THE DHS PHISHING IQ TEST PART 1
LEGITIMATE V PHISHING How do you know if an is legitimate, or is a phony, phishing ? Take the DHS Phishing IQ Test, and well show you what to look for in a phishing . The best way to avoid getting phished is to NEVER CLICK ON LINKS IN THAT ASK FOR YOUR IDENTIFYING INFORMATION DHS IT Security & Privacy Training 2
INSTRUCTIONS FOR THE DHS PHISHING IQ TEST You will see an example of an on the screen. Decide whether it is legitimate or phishing DHS IT Security & Privacy Training 3
LEGITIMATE OR PHISHING? 2014 DHS IT Security & Privacy Training 4 Legitimate Phishing Which answer? This is supposedly a message from PayPal stating you have added a named person to your PayPal account. The message threatens to suspend your PayPal account if you do not respond.
If you download, complete, and send the Personal Profile Form at the end of this , you may have given away your personal information. Remember, don't use the links in an , instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't know the sender DHS IT Security & Privacy Training 5
LEGITIMATE OR PHISHING? 2014 DHS IT Security & Privacy Training 6 Which answer? LegitimatePhishing This is supposedly a notification from Facebook. It provides a link to click to remove the message.
One way you can tell is to put your cursor over the link, then look at the link in the bottom of the browser. Do they match? This doesnt. So its easy to see this is phishing for your information. Remember, don't use the links in an , instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't know the sender DHS IT Security & Privacy Training 7
LEGITIMATE OR PHISHING? 2014 DHS IT Security & Privacy Training 8 Which answer? Legitimate Phishing This is supposedly from Prevention Magazine. It is for a subscription confirmation.
This was legitimate. The receiver was a subscriber to the magazine and she later received a paper bill through the USPS mail. However, the receiver was not sure if the was legitimate, so she did not use the links in this to get to the web page DHS IT Security & Privacy Training 9