Phishing messages can put your AmailPlus mailbox, business information and other accounts at risk. This guide explains the warning signs and how to check a suspicious request before you act.

What is phishing?

Phishing is an attempt to trick you into sharing sensitive information or taking an unsafe action by pretending to be a person or organisation you trust. An attacker may impersonate Aveshost, a supplier, a colleague or your bank to steal a password, obtain payment information, persuade you to transfer money or get you to open a harmful file.

How to spot a phishing attack

1. Check the sender's full email address

Look beyond the display name. A message labelled “Aveshost Support” is not proof that Aveshost sent it. Expand the sender details and inspect the complete address, particularly the domain after the @ symbol.

Watch for added words, missing letters and lookalike characters. For example, [email protected] is an illustrative lookalike address, not an Aveshost support address. A public email address can also be suspicious when you expected a message from a company's own domain. Even a familiar address may belong to a compromised account, so check the request as well.

2. Look for spelling and wording problems

Unusual spelling, awkward sentences or inconsistent terminology can be warning signs. However, a well-written message can still be fraudulent. Do not rely on good grammar as evidence that a message is genuine.

3. Notice pressure, threats and unexpected rewards

Be cautious about messages demanding immediate action to prevent mailbox suspension, avoid a penalty or claim a prize you did not expect. An urgent deadline is a reason to verify the request independently before entering details or making a payment.

4. Inspect links and attachments before opening them

On a computer, hover over a link without clicking to inspect its destination. The visible text may say www.aveshost.com while the link points somewhere else. Read the actual hostname carefully: in the illustrative address aveshost.com.login-check.example, the website belongs under login-check.example, not aveshost.com.

For account access, use a trusted bookmark or type the known address yourself. Avoid opening unexpected attachments, and do not enable macros or install software simply because an email tells you to. Confirm unexpected files with the sender through a known contact method.

5. Treat branding as a clue, not proof

A distorted logo, unusual layout or inconsistent colours may indicate a fake message. Attackers can also copy genuine logos and email designs. Check the sender, destination and purpose of the request even when the message looks professional.

6. Protect passwords and verification codes

Do not send your AmailPlus password, one-time verification codes, recovery codes or full payment-card details in an email reply. Treat requests for these details as suspicious. Sign in through the official website you opened yourself, and contact Aveshost Support if you are unsure about a request.

7. Verify through official channels

Do not use the reply address, phone number or support link supplied in a suspicious message to verify that same message. Open the Aveshost website yourself and use Aveshost Support. You can access your client account at my.aveshost.com and webmail at webmail.amailplus.com.

8. Question requests that do not fit the situation

An unexpected request from “your manager” to transfer funds, change bank details, buy gift cards or share a confidential document needs a separate check. Call the person using a number you already know, or use another established communication channel. A familiar name or existing email conversation does not guarantee the request is legitimate.

9. Check the website address as well as HTTPS

Before entering a password, check the full address in the browser. HTTPS encrypts the connection, but phishing websites can use HTTPS too. A padlock or other secure-connection indicator alone does not prove that a site belongs to Aveshost or another trusted organisation. If the address is unfamiliar or the browser displays a security warning, stop and verify the destination.

Common phishing techniques

  • Email phishing: messages impersonating a company or service to lure recipients into clicking a link, opening a file or providing information.
  • Spear phishing: a tailored message aimed at a particular person or business, often using details that make it seem credible.
  • Smishing: phishing delivered through text messages.
  • Vishing: a phone call in which an attacker impersonates a trusted organisation or support agent.
  • Clone phishing: a copied legitimate message with a link or attachment replaced by a malicious one.
  • Whaling: targeted phishing aimed at executives or other people with access to valuable information or payment authority.

Protecting your AmailPlus account

  • Use a long, unique mailbox password. A password manager can help you generate and store it. Change it promptly if it has been exposed or you suspect unauthorised access.
  • Enable two-factor authentication wherever your account supports it. Ask Aveshost Support about the options available for your service if you cannot find them.
  • Keep your browser, operating system, email applications and security software updated.
  • Use trusted bookmarks for AmailPlus webmail and the Aveshost client area instead of signing in through unexpected email links.
  • Report suspicious messages through Aveshost Support before following their instructions. Do not include your password or verification codes in the report. Support can advise how to provide the message and its headers safely.
  • Keep backups of important business information and make sure colleagues know how to verify unusual requests.

If you already clicked a link or shared information

If you entered your password on a suspicious page, use the official website from a trusted device to change it immediately. Change it on any other account where you reused it, and contact Aveshost Support for help checking your mailbox and access settings.

If you opened a suspicious download, update your security software and run a scan. If you shared payment information or sent money, contact the relevant bank or payment provider immediately using its official contact details.

Remember: Pause, check the request through a trusted channel and proceed only when you have verified it.

For further guidance, see the FTC guide to recognising and avoiding phishing scams.

這篇文章有幫助嗎? 0 用戶發現這個有用 (0 投票)