Spot the Phish Website - Costco

Spot the Phishing Attempt - Cybersecurity Awareness

The images displayed below are a combination of phishing emails and real email messages. Can you tell which of them are phishing attempts? Click on the images to zoom in.

 

Spoiler Alert: Answers are below.

 

Image 1 details: The image contains a phishing hyperlink that spells Costco as Costoco, a huge cybersecurity awareness red flag.

Costco 1 Phishing Attempt and Explanation

Image 2 details: Michelin is spelled wrong.

Costco 2 Phishing Attempt and Explanation

Image 3 details: The image has a phishing barcode and a QR code. There are free barcode reader verification websites available online. For example: https://online-barcode-reader.inliteresearch.com/. The barcode and QR code used in the image below turn up as phishy when verified online, this one looks like a phishing attack.

Costco 3 Phishing Attempt with explanation

Image 4 details: The hyperlink is a legitimate Costco website link. There aren’t any typical red flags in the email and it passes all cybersecurity checks.

 

Boost Your Cybersecurity with ERMProtect

No matter how much an organization improves its technical defenses, employees can fall victim to phishing attacks and other hacker lures. ERMProtect™ arms employees with the tools and security awareness they need to protect themselves and their organizations from cyber attacks. To speak with an expert on our cybersecurity team please call (800) 259-9660 or click here to schedule a free demo.

ERMProtect's Weekly Newsletter

Get a curated briefing of the week's biggest cyber news every Friday.

Stop Phishing Attacks with ERMProtect's Security Awareness Training

Turn your employees into a human firewall with our innovative Security Awareness Training.

Our e-learning modules take the boring out of security training.

Intelligence and Insights

Aligning Your Incident Response Plan with NIST SP 800-61 Rev. 3

Aligning Your Incident Response Plan with NIST SP 800-61 Rev. 3

This article offers key updates in the latest NIST guidance, why they’re significant, and what practical steps you can take to update your organization’s incident response plan …
CEO Checklist: How To Know If Your Organization Is Cyber Secure

CEO Checklist: How To Know If Your Organization Is Cyber Secure

This CEO Checklist is a starting point for executive oversight – to spot gaps, test what your team is telling you, & prioritize where to invest attention/budget …
Guide to Penetration Testing Services

Guide to Penetration Testing and Advanced Techniques in Penetration Testing Services

Penetration testing is the interactive nature of the control evaluation. Unlike static assessments, penetration testing services involve dynamic interaction with the system …