Bitrix24 Helpdesk

Phishing: How to protect your company

Phishing is a type of fraud aimed at obtaining confidential data from users or companies.

Regular phishing targets a wide audience. Fraudsters send spam to steal passwords, bank card details, or gain access to personal accounts.

Corporate phishing targets employees with access to critical data. The goal of this type of phishing is to gain access to internal systems, or disrupt infrastructure operations.


How fraudsters deceive

Research the company. Fraudsters start by examining social media, the company structure, and communication style.

Forge emails from executives or colleagues using cloned domains.

Send messages pretending to be real employees, complete with profile photos. They may also send voice messages generated by artificial intelligence.

Send malicious files. For instance, asking to update a program.

Create fake login pages to steal passwords.


How to protect against phishing

We have compiled several tips to help protect yourself and your company from fraudsters.

Don’t click on links immediately and check the sender’s address. Hover over the name in the email or the link to see the actual email and domain.

Avoid opening suspicious attachments. For example, files asking to update a program or enable macros. Files in exe, js, scr formats, or password-protected zip files may be malicious.

Don’t rush to follow instructions in emails marked "Urgent". Verify any suspicious requests for money transfers or data by calling or messaging a colleague in your work chat.

Keep your software updated. Updates fix vulnerabilities that fraudsters exploit.

Set up an email filtering system. These systems use special algorithms to check incoming emails, filter out suspicious ones, and send them to spam.

Develop and implement an information security policy. Your company should have clear rules on checking emails, using the internet and smartphones, and responding to hacking attempts.

Use antivirus software and two-step authentication.

Enable two-step authentication for Bitrix24 login

Train employees to recognize phishing. Organize lectures and webinars on cyber fraud and conduct tests to assess their knowledge.

Carefully check the domain of the site where you want to log in. For example, the Bitrix24 cloud address only contains the bitrix24 domain, not bltrix, bitrix25, or others.

Report suspicious emails or websites to your company’s security department. Stay vigilant and always double-check suspicious messages.


    In brief

  • Phishing is a type of fraud aimed at obtaining confidential data from users or companies.

  • Regular phishing targets a wide audience. Fraudsters send spam to steal passwords, bank card details, or gain access to personal accounts.

  • Corporate phishing targets employees with access to critical data. The goal is to gain access to systems, or disrupt infrastructure operations.

  • To protect your company’s data from fraudsters, follow these rules: avoid opening suspicious emails and attachments, verify sender addresses, update software, use antivirus software and two-step authentication, and develop and implement an information security policy.
Was this information helpful?
Integration specialist assistance
That's not what I'm looking for
Complicated and incomprehensible text
The information is outdated
It's too short. I need more information
I don't like the way this tool works
Go to Bitrix24
Don't have an account? Create for free
Related articles
Create and configure Open Channels Inventory access permissions Place CRM form on Bitrix24 site Workflow autorun Bitrix24 Booking: put a client on the waiting list Inventory management documents in deals Log in to Bitrix24 account via browser Bitrix24: what's new in April 2025 Set login and password when using social network login