Phishing is the most common way accounts get stolen. An attacker sends a convincing-looking email, message or website that tricks you into handing over your password, payment details or other sensitive information — or into installing malware. The best defense is knowing what phishing looks like before you click.
What Is Phishing?
Phishing relies on social engineering: manipulating trust and emotion rather than breaking technical defenses. Attackers impersonate banks, delivery companies, government offices, coworkers or tech support. The message usually contains a hook — a problem, a prize, a deadline or a threat — designed to make you act before you think.
The Common Warning Signs
- Unexpected contact. A message you were not expecting, out of the blue.
- Urgency. "Your account will be closed in 24 hours if you do not act now."
- Threats or fear. Claims of suspicious activity, legal action or missed payments.
- Requests for credentials or money. Legitimate organisations rarely ask for login details or gift cards in a message.
- Poor language or layout. Odd grammar, typos or mismatched branding.
- An unknown link or attachment. The payload of most phishing messages.
Check the Sender, Not the Name
The display name is easy to fake. Always click (or hover) to reveal the actual email address.
- Does the domain match the real organisation? "support@paypa1-security.com" is not PayPal.
- Is it a public email like @gmail.com pretending to be your bank?
- Does it contain slight misspellings or extra characters of a known brand?
If you have the slightest doubt, contact the organisation using a phone number or website you already know — not one from the message.
Inspect Links Before You Click
Hover over any link without clicking. Your browser or email client will show where it really points. Ask yourself: does this address match the site it claims to be? Attackers disguise links with clever text and shortened URLs.
Practical Tip
When in doubt, don't click. Type the known website address into your browser yourself, or use the official app.
Beware of Urgency and Fear
Scammers manufacture pressure so you skip your normal caution. Real organisations rarely demand that you act immediately and never over a random email. A legitimate "account problem" can be verified by calling the official number.
Beyond Email: Smishing and Phone Scams
Phishing also arrives by SMS (smishing) and phone calls (vishing). Text messages claiming missed deliveries, "fraud alerts" or one-time codes can be just as dangerous as email. The same rules apply: check the number, ignore the urgency, and verify through official channels. Never hand over a confirmation code to someone who called you.
What to Do If You Are Unsure
- Do not reply, click or download.
- Report it to your email provider using the "Report phishing" option if available.
- If you clicked or entered details, act quickly: change your passwords, enable multi-factor authentication, and contact the real organisation and your bank. Review how strong passwords protect you.
- When in doubt at work, tell your IT support or manager before doing anything.