How to avoid the horrors in your inbox this Halloween

With Halloween looming closer, it’s not just the monsters under the bed we have to worry about. Ghosts hide in unexpected places, ghouls are lurking at our fingertips, the real horrors of Halloween are closer than you might realize, and clicking on a phishing email can unleash great terrors upon you!

Our inboxes are filled with unwelcome surprises and these sorts of monstrosities won’t be scared away by garlic, mirrors, or a silver bullet. Here’s how to avoid them this Halloween!

Trick or Treat?

Don’t allow yourself to fall victim to hackers who take advantage of Halloween marketing emails hoping to lure you into their trap. Promises of scarily low prices may seem appealing but think twice before you open a link sent to you via email. Do not be fooled – remember to check the domain address twice to see if the message is from a legitimate sender.

By keeping lists of safe contacts, you can be more confident that you’re not being lured into giving away data or sensitive information. Phishing emails can come in all different shapes and sizes, you don’t have to be asked for data directly to be tricked into giving it away so be confident you know who you’re dealing with before making any decisions that could come back to bite you.

Beware of werewolves in sheep’s clothing

Today, hackers are more sophisticated than ever before, domain addresses can be replicated directly and they no longer show classic telltale signs like big teeth or sharp claws. No matter how hard you look there is seemingly no difference between a fake email and a legitimate one so it is essential you make use of the safety features and verification methods readily available to you.

Most email providers such as Gmail and Microsoft have anti-phishing and malware capabilities and have already adopted DMARC – make use of these protection methods and don’t rely on the naked eye to spot an imposter.

Delving into the darkness

With new online retailers popping up every day, it can be tempting at Halloween to try somewhere new to buy your broom or cauldron, but remember to err on the side of caution. There are ghosts lurking around every corner and it’s important to remember that while your inbox might be protected – some retailers’ digital assets aren’t.

Before you partake in any risky business, take the time to search who you’re shopping with. Often, a quick Google search can flag up any horror stories about untrustworthy retailers and save you from becoming their next casualty. But, if you do choose to go with someone you don’t know, companies that invite double sign-ins or ask that ask for email verification are more secure than those who don’t.   

Don’t fall victim to everyday inbox horrors   

You wouldn’t face a zombie attack without gathering some supplies first, so be prepared and use what’s readily available to you to ensure you are prepared for what lurks behind the corner. This Halloween, remember: don’t forget your fancy dress, get to grips with DMARC, know who you’re dealing with, make use of in-built safety features, and most importantly, don’t go into that haunted house alone!

To find out more about How Red Sift can help protect you and your business from the horrors of email phishing, get in touch!

Get in touch

PUBLISHED BY

Red Sift

29 Oct. 2018

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
Finance

41% of top Fintech companies are vulnerable to email phishing

Jack Lilley

Only 26% of leading Fintechs enforce DMARC at p=reject, the strongest protection against spoofing by bad actors. Phishing remains a top driver of breaches and fraud. Financial services are a prime target because email moves money, resets passwords, and confirms identity. Verizon’s 2025 Data Breach Investigations Report again lists social engineering and phishing among…

Read more
Certificates

New in Certificates Lite: Active certificate scanning and smarter expiry alerts

Francesca Rünger-Field

A quick recap Earlier this year, we launched Red Sift Certificates Lite, the free TLS certificate expiration monitoring service recommended by Let’s Encrypt. Since launch, thousands of organizations have adopted it to track their certificates and avoid expiry-related outages. What we heard from customers At launch, we had adopted Let’s Encrypt’s approach for consistency…

Read more
AI

Red Sift’s AI Agent, Part II: Optimization for accuracy and scale

Phong Nguyen

In our previous blog post, we introduced Red Sift’s AI Agent for lookalike classification – an intelligent system that determines whether a suspicious domain has been deliberately crafted to mimic a legitimate one or if the resemblance is merely coincidental. That post focused on the what and why of the solution: why rule-based automation…

Read more
Brand Protection

Separating signal from noise when fighting brand spoofing

Rahul Powar

“Alert fatigue” must be the most common malady among cybersecurity professionals. According to a recent survey, 56% of large companies handle 1,000+ alerts each day. For 70% of security professionals, the volume of alerts has doubled in the past few years, with more than 51% of campaigns involving some form of AI-generated brand spoofing.…

Read more