Three phishing tricks that are most often used to scam you

Phishing (phishing) for years cybercrime is the most common method because it targets weaknesses in human attention, not systems. Attackers use the names of well-known brands and service providers, using an urgent tone, to try to get the recipient to click without thinking – and enter their password or bank card details on a fake page. Below are the three most common forms. 

What most phishing messages have in common is an artificial sense of urgency: the message suggests that you must act immediately or you will lose money, lose access, or miss out on something. This pressure intentionally short-circuits the process of deliberation – it targets the exact moment when someone quickly, mechanically, clicks on a link without looking at the sender’s real address or URL. The following three schemes regularly appear in almost every mailbox in Hungary. 

Courier emails 

Attackers send messages on behalf of well-known parcel delivery services, stating that the package was not delivered successfully or that a symbolic small amount – a few hundred forints – must be paid for the delivery. The essence of the trick is precisely this small amount: most people do not suspect a fee of a few hundred forints, while the bank card details provided by clicking on the link are sent to the attackers, who can then charge the card without any restrictions. It is worth considering it as a rule that we only pay for packages in the official application or at the courier's location, never via a link received in an email. 

Bank notifications 

These messages claim that the account has been blocked for security reasons, a suspicious transaction has been detected, or that customer information needs to be updated urgently. The goal is to panic the recipient and click on the provided link to enter their login details on a deceptively similar banking interface – which the attackers use to log in to the real system in real time. As a general rule, banks never ask for passwords, PINs, or one-time codes via email or phone; if in doubt, the safest course of action is to visit the bank’s official app or officially known phone number directly, not the contact information provided in the email. 

Microsoft 365 or Google account alerts 

The user receives a message stating that their password has expired, their mailbox is full, or that a login from an unusual location has been detected. The link provided leads to a login page that is visually almost identical to the original, where the entered username and password are sent directly to the attackers. Since these accounts are often the key to corporate mail, documents, and other services, the gained access can then be extended to other systems in the company. Two pillars of defense are enabling two-factor authentication (MFA) and getting in the habit of always checking the domain name that appears in the browser address bar before logging in. 

What can the company do to prepare its employees? 

The above schemes are easily recognizable on their own, but real protection comes from regularity: periodic, practical training – even with simulated phishing campaigns –, a clear internal procedure for reporting suspicious messages, and a corporate culture in which a colleague who admits to a wrong click is greeted with help, not shame. 

The Hungarian Cybersecurity Cluster is working with its partners to ensure that domestic businesses are prepared to face these challenges - through research collaborations, professional programs and training.