Skip to main content
Skillrung

Spotting a malicious message: the signs that still hold

A fraudulent message is no longer given away by its mistakes: it is correctly written and quotes accurate details. What betrays it lies in what it asks for — an urgency that nothing justifies, a login, a payment, an unexpected attachment. The channel changes, text message, phone call or code to scan, the mechanism stays the same. The defence never depends on the message: call back on a number you already knew.

  • Written by Skillrung team
  • Review by a subject-matter expert under way
  • Updated on

What is this course about?

Recognise a malicious message even when it is written impeccably, and verify through the one route that settles the matter.

This is a core course: the material taught is the same for everyone, only the examples, the tools mentioned and the people you deal with change with your job. It has 3 sections, of which 1 section is followed by a quiz, and reads in 25-30 min. The legal framework cited is French law.

The most dangerous message looks just like yours

It arrives at the right moment, with the right vocabulary, and quotes an accurate detail about your structure. Nothing jars: not the language, not the layout, not the name on display. What can still be spotted is what it asks you to do, and the speed at which it asks.

Key points

What a malicious message always ends up asking for

Four requests, and any one of them justifies a check.

  • An urgency that nothing justifies, with a short deadline
  • A login, a password or a code received by text message
  • A payment, a transfer or a change of bank details
  • Opening an attachment you were not expecting

What you will be able to do

  • Understand what makes a fraudulent message credible today.
  • Identify the signs of a fraudulent message and verify through another channel.
  • Leave with three habits you can apply to your messages.

The first 4 slides, free

What you read with no account and no card. Here, the generic version; in the player, the examples take the vocabulary of your job.

Try it, before you even create an account

Choose a job: the passage below is rewritten straight away. Nothing is saved, and no extra content opens.

No job selected: the generic version is being shown.

Generic version
It arrives at the right moment, with the right vocabulary, and quotes an accurate detail about your structure. Nothing jars: not the language, not the layout, not the name on display. What can still be spotted is what it asks you to do, and the speed at which it asks.

Real extract from the free slide “The most dangerous message looks just like yours” of this course.

  1. FreeSlide 1 of 13 · Why a malicious message still gets through

    The most dangerous message looks just like yours

    It arrives at the right moment, with the right vocabulary, and quotes an accurate detail about your structure. Nothing jars: not the language, not the layout, not the name on display. What can still be spotted is what it asks you to do, and the speed at which it asks.

  2. FreeSlide 2 of 13 · Why a malicious message still gets through

    What you will be able to do by the end

    • Read the six signs of a malicious message
    • Recognise a fraud by text message, phone call or code to scan
    • Verify through a route the sender does not control
  3. FreeSlide 3 of 13 · Why a malicious message still gets through

    What a malicious message always ends up asking for

    Four requests, and any one of them justifies a check.

    • An urgency that nothing justifies, with a short deadline
    • A login, a password or a code received by text message
    • A payment, a transfer or a change of bank details
    • Opening an attachment you were not expecting
  4. FreeSlide 4 of 13 · Why a malicious message still gets through

    Where do you stand?

    One question to place your reflexes, with no score and no judgement. Answer before you carry on.

    1 short questions, marked immediately, inside the course.

These 4 slides can be read in the player, with no account and no card.

Read the first slide

Programme

3 sections, 13 slides and 4 quizzes in total. Each content section ends with a quiz that checks it has been learned.

  1. IntroductionFree

    Why a malicious message still gets through

    Understand what makes a fraudulent message credible today.

    • 4 slides
  2. SectionSubscribers

    Spotting a malicious message

    Identify the signs of a fraudulent message and verify through another channel.

    • 7 slides
    • Section quiz: 5 questions
  3. RecapSubscribers

    Your action plan

    Leave with three habits you can apply to your messages.

    • 2 slides

9 slides are for subscribers

The first four slides of this course can be read without an account and without a bank card. From the fifth on, the €29.99/month incl. VAT subscription is needed. The Beginner level quiz, though, stays free: it measures your level without asking you for anything.

How your level is measured

  • Beginner
    Questions drawn
    10
    Pass mark
    70 %
    Question bank
    30
    Time limit
    20 min

    Free, no account and no subscription.

  • Intermediate
    Questions drawn
    12
    Pass mark
    75 %
    Question bank
    36
    Time limit
    24 min

    Subscribers only, once the Beginner level is passed.

  • Expert
    Questions drawn
    15
    Pass mark
    80 %
    Question bank
    45
    Time limit
    30 min

    Subscribers only, once the Intermediate level is passed.

The level shown for a course is the highest level you have passed, with your best score and its date. Questions are drawn at random on every attempt. Play the Beginner quiz for this course or read how we measure your level.

Which jobs is it for?

Common core: the examples change with your job, what is taught stays the same. It addresses all 58 jobs in the directory. See courses by job.

Frequently asked questions

Are spelling mistakes no longer enough to spot a fraud?

No, and relying on them has become dangerous. The messages going round today are correctly written and borrow the vocabulary of your job. Looking for the mistake amounts to trusting every impeccable message, which is exactly the effect being sought.

What should I do if I have already clicked on a suspicious link?

Do not keep the information to yourself. If you entered a password, change it immediately on the service concerned and everywhere it was reused, then switch on a second factor. Then tell your manager or your IT provider, even if nothing seems to have happened.

Does this course cover text messages and phone calls too?

Yes. A whole section covers the channels beyond email: the text message announcing a held parcel, the call claiming to be IT support, the code to scan stuck over the official sticker on a terminal.

What can I read without a subscription?

The first four slides of every course are available without an account and without a subscription, as is the Beginner level quiz. From the fifth slide onwards, the €29.99/month incl. VAT subscription is required. Creating a free account unlocks no extra slide: it keeps your progress, your job and your results.

How is my level measured?

By three level quizzes: Beginner (10 questions, 70 % to pass), Intermediate (12 questions, 75 %) and Expert (15 questions, 80 %). The level shown is the highest level passed, with the best score obtained and its date.

Who writes and who reviews this course

  • Skillrung team

    Editorial team of skillrung.com

    The skillrung editorial team writes the courses from the publications of the French and European authorities: ANSSI, CNIL, Cybermalveillance.gouv.fr, Légifrance and EUR-Lex. Every figure is tied to its primary source, dated and verifiable from the course page. The team does not stand in for an expert reviewer: every course intended for publication is reviewed by a named professional of the field concerned, whose name and review date appear on the course page.

Artificial intelligence assisted the drafting. Editorial responsibility for the published text remains human.

Statements with regulatory scope verified on .

Sources

Every figure stated in this course points to a primary source, dated and verifiable.

  1. Rapport d'activité et état de la menace 2025

    Cybermalveillance.gouv.fr, published on

What Skillrung is not

  • Skillrung is not a French training body certified under the Qualiopi scheme.
  • As things stand, our content is not eligible for the French CPF, OPCO, DPC or FAF funding schemes.
  • A Skillrung certificate of completion is not a diploma, not a professional title and not a qualification registered in any national register. It records a result obtained in an unsupervised online assessment, on a given date.
  • Taking a Skillrung course does not make your organisation compliant and does not replace the obligations that fall on your employer or on you.
  • Our content is educational. It is neither legal advice, nor medical advice, nor a security audit.
  • For a self-employed professional or a company, the subscription is a deductible business expense : confirm this with your accountant.

Same topic

The other cybersecurity courses