Site icon

What Is Phishing, and How Do You Spot It?

A glowing blue email envelope icon caught on a metallic fishing hook against a dark circuit-board background

You get an urgent email. Your bank account has a problem, it says, and you need to confirm your details right now or lose access. There is a link, and a sense of panic. This is phishing, the single most common trick criminals use to steal money and passwords online. The messages can look convincing, but almost all of them share a handful of warning signs. Once you know what to look for, they become much easier to catch.

Phishing sits behind a huge share of online fraud, which is why learning to recognize it is one of the most useful security skills you can pick up. Here is a clear guide to what phishing is and how to protect yourself.

The short version

Phishing is a scam in which an attacker pretends to be a trustworthy person or company to trick you into handing over sensitive information or clicking a harmful link. It usually arrives by email or text, uses urgency or fear to rush you, and points to a fake login page or malicious file. You avoid it by slowing down, checking the sender and links carefully, and never entering personal details in response to an unexpected message.

What phishing is

Phishing is a form of social engineering, which means it targets people rather than machines. According to the Cybersecurity and Infrastructure Security Agency, phishing is an attack in which a threat actor poses as a trustworthy colleague, acquaintance, or organization to lure a victim into providing sensitive information or network access.

The name is a play on fishing, and the comparison is apt. The attacker casts out bait, usually a message designed to look legitimate, and waits for someone to bite. The goal is almost always to get you to reveal something valuable, such as a password, a credit card number, or a login code, or to click something that installs malicious software. Because it exploits human trust rather than a technical flaw, phishing works against even well-secured systems. For more on staying safe online, browse SciExaminer’s Technology section.

How a phishing attack works

Most phishing follows a familiar script. The attacker sends a message that appears to come from a company or person you trust, such as a bank, a delivery service, or an online store. The Federal Trade Commission notes that these messages often tell a story to trick you into clicking a link or opening an attachment, claiming there is a problem with your account or an overdue invoice that needs immediate attention.

The key ingredient is pressure. The FTC points out that scammers want you to act before you have time to think, so they lean on urgency and fear. Click the link, and you usually land on a fake page that looks like a real login screen. Whatever you type there, including your username and password, goes straight to the attacker. In other cases the attachment carries malware that quietly infects your device. The whole design is built to short-circuit your caution in the moment.

Common types of phishing

Phishing is not always a mass email blasted to millions of people. Some of the most damaging attacks are narrow and carefully aimed. As Cloudflare explains, spear phishing is a targeted attack that uses personalized details, such as your name, employer, or real facts about your life, to make the message far more convincing than a generic scam.

A step further is whaling, a form of spear phishing that goes after high-level executives who have significant authority or access to money and systems. There is also smishing, which is phishing carried out through SMS text messages rather than email. CISA warns that these texts can contain links that automatically open a browser or dial a number when tapped. The channel changes, but the aim stays the same: to trick a specific target into a costly mistake.

How to spot a phishing message

The good news is that phishing messages tend to give themselves away, and a few quick checks catch most of them. CISA highlights several classic red flags. Look closely at the sender’s address, since criminals often use one that resembles a real company but alters or omits a few characters. Be wary of generic greetings like “Dear Valued Customer” instead of your name, which suggest a mass mailing.

Links deserve special attention. CISA advises hovering your cursor over any link without clicking; if the address that appears does not match the text or the company it claims to be from, the link may be spoofed. Beyond those, the FTC flags unexpected requests to click or open something, urgent or threatening language, and any message pushing you to act immediately. Genuine organizations rarely ask you to confirm passwords or account numbers by email or text.

What to do, and what not to do

When a suspicious message arrives, the safest move is to slow down. Do not click links, open attachments, or reply with personal details. If the message claims to be from a company you use, the FTC recommends contacting that company directly through a phone number or website you know is real, never the contact details supplied in the message itself.

It also helps to build a safety net in advance. Turning on multi-factor authentication means that even if a scammer captures your password, they still cannot log in without a second code. If you want to understand that defense in detail, see our guide to two-factor authentication. Keeping your software updated and reporting phishing attempts to your email provider or the relevant authority rounds out a simple, effective routine that dramatically lowers your risk.

What to know

Frequently asked questions

What is phishing in simple terms?

Phishing is an online scam in which someone pretends to be a trustworthy company or person to trick you into giving up sensitive information or clicking a harmful link. It usually comes as an email or text that creates a sense of urgency and points you to a fake website designed to steal your details.

How can I tell if an email is a phishing attempt?

Watch for a sender address that only resembles a real company, a generic greeting instead of your name, and links that do not match their supposed destination when you hover over them. Unexpected requests, urgent or threatening language, and pressure to act immediately are all strong warning signs of phishing.

What should I do if I clicked a phishing link?

Do not enter any information on the page it opened. Change the password for any account you may have exposed, turn on multi-factor authentication, and watch your accounts for unusual activity. If you entered financial details, contact your bank right away and report the scam to the relevant authority in your country.

What is the difference between phishing and spear phishing?

Ordinary phishing is sent broadly to many people using generic messages. Spear phishing is targeted, using personal details about a specific victim, such as their name, job, or company, to make the message far more believable. Spear phishing takes more effort but has a much higher success rate.

Can phishing happen through text messages?

Yes. Phishing sent by SMS text message is called smishing. These texts can contain links that open a browser or dial a phone number when tapped, and they use the same tricks as email phishing. Treat unexpected texts asking you to click a link or share details with the same caution.

What this means

Phishing works because it targets people, not technology, which is exactly why awareness is such a strong defense. The scammers rely on you being busy, distracted, or scared enough to act without checking. The habit that defeats them is simple: pause before you click, look at who really sent the message, and verify anything urgent through a channel you trust. Add multi-factor authentication and a healthy skepticism of unexpected requests, and the vast majority of these attacks fall apart. For more practical guides to protecting yourself online, the Technology section is a good place to keep reading.

Exit mobile version