Dialogue: the “helpful reply” trap
Avoid turning a suspicious email into a discovery conversation for the attacker.
Suspicious sender ? Impersonated security support Second-wave lure The attacker shifts from “click this link” to “just answer a few questions.” That move catches people who know the first rule but not the deeper principle. Do not let a suspicious sender conduct discovery Google’s guidance is explicit: do not share passwords and do not reply to suspicious requests for personal or financial information. The professional extension is to withhold context, too. A suspicious sender gets zero trust and zero extra context. The follow-up question Turn 1 The sender writes, “For verification, please reply with the username affected and whether you…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in