Most IT security breaches do not start with advanced hacking. They start with an employee clicking a link in an email. Phishing remains the most commonly used attack method against Danish companies, and attacks are becoming increasingly convincing. It is no longer enough to look for spelling errors and odd sender addresses. You and your colleagues need to know the rules of the game.

What is phishing?

Phishing is an attempt to trick you into disclosing login credentials, paying money, or installing malicious software, by impersonating someone you trust. It most commonly occurs via email, but also via SMS (called smishing) and phone (called vishing).

Attackers invest time in making the message credible. They copy logos, write flawless Danish, and construct a scenario that creates urgency. The goal is to make you act before you have time to think it through.

Three attack types you need to know

Email phishing

The classic variant. You receive an email that appears to come from Post Danmark, SKAT, Microsoft, your bank, or, and this is where it gets dangerous, from your own manager or a colleague. The email typically contains a link to a fake login page or an attachment with malicious code.

A realistic Danish example: You receive an email with the subject line "Your Microsoft 365 license expires today, confirm your subscription". The sender address resembles support@microsoft-renewal.dk, the logo is correct, and the link leads to a page that is identical to Microsoft's login page, but the address in the browser's address bar ends in .net instead of .com.

SMS phishing (smishing)

Here the employee receives an SMS that typically claims to be from PostNord, a bank, or a public system. The text is short and creates a problem that requires immediate action: "Your package is held. Pay 9 DKK in duty here: [link]". The link leads to a fake payment page that harvests card details.

SMS phishing works because people are used to acting quickly on their phones, and because we generally trust SMS more than email.

Voice phishing (vishing)

A person calls claiming to be from IT support, Microsoft, your bank, or a government agency. They tell you that suspicious activity has been detected on your account or computer. The solution requires you to install a program, provide your password, or approve an MFA notification.

Remember: No legitimate IT support, bank, or government agency will ever ask you to disclose your password over the phone.

Seven red flags you should always check

  • The sender address does not match. Look at the domain after the @ sign. support@microsoft-help.dk is not Microsoft. invoices@your-bank-secure.com is not your bank.
  • Urgency and threats. "Your account will be closed in 24 hours," "Pay now to avoid legal consequences." These are manipulation tactics.
  • You are asked to log in via a link. Always go directly to the website instead of clicking. Type the address manually into the browser's address bar.
  • Unexpected attachments. A colleague suddenly sends you a zip file or a Word file you did not ask for? Call and check before you open it.
  • Requests to approve MFA when you did not initiate it yourself. If you receive an approval request on your phone and you are not in the process of logging in, then it is an attacker trying to break in using your password.
  • Unknown links in SMS messages. Go to the sender's official website instead of tapping the link.
  • The language seems slightly off. Even if the spelling is correct, the sentence construction may be unnatural, a sign of machine-translated text.

Remember this rule of thumb: If a message creates a problem that requires immediate action, and the solution involves clicking a link, installing something, or disclosing information, then it is most likely a scam. Stop and verify through another channel.

What do you do if you receive a suspicious message?

  1. Do not click. Do not open links or attachments before you are certain.
  2. Verify the sender's identity through another channel. Call the person or company on a phone number you find yourself, not a number in the email.
  3. Report it to IT. Even if you did not click. Several employees may have received the same email, and IT needs the opportunity to block it.
  4. If you have already clicked: Change your password immediately, contact IT, and explain exactly what happened. The faster you act, the better.

How to train your employees

Technology alone does not solve the phishing problem. The human factor is critical, and it requires ongoing training, not just a single PowerPoint presentation at onboarding.

Simulated phishing tests

The most effective companies regularly send fake phishing emails to their own employees. If someone clicks the link, they are shown an educational message and sent to a short training module. The goal is not to punish, but to educate. Studies show that simulated tests reduce click rates by 60–80% over 12 months.

A clear reporting culture

Employees should know they can and must report suspicious messages, without fear of being blamed for clicking. Shame is the attacker's best ally. Create a simple procedure: one place to send suspicious emails, and a confirmation that IT has received the report.

Concise, concrete examples

Use actual phishing examples from your industry. An accounting employee should see fake invoices. A receptionist should see fake IT support calls. The more recognizable the scenario, the better it sticks.

Summary

Phishing works because it exploits human behavior: busyness, trust, and helpfulness. The best defense is a combination of technical measures (spam filters, MFA, DNS protection) and well-trained employees who pause before clicking. Start by making the procedure clear: what should an employee do when in doubt? That procedure should be second nature.