Skip to content
PURPLEDUEL

What is phishing and how to spot it

Updated · 3 min read

Phishing is a scam in which someone pretends to be a person or company you trust (your bank, a courier, your boss, an online service) to get you to click a link, open an attachment or hand over passwords and personal data yourself. It does not exploit a flaw in your computer: it exploits trust, which is why it remains one of the most common ways into a security incident.

How a phishing attack works

A typical attack has four steps. The attacker writes a believable message (email, text, social media message or phone call), builds a page that imitates the real one, usually with a very similar address, pushes you to act quickly or out of fear ("your account will be locked", "parcel on hold"), and finally collects whatever you type or gets you to install malware.

A worked example

This email is invented for the occasion, but it looks like thousands of real ones:

From: Customer Care <support@secure-bank-check.example>
Subject: URGENT: your account will be suspended within 24 hours

Dear customer,
we detected a suspicious sign-in. To avoid suspension,
confirm your details right now:
https://login.secure-bank-check.example/signin

Even without opening the link there are at least five red flags:

How to defend yourself

What to do if you already clicked

Stay calm, but act fast. If you typed a password, change it on the genuine site and on every other service where you reused it, and turn on two-step verification. If you entered payment details, call your bank and block the card. If you opened an attachment, disconnect the device from the network, run a scan and tell your IT team. The faster you react, the smaller the damage.

Keep reading