Assurex Scam Ya Sach?
At work

Work phishing emails: shared files, payroll and passwords

Before you click, read the sender's domain. Outside domains asking you to sign in are the most common attack at work.

Test yourself: how many would you spot?

How it works

  1. An email copies a trusted tool: file sharing, HR, IT or a courier.
  2. A link, QR code or .html file opens a fake login page.
  3. Your password, and sometimes MFA code, goes to the attacker.

Red flags

  • Outside or lookalike domains ('m1crosoft', 'yourcompany-support.net')
  • Tempting files like salary sheets, or 'act today' deadlines
  • QR codes and .html attachments

Stay safe

  • Open shared files from your own drive or app
  • Make HR and payroll changes only in the official portal
  • Use the report-phishing button or tell IT

Already happened? Act fast

Questions

Why do attackers use QR codes?

Email filters often can't read QR codes, and phones have fewer protections. Treat QR codes in emails with suspicion.

Related scams