Phishing is a type of online scam in which criminals pose as a person or organisation you trust — a bank, an employer, a delivery service, a colleague — to trick you into clicking a harmful link, opening a dangerous attachment, or handing over personal information such as passwords or card numbers; you avoid it mainly by slowing down, spotting the warning signs, and verifying through official channels before you act.
Phishing is one of the most common cyber threats precisely because it targets people rather than machines. Instead of breaking through technical defences, attackers exploit trust, curiosity, and urgency. The good news, as U.S. government resources emphasise, is that a few simple habits stop the great majority of attempts. This guide explains how phishing works and how to protect yourself.
How does phishing work?
A phishing attempt usually arrives as a message designed to look legitimate. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), phishing messages commonly come by email, text, social-media direct message, or phone call, and are crafted to appear to come from a trusted person or organisation. The message tries to provoke a quick reaction — clicking a link that leads to a fake login page, opening an attachment that installs malicious software, or replying with sensitive details.
The core trick is impersonation plus pressure. A convincing logo, a familiar sender name, and a plausible reason (“your account is on hold,” “confirm your payment”) lower your guard, while urgency pushes you to act before you think. Some campaigns are mass-produced and generic; others, known as spear phishing, are tailored to a specific person using details gathered in advance. The rise of automated tools has made polished, personalised scams easier to produce, a trend connected to broader shifts we cover in what generative AI can and cannot do.
What are the warning signs?
Both CISA and the U.S. Federal Trade Commission (FTC) publish consumer guidance on recognising phishing. Common red flags include:
- Urgent or emotional language — messages claiming dire consequences if you do not respond immediately.
- Requests for personal or financial information — legitimate organisations generally will not email or text you a link asking you to update payment details.
- Unexpected or strange requests — something you did not ask for or would not normally receive.
- Generic greetings — “Dear customer” rather than your name, or claims that your account has a billing problem.
- Suspicious links or sender addresses — addresses and web links that look slightly off or do not match the real organisation.
CISA sums up its advice memorably as three steps: Recognise, Resist, Delete. Recognise the signs, resist the urge to act quickly, and delete the message.
Why does phishing keep working?
Phishing endures because it targets human psychology rather than software. Attackers lean on instincts that usually serve us well — the desire to be helpful, to respond promptly to authority, and to resolve a problem before it worsens. A message that appears to come from a manager, a bank, or a government office borrows that authority, and a deadline manufactures pressure that discourages careful checking. Attackers also send messages in huge volumes, so even a very low success rate can be worthwhile for them. Recognising that these are deliberate manipulation techniques, not genuine emergencies, is itself a strong defence: the moment a message tries to rush you, that is the cue to slow down.
How can you avoid falling for phishing?
Prevention is mostly about habits rather than technical skill. The table below groups practical defences.
| Habit | What to do | Why it helps |
|---|---|---|
| Verify independently | Contact the organisation using a number or website you already trust, not one in the message | Confirms whether a request is genuine |
| Do not click in haste | Hover to inspect links, and avoid unexpected attachments | Fake pages and malware rely on quick clicks |
| Use strong, unique passwords | Different password per account, ideally via a password manager | Limits damage if one account is exposed |
| Turn on two-factor authentication | Add a second login step where available | A stolen password alone is not enough |
| Keep software updated | Install updates for devices and apps | Closes security gaps attackers exploit |
Enabling two-factor authentication is one of the strongest safeguards, since it means a captured password does not immediately open your account. Because email is often the recovery route for everything else, protect it first. For more on the wider security picture, see our internet coverage and broader technology reporting.
Is phishing only sent by email?
No. The same tactic appears across channels. Phishing by text message is sometimes called smishing; phishing by phone call is known as vishing; and attackers also use social-media direct messages and messaging apps. Whatever the medium, the pattern is the same — a trusted-looking source, a pressing request, and a push to act fast — so the same caution and verification habits apply everywhere.
What should you do if you are targeted?
If a message looks like phishing, do not click links, open attachments, or reply. The FTC advises checking directly with the organisation through a contact method you know is real. You can report the message — many email and messaging services have a built-in reporting option, and CISA encourages reporting phishing — and then delete it.
If you think you already clicked a link or shared information, act quickly. Change the password on any affected account and switch on two-factor authentication, watch closely for unusual activity, and if financial details were involved, contact your bank or card provider promptly. The FTC’s consumer pages outline recovery steps depending on exactly what was exposed. Reporting also helps others, since it feeds the data that authorities and providers use to shut scams down.
Frequently asked questions
What is the simplest way to spot a phishing message?
Watch for urgency, unexpected requests, and pressure to act fast, especially messages demanding personal or financial details or warning of dire consequences. The U.S. Cybersecurity and Infrastructure Security Agency highlights urgent or emotionally appealing language and strange requests as key warning signs. When in doubt, slow down and verify through an official channel.
What should I do if I think I received a phishing message?
Do not click links, open attachments, or reply. The FTC advises checking with the organisation directly using a contact method you know is genuine, not one supplied in the message. You can report phishing emails and delete them, and many providers offer a built-in reporting option.
What happens if I already clicked a phishing link or shared details?
Act quickly. Change the password for any affected account and enable two-factor authentication, watch for unusual activity, and if financial information was involved, contact your bank or card provider. Official resources from the FTC explain recovery steps depending on what was shared.
Are phishing attacks only sent by email?
No. Phishing also arrives by text message, sometimes called smishing, by phone call, known as vishing, and through direct messages on social media. The tactic is the same across channels: impersonate a trusted source and pressure you into acting. The same caution applies everywhere.
Can spam filters catch every phishing attempt?
No. Filters block a large share of malicious messages, but some still get through, and attackers constantly adjust their methods to evade detection. Technology helps, but your own caution, verification habits, and reporting remain essential layers of defence.




