How to avoid the horrors in your inbox this Halloween

With Halloween looming closer, it’s not just the monsters under the bed we have to worry about. Ghosts hide in unexpected places, ghouls are lurking at our fingertips, the real horrors of Halloween are closer than you might realize, and clicking on a phishing email can unleash great terrors upon you!

Our inboxes are filled with unwelcome surprises and these sorts of monstrosities won’t be scared away by garlic, mirrors, or a silver bullet. Here’s how to avoid them this Halloween!

Trick or Treat?

Don’t allow yourself to fall victim to hackers who take advantage of Halloween marketing emails hoping to lure you into their trap. Promises of scarily low prices may seem appealing but think twice before you open a link sent to you via email. Do not be fooled – remember to check the domain address twice to see if the message is from a legitimate sender.

By keeping lists of safe contacts, you can be more confident that you’re not being lured into giving away data or sensitive information. Phishing emails can come in all different shapes and sizes, you don’t have to be asked for data directly to be tricked into giving it away so be confident you know who you’re dealing with before making any decisions that could come back to bite you.

Beware of werewolves in sheep’s clothing

Today, hackers are more sophisticated than ever before, domain addresses can be replicated directly and they no longer show classic telltale signs like big teeth or sharp claws. No matter how hard you look there is seemingly no difference between a fake email and a legitimate one so it is essential you make use of the safety features and verification methods readily available to you.

Most email providers such as Gmail and Microsoft have anti-phishing and malware capabilities and have already adopted DMARC – make use of these protection methods and don’t rely on the naked eye to spot an imposter.

Delving into the darkness

With new online retailers popping up every day, it can be tempting at Halloween to try somewhere new to buy your broom or cauldron, but remember to err on the side of caution. There are ghosts lurking around every corner and it’s important to remember that while your inbox might be protected – some retailers’ digital assets aren’t.

Before you partake in any risky business, take the time to search who you’re shopping with. Often, a quick Google search can flag up any horror stories about untrustworthy retailers and save you from becoming their next casualty. But, if you do choose to go with someone you don’t know, companies that invite double sign-ins or ask that ask for email verification are more secure than those who don’t.   

Don’t fall victim to everyday inbox horrors   

You wouldn’t face a zombie attack without gathering some supplies first, so be prepared and use what’s readily available to you to ensure you are prepared for what lurks behind the corner. This Halloween, remember: don’t forget your fancy dress, get to grips with DMARC, know who you’re dealing with, make use of in-built safety features, and most importantly, don’t go into that haunted house alone!

To find out more about How Red Sift can help protect you and your business from the horrors of email phishing, get in touch!

Get in touch

PUBLISHED BY

Red Sift

29 Oct. 2018

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
AI

Staying ahead of AI-powered brand impersonation

Rahul Powar

Executive summary: AI has supercharged brand impersonation, with Q2 2024 seeing nearly half of all processed emails containing spoofing or phishing attempts—40% of which were AI-generated. The scale, speed, and sophistication of these attacks are overwhelming security teams, draining resources on false positives, and leaving critical threats undetected. Consumers are unforgiving when trust is…

Read more
BEC

What is email spoofing and how can you prevent it?

Faisal Misle

Executive summary: Email spoofing is a growing cyber threat where attackers forge the sender’s address to impersonate trusted sources, enabling phishing, business email compromise, and financial fraud. Because legacy email protocols like SMTP lack strong authentication, spoofing can bypass traditional filters. Organizations can mitigate this risk by implementing robust email authentication measures, especially DMARC.…

Read more
Email

What is social engineering and how can you prevent it?

Jack Lilley

Executive summary: Email phishing has evolved and criminals now use social engineering to impersonate executives, suppliers, and even government agencies, persuading recipients to approve payments or disclose credentials. Because human judgment sits at the heart of these attacks, technical controls that eliminate spoofed messages before they reach the inbox are essential. DMARC provides that…

Read more
Cybersecurity

Attackers are abusing Microsoft 365: Here’s how to stay protected

Jack Lilley

Executive summary: Varonis has surfaced an active phishing campaign that spoofs internal users by abusing Microsoft 365’s Direct Send feature. Because Direct Send doesn’t require authentication and is treated as “internal,” these messages often bypass the checks you rely on for outside mail. Microsoft now offers an opt-in switch, RejectDirectSend, to block the pathway,…

Read more