Spoofing and Phishing Security Guidelines

Spoofing & Phishing Security Guidelines
Applicable To: Visitors, Customers, Partners, Students, Vendors, and Employees of Fortress SECMITS

1. Purpose

Fortress SECMITS is dedicated to safeguarding against spoofing, phishing, and other social engineering attacks. These guidelines outline how we communicate, how to identify legitimate communications, and steps to take if you suspect fraudulent activity. Cybercriminals may impersonate organizations through various channels to steal sensitive information or financial details. Staying vigilant is your best defense.

2. What Are Spoofing and Phishing?

Spoofing
Spoofing involves impersonating a trusted entity to deceive recipients into believing the communication is legitimate. Examples include:

  • Fake email addresses resembling Fortress SECMITS
  • Fraudulent websites mimicking our branding
  • Caller ID spoofing
  • Fake social media profiles
  • Domain impersonation

Phishing
Phishing is a social engineering attack aimed at tricking individuals into:

  • Revealing passwords
  • Sharing banking information
  • Providing OTPs or MFA codes
  • Downloading malware
  • Making unauthorized payments
  • Disclosing confidential information

3. How Fortress SECMITS Communicates

Our official communications are conducted only through authorized channels. We will never ask you to:

  • Share your account password
  • Reveal One-Time Passwords (OTP)
  • Share Multi-Factor Authentication (MFA) codes
  • Provide banking PINs
  • Install remote access software without prior authorization
  • Make payments to personal bank accounts
  • Share sensitive information over unsecured channels

If you receive such requests claiming to be from Fortress SECMITS, treat them as fraudulent.

4. Recognizing Suspicious Communications

Be cautious if you notice:

  • Urgent requests demanding immediate action
  • Threats of account suspension
  • Requests for confidential information
  • Unexpected invoices or payment requests
  • Suspicious attachments
  • Links directing to unfamiliar websites
  • Poor grammar or unusual formatting
  • Sender email addresses that closely resemble, but are not identical to, official domains

Always verify before taking action.

5. Verify Before You Trust

Before responding to any communication:

  • Carefully verify the sender’s email address.
  • Confirm the website URL before entering credentials.
  • Contact Fortress SECMITS using publicly available contact information.
  • Never rely solely on phone numbers or email addresses provided in suspicious messages.
  • When in doubt, contact our support team directly.

6. Website Safety

Always ensure:

  • The website uses HTTPS.
  • The browser displays a secure connection.
  • The domain name is correct.
  • The certificate is valid.

Never enter credentials on websites reached through unsolicited emails or messages.

7. Payment Security

Before making any payment:

  • Verify payment instructions through an independent communication channel.
  • Confirm any changes to bank account details directly with Fortress SECMITS.
  • Be cautious of urgent requests to transfer funds.
  • Never send payments to personal accounts unless officially verified.

8. Protecting Your Account

Users are encouraged to:

  • Use strong, unique passwords.
  • Enable Multi-Factor Authentication whenever available.
  • Keep operating systems and browsers updated.
  • Use reputable antivirus software.
  • Avoid using public Wi-Fi for sensitive transactions.
  • Log out after completing transactions.

9. If You Suspect a Phishing Attempt

If you receive suspicious communications:

  • Do not click any links.
  • Do not download attachments.
  • Do not reply.
  • Do not provide personal or financial information.
  • Take screenshots if possible.
  • Report the incident immediately to Fortress SECMITS.
  • Delete the suspicious message after reporting.

If you have already clicked a suspicious link:

  • Change your passwords immediately.
  • Enable MFA if not already enabled.
  • Scan your device for malware.
  • Contact your bank if financial information was exposed.
  • Notify Fortress SECMITS immediately.

10. How Fortress SECMITS Protects You

We continuously implement security measures including:

  • Secure website encryption (HTTPS)
  • Access controls
  • Identity verification procedures
  • Security monitoring
  • Employee security awareness training
  • Regular security reviews
  • Email authentication technologies (SPF, DKIM, and DMARC) to reduce domain spoofing risks.

While we take extensive precautions, cybersecurity is a shared responsibility.

11. Reporting Security Incidents

If you believe someone is impersonating Fortress SECMITS or attempting to deceive you:

  • Contact us immediately through the official contact information published on our website.
  • Include screenshots, email headers, URLs, or any other relevant evidence to assist our investigation.

Prompt reporting helps us protect our community and respond quickly to potential threats.

12. Disclaimer

Fortress SECMITS cannot be held responsible for losses resulting from interactions with fraudulent third parties impersonating our organization. We encourage all users to independently verify communications before sharing sensitive information or making payments.

13. Updates to These Guidelines

These Spoofing & Phishing Security Guidelines may be updated periodically to address evolving cyber threats, regulatory requirements, and industry best practices. Users are encouraged to review this page regularly to stay informed about the latest security recommendations.

Scroll to top