraud attempt. - Check the links
So-called phishers often misuse the appearance of reputable companies and include them in their emails. Pay close attention to the links in the letter, as these are usually not attributable to the company and indicate a Phishing page. To be on the safe side, move your mouse over them without (!) clicking on them. You will then see the actual target page - an untrustworthy address. An example in german can be found here. - Check your connections
Check your connections and only enter user names and passwords when you are on a secure website (e.g. https://www.strato.de). 'https' is the abbreviation for Hypertext Transfer Protocol Secure (secure transmission protocol).
You can find more tips in the german STRATO blog post How do I recognise Phishing emails? (with an english mail example)
What do I do after receiving a Phishing e-mail?
Never follow the requests of Phishing e-mails! Never pass on your personal data by e-mail. Do not click on the links and do not download the e-mail attachments.
Even if you are asked to reply within a certain period of time, please do not comply with this request under any circumstances - especially not if it is accompanied by a threat, for example the cancellation of a domain or the blocking of your e-mail access. These threats in particular are often a sign that it is a Phishing e-mail.
Before you delete the Phishing e-mail, you can check that it is genuine.
How does STRATO protect me from Spam/Phishing?
STRATO takes the following measures against Spam/Phishing:
1. Preventive measures:
STRATO provides a spam filter in its webmailer. Use this or the spam filter of your own e-mail programme. The filter helps to recognise unwanted emails and at the same time achieve the highest possible spam recognition rate. Activate the DMARC mechanism.
2. Communicative measures:
STRATO informs you when Phishing mails are in circulation and gives you tips on how to recognise them.
3. Measures in the event of abuse:
STRATO has its own Abuse department that investigates and prevents cases of abuse. If email inboxes or STRATO servers are misused for phishing, Abuse takes appropriate measures, such as blocking.
Check the authenticity of a STRATO e-mail with the STRATO Mailvalidator
Have you received an e-mail from STRATO? And do you doubt whether it is genuine? Then use our mail validator and find out immediately whether it is phishing. You can find our mail validator here.