Phishing is a term that references efforts by a fraudster to obtain personal information such as usernames and passwords. Once obtained, these details are later used to gain access to your systems. 

This article includes: 

Recognising fake emails

Fraudsters will attempt to phish personal details by disguising themselves as a trustworthy entity, such as a a legitimate company. 
 

Signs to look out for when recognising fake emails are: 

Ensure any links are to the destination you expect by hovering your mouse over them

Tell-tale signs that indicate an email isn't genuine include:

  • The email isn't received from a known or expected email address - It may only be a slight variation such as propertyalerts@zoooplla.co.uk or propertyalerts@zoopla.hcmbbus.co.uk
  • Urgent Subject line - Such as "Important: Your account needs urgent attention"
  • Uses generic details 
  • Varying type and sizing of font
  • When hovering the mouse over the links, there is no https at the start of the addresses, and they are generic and fraudulent web addresses that have no relation to Zoopla

If you have received which is cause for concern:

  • Don't click on any links contained in the email
  • Don't reply to the email
  • Don't download any attachments contained in the email
  • If you are unsure, forward the email to help@zoopla.co.uk and we will investigate for you

Spotting an attempt at phishing

  • Check the URL - Is it a secure website
    An 'https' at the start of the URL in your browser and a padlock indicates that your connection is secure and the information you send is kept private. If the browser states 'Not secure' and/or has an unlocked key icon appearing next to the URL, your connection is not private and any personal details you enter or send can be intercepted
  • Unusual contacts - Emails from an unknown source or unexpected email address
    Emails that appear to have been sent by entities known to you could be fraudulent if the sender has attempted to mimic an email address, brand or name.  If the sender seems different from what you had expected, it may be a phishing attempt.  Never open emails which you suspect are fraudulent
  • Urgent subject lines
    Emails with a subject line meant to cause alarm, i.e. 'Security Alert' or 'Your account may be suspended’ can be an attempt to convince you to act straight away in securing your account or changing your login details. Acting on this urgency by clicking links in the email could expose you to fake websites, or keylogging software that can monitor what keys you press and record password entries. Never open emails or click on links which you suspect are fraudulent
  • Requests for personal and private information
    Be wary of any company that emails asking you for usernames, passwords, verification codes or other secure data. This is unusual behaviour and likely an attempt at phishing
  • Web pages or links with odd URLs / addresses
    Malicious websites may look identical to legitimate sites but the underlying address or URL may use a variation in spelling or a different domain, i.e. rather than ending with .co.uk, it might have .co.net
    • When viewing an email, hover over hyperlinks (or buttons) to see the underlying website address
    • If in doubt, don't follow the link, rather, access your accounts in the usual way such as manually typing the address in the search bar or by using Google 
  • Unusual Content or Layout once you've clicked through to a website that seems legitimate 
    • Does the page include unusual functionality e.g. somewhere to enter additional details that have never been requested before. 
    • Is the layout not as expected - this may just be a design change, but if it doesn't look right leave the page and navigate to that page in the way you would normally to check.

 Note

  • If you think you may have entered your details on a scam site, visit the real Zoopla site in your normal way and change your password immediately. This article also contains information on Managing your passwords effectively
  • You can report suspicious and fraudulent emails in the UK to Action Fraud