What Is Phishing? How to Spot and Stop It
Phishing is a type of cyber attack where a scammer pretends to be someone you trust, a bank, a coworker, a delivery service, to trick you into handing over information or clicking a malicious link. It is the single most common way that data breaches and account takeovers begin.
The good news: once you know the warning signs, most phishing attempts are easy to spot. This guide covers how phishing works, the different forms it takes, and exactly what to look for.
How phishing works
A phishing attack usually arrives as a message that creates a sense of urgency or fear, "Your account has been suspended," "Confirm this payment," "Your package could not be delivered." The goal is to make you act before you think.
The message directs you to a fake login page or an attachment. If you enter your credentials or open the file, the attacker captures your password, installs malware, or tricks you into approving a fraudulent transaction.
Common types of phishing
Phishing is not limited to email. The same trick shows up across every channel you use:
- Email phishing: mass emails impersonating a brand or service.
- Spear phishing: a targeted message tailored to you or your role, often using details from social media.
- Smishing: phishing over SMS or text messages, often about deliveries or bank alerts.
- Vishing: phishing by phone call, where a "support agent" asks for codes or remote access.
- Business email compromise (BEC): an attacker impersonates an executive or vendor to request a wire transfer or gift cards.
How to spot a phishing attempt
Before you click or reply, check for these red flags:
- A sense of urgency or a threat ("act now or your account closes").
- A sender address that does not match the real organization (hover to check).
- Generic greetings like "Dear Customer" instead of your name.
- Links that point to a look-alike or unfamiliar domain.
- Requests for passwords, codes, or payment that would never come by email.
- Spelling and grammar mistakes, or a tone that feels slightly off.
How to protect yourself
A few habits stop the vast majority of phishing:
- Never enter your password after clicking a link in a message, navigate to the site yourself.
- Turn on multi-factor authentication (MFA) so a stolen password is not enough.
- Verify unexpected money or data requests through a second channel (call the person).
- Report suspicious messages to your IT or security team.
- Keep your devices and browser updated.
How it plays out in the real world
Based on real, widely reported incident patterns; names and details are illustrative.
The payroll update that stole a paycheck
Employees at a mid-size company received an email from 'HR Operations': the payroll provider was upgrading, and everyone had to re-confirm their direct-deposit details before Friday to avoid a delayed paycheck. The link opened a login page that looked exactly like the real HR portal, same logo, same colors.
A handful of employees signed in. Their credentials went straight to the attacker, who logged into the real portal and quietly changed their direct-deposit account numbers. Nobody noticed until payday, when the money landed in accounts the attackers controlled.
- A perfect-looking page proves nothing. The fake portal was pixel-identical because attackers simply copy the real page. Only the address bar tells the truth. Type the portal address yourself or use a saved bookmark.
- Deadlines around money are bait. "Before Friday or your paycheck is delayed" is engineered panic. Real HR changes come with notice and never threaten your salary over a click.
- Credentials plus a self-service portal equals cash. Anything that pays you, payroll, expenses, benefits, is a direct target. Protect those logins with MFA and never reach them through emailed links.
Test yourself
Test your phishing instincts with a free, custom quiz.
Frequently asked questions
What is the most common sign of phishing?
Urgency. Phishing messages pressure you to act immediately, before you have time to check whether they are genuine. Any message that rushes you to log in, pay, or share a code deserves a second look.
What should I do if I clicked a phishing link?
Do not enter any information. Close the page, change the password for any account you may have exposed, enable MFA, and report it to your IT or security team. If you entered card details, contact your bank.
Is phishing only email?
No. Phishing also happens by text (smishing), phone (vishing), social media, and messaging apps. The core trick, impersonating someone you trust to create urgency, is the same everywhere.