Phishing is an impersonation scam that uses messages, calls, or fake websites to steal credentials, payment details, or other sensitive information. A phishing attempt may also deliver malware through an attachment or download. The sender usually pretends to be a bank, delivery company, employer, colleague, or online service.
Common forms of phishing
- Email phishing: a broad campaign sends fake invoices, security alerts, or delivery notices.
- Spear phishing: the message is tailored to a specific person or organization using researched details.
- Smishing and vishing: the same deception arrives by text message or voice call. Read Smishing for text-message examples.
- QR phishing: a QR code hides the destination and opens a fake payment or sign-in page on a phone.
- Consent phishing: a malicious cloud application asks for access to mail, files, or account data.
Warning signs
- The full sender address or domain differs from the organization it claims to represent.
- The message creates urgency, fear, secrecy, or an unexpected reward.
- A link uses a misspelled domain, URL shortener, unrelated hostname, or an encoded QR code.
- The request asks for a password, MFA code, gift card, cryptocurrency, bank transfer, or remote access.
- An unexpected attachment asks you to enable macros, run a script, or bypass a security warning.
Good spelling and an HTTPS padlock do not prove that a message or site is genuine. Modern phishing can copy branding accurately and use a valid TLS certificate.
How to verify a request safely
- Do not use the supplied link, phone number, or attachment.
- Open the service from a saved bookmark or type its known address yourself.
- Contact the person or organization through a separate, trusted channel.
- Inspect the complete domain before entering information, especially on a phone where it may be shortened.
- Report the message with the mail provider's phishing control or to the impersonated organization, then delete it.
If you clicked or responded
- If no information was entered or file opened, close the page and clear any download it started.
- If you entered a password, change it from the real site, revoke active sessions, and enable multi-factor authentication.
- If you approved an MFA prompt or application permission, remove the unknown device or application and contact the account provider.
- If you opened an attachment or ran a file, disconnect the device if suspicious activity begins and perform a full security scan.
- If payment or identity data was exposed, contact the financial institution and monitor the affected accounts immediately.
Phishing is a form of social engineering. Unique passwords, phishing-resistant MFA, current software, and a practiced reporting process limit the damage when a convincing message reaches a user.