Skip to content

Recognising phishing and fraud

Phishing is a message pretending to come from someone you trust (your bank, a supplier, Sooma, a colleague) to get you to hand over your password, pay a fake invoice or open a malicious attachment.

Warning signs

  • Urgency or threats: "your mailbox will be deactivated today", "overdue payment", "confirm within 24 hours".
  • A sender that does not add up: the name looks right but the address does not (for example support@sooma-mail.com instead of a Sooma address). In webmail, hover over the sender's name to see the full address.
  • Misleading links: the text says one thing and the address the link points to is another. Hover over it before clicking.
  • Requests for passwords or codes: Sooma never asks for your password by email, phone or SMS.
  • Bank details change: a supplier who has "changed bank" and asks you to pay into another account. Always confirm by phone, on a number you already had.
  • Unexpected attachments: invoices, orders or documents you did not ask for, especially .zip, .html, .exe or Office documents asking you to "enable content".

What to do

  1. Do not click links, open attachments or reply.
  2. If the message claims to come from someone you know, confirm through another channel (phone, chat, in person).
  3. Move the message to Spam or delete it.
  4. If you think it is an attempt targeting your company, tell the service administrator.

If you have already clicked or given away your password

  1. Change your password immediately, on a trusted computer.
  2. Update the new password on your devices.
  3. Check under Preferences > Filters and Out of Office for any forwarding you did not create. It is a common trick to keep reading your mail.
  4. Tell the administrator and open a ticket with Sooma support.