What is phishing and how to spot it
Phishing is a scam in which someone pretends to be a person or company you trust (your bank, a courier, your boss, an online service) to get you to click a link, open an attachment or hand over passwords and personal data yourself. It does not exploit a flaw in your computer: it exploits trust, which is why it remains one of the most common ways into a security incident.
How a phishing attack works
A typical attack has four steps. The attacker writes a believable message (email, text, social media message or phone call), builds a page that imitates the real one, usually with a very similar address, pushes you to act quickly or out of fear ("your account will be locked", "parcel on hold"), and finally collects whatever you type or gets you to install malware.
- Mass phishing: the same generic message sent to thousands of people, such as a fake courier or fake bank.
- Spear phishing: a message built around one person, with real details taken from social media or the company website (a colleague's name, a current project).
- CEO fraud: a fake message from an executive asking a colleague for an urgent transfer or confidential data.
- Smishing and vishing: the same trick over text message or phone call.
A worked example
This email is invented for the occasion, but it looks like thousands of real ones:
From: Customer Care <support@secure-bank-check.example>
Subject: URGENT: your account will be suspended within 24 hours
Dear customer,
we detected a suspicious sign-in. To avoid suspension,
confirm your details right now:
https://login.secure-bank-check.example/signin
Even without opening the link there are at least five red flags:
- Urgency and threat: "within 24 hours", "suspended". Whoever wants to trick you takes away your time to think.
- Inconsistent sender: the domain
secure-bank-check.exampleis not your bank's, and the display name ("Customer Care") can be anything. - Generic greeting: "Dear customer" instead of your name.
- The link leads somewhere else: hover over the link (or press and hold on a phone) without clicking and read the real address. What matters is the domain, the part right before the first slash.
- A request for credentials: a serious bank never asks you to confirm passwords or codes by email.
How to defend yourself
- Do not click, go there yourself. For any important notice, type the address or use the official app.
- Use multi-factor authentication. Even if someone learns your password, it is not enough. Passkeys and hardware keys are phishing-resistant: see the guide to MFA and passkeys.
- Use a password manager. It only fills in credentials on the right domain; if it offers nothing on a page that looks like your bank, that is a warning sign.
- Keep devices updated and protected. Antivirus and EDR limit the damage of an attachment opened by mistake.
- Train and simulate. At work, controlled phishing exercises teach people to recognise messages and report them without embarrassment.
- Report it. Use the "report phishing" button in your mail client or tell your security team: one report can protect all your colleagues.
What to do if you already clicked
Stay calm, but act fast. If you typed a password, change it on the genuine site and on every other service where you reused it, and turn on two-step verification. If you entered payment details, call your bank and block the card. If you opened an attachment, disconnect the device from the network, run a scan and tell your IT team. The faster you react, the smaller the damage.