Phishing is responsible for more successful account compromises than almost any other attack technique — and it works because it exploits human instincts rather than technical vulnerabilities. You don’t need a weak password or an unpatched system to fall victim. You just need to click a link at the wrong moment. Avoiding phishing scams means developing pattern recognition for the signals that reveal deceptive communications, and building habits that reduce exposure even when those signals are subtle. For the bigger picture, our Complete Guide to Online Security and Privacy pulls everything together.
Every phishing attempt has one of three goals: stealing credentials (getting you to log into a fake site), delivering malware (getting you to open an attachment or download a file), or social engineering you into an action (transferring money, sharing sensitive data, granting account access). Identifying the goal helps recognise the scam even when the message appears legitimate.
The patterns that reveal phishing — recognise them before clicking
Urgency is the most universal signal. “Your account will be suspended in 24 hours.” “Unusual activity detected — verify immediately.” “Package awaiting delivery — confirm today.” Urgency is engineered to bypass critical thinking by creating pressure to act before pausing. When a message creates pressure to act immediately, that pressure is itself the signal to slow down rather than speed up. Legitimate services almost never require instant action to prevent irreversible consequences.
Sender identity mismatch reveals phishing at the first point of inspection. Phishing emails claim to be from trusted organisations but the actual sending email address doesn’t match. Check the full “From” address, not just the display name: “PayPal Support” as the display name with “[email protected]” as the actual address reveals the mismatch immediately. In Gmail: hover or tap the sender name to see the full address. In Outlook: click the “From” field to expand it. Make this check automatic — every email claiming to require action should have its sending domain verified before any link is clicked.
Lookalike domains in URLs are the companion to display name spoofing. “paypa1.com” (with the number 1 replacing the letter l), “amazon-security.net” (adding a word before the TLD), or “amazon.customer-support.com” (where the real domain is customer-support.com, not amazon.com). The real domain is always the part immediately before the TLD (.com, .org, .net).
What to do when you receive a suspicious message
- Stop before clicking anything. The fastest defence is not clicking links in messages you didn’t expect. Even if the message looks legitimate, navigate to the service’s official website directly rather than through the provided link.
- Check the sending address — the full address, not the display name. Expand the “From” field and compare the actual domain to the legitimate organisation’s known domain. A mismatch is definitive.
- Hover over links before clicking. On desktop: hover the mouse over any link and check the actual URL in the status bar at the bottom of the browser or email client. On mobile: long-press the link to see a preview. The URL should match the claimed organisation’s actual domain.
- Verify through a separate channel. If a message claims to be from your bank about suspicious activity, call the bank’s official number (printed on your card, not from the message) or log into your account through the official app or a manually-typed URL. Never verify legitimacy by responding to the suspicious message itself.
- Check the URL when a page loads. If you click a link, look at the address bar before entering any credentials. The URL should show the legitimate organisation’s actual domain — not a lookalike with transposed letters, added words, or unfamiliar TLDs. Our guide on checking website safety covers URL inspection in detail.
- Don’t open unexpected attachments. PDFs, Word documents, ZIP files, and HTML attachments are all used to deliver malware. An attachment you didn’t expect from a sender you didn’t invite to send files is a risk regardless of file type. Confirm via a separate channel before opening anything unexpected.
- Report and delete. Report phishing to your email provider (Gmail: three dots → Report phishing; Outlook: flag icon → Report phishing) and delete. Don’t forward it to others — forwarded phishing emails create additional risk if the recipient interacts with the content.
Step 4 — verification through a separate channel — is the most important step for any message claiming to require urgent financial or account action. The cognitive shortcut phishing exploits is the assumption that responding through the channel provided in the message is the correct action. Going to the genuine source independently — the official app, the official phone number, the official website typed directly — eliminates the risk regardless of how convincing the message was.
Phishing across every channel
SMS phishing (smishing) is particularly effective because mobile users are less likely to hover over links, messages appear in the same stream as legitimate delivery notifications and bank alerts, and shortened URLs in SMS messages hide the actual destination. Treat every text message link from an unknown sender as a risk. Navigate directly to any claimed service’s official app or website rather than clicking the link. High-volume SMS phishing campaigns in 2026: delivery scam texts claiming a package requires a customs fee, government-impersonation texts claiming tax debts, and bank fraud alert texts with a link to “verify.”
Voice phishing (vishing) uses phone calls from numbers that appear legitimate through caller ID spoofing. An attacker claiming to be from your bank or the IRS requesting account verification information is a vishing attempt. Never provide personal information, PINs, or one-time codes to an inbound caller regardless of how convincingly they identify themselves. Hang up and call back on the official number. One-time authentication codes are specifically requested in real-time by live attackers who are simultaneously attempting to log into your account — sharing them is the most acute form of phishing susceptibility.
Social media direct messages claiming you’ve won a prize, need to verify an account, or have been tagged in something are phishing vectors that benefit from the platform’s trusted appearance. Apply the same verification habits as email — check the actual sender account, don’t click unexpected links, navigate directly to the claimed service rather than following the link.
Technical tools that help
Your password manager plays a passive but critical phishing detection role: it won’t autofill credentials on phishing sites because the domain doesn’t match the saved entry. This makes the autofill a real-time phishing detector — if the autofill doesn’t trigger on a site claiming to be your bank, the domain isn’t the bank’s actual domain. Never manually type credentials after autofill fails to trigger on a login page you reached through a link.
Browser-based Safe Browsing (Chrome’s Enhanced protection, Firefox’s phishing protection) provides a real-time warning when you navigate to a known phishing URL — an important backstop for cases where a phishing link was clicked before the domain was checked. Enable Enhanced protection in Chrome: Settings → Privacy and security → Security → Enhanced protection.
Hardware security keys (FIDO2: YubiKey, Google Titan Key) provide the strongest technical defence for high-value accounts. A FIDO2 key cryptographically verifies the site’s domain before completing authentication — it physically cannot be used on a phishing site because the domain verification fails even if the user enters their credentials on the fake page. For email, financial, and corporate accounts, hardware keys are the only authentication method that eliminates credential phishing as an attack vector entirely.
Our guides on using a password manager and setting up two-factor authentication cover the complementary account security tools that work alongside phishing prevention habits. For phishing volume statistics and the most prevalent current campaigns, the Anti-Phishing Working Group’s quarterly reports provide current data on which organisations are most frequently impersonated and which attack types are growing.
Phishing at work — the organisational dimension
Workplace phishing often targets different goals from personal phishing. Business email compromise (BEC) — where attackers impersonate executives or vendors to authorise fraudulent wire transfers or redirect payroll deposits — is the highest-value category and doesn’t require any link clicking or malware. A convincing email from “the CEO” to accounts payable requesting an urgent wire transfer succeeds through authority and urgency alone.
Organisations avoid this at the process level by establishing verification protocols independent of email: a policy that all wire transfers or payment detail changes above a threshold require phone verification with a known contact, using a previously-established number rather than one provided in the requesting email. This out-of-band verification protocol specifically addresses BEC attacks that bypass all technical controls by targeting the human process.
Security awareness training with simulated phishing exercises provides the practical experience of recognising phishing signals under realistic conditions. Employees who fail simulated phishing tests receive immediate training without the consequence of a real compromise. Organisations running regular phishing simulations see significantly lower click-through rates on real phishing campaigns than those relying on annual training alone.
AI-personalised phishing — the 2026 evolution
Traditional phishing sends the same message to thousands of recipients. Spear-phishing tailors the message to a specific target using their name, employer, recent activity, or relationships — information scraped from LinkedIn, social media, and breach databases. AI tools have made personalised spear-phishing dramatically cheaper to produce at scale, reducing the distinguishing value of personalised detail as a trust signal.
To avoid phishing that includes your name, employer, or other personal details: treat messages with personal information as requiring the same verification as generic ones. Personalisation does not confer legitimacy. The urgency signal, the unusual request, and the out-of-band verification habit are more reliable indicators than whether the message contains your correct name and job title.
Reducing the public information available for spear-phishing profiling is a complementary defence — restricting social media profiles, opting out of data brokers, and limiting what personal information is publicly associated with your work email address reduces the material available to attackers crafting targeted messages. The connection between data broker opt-outs and phishing resistance is underappreciated: a personalised phishing email requires personal data to personalise.
Phishing recognition quiz — common scenarios
Testing pattern recognition with realistic scenarios:
| Scenario | Phishing indicator | Correct action |
| Email from “Amazon Customer Support” with sending address [email protected] saying your account will be suspended | Domain mismatch + urgency. Real domain would be amazon.com | Don’t click. Navigate directly to amazon.com to check account status. |
| Text from unknown number with a link claiming your DHL package needs custom clearance payment | Unsolicited SMS link. Real delivery companies email with tracking numbers, not text links to payment pages. | Don’t click. Go to the carrier’s official app and enter your tracking number manually. |
| Phone call from “Bank Fraud Department” who knows your full name and last 4 card digits, asking for your full card number to “verify your identity” | Vishing. Legitimate banks never ask for full card numbers inbound. | Hang up. Call the number on the back of your card. |
| Email from your “CEO” asking you to urgently purchase gift cards and email the codes | BEC + urgency + unusual request. CEOs don’t email gift card requests. | Call the CEO on a known number to verify before doing anything. |
| LinkedIn message from a “recruiter” with a Word attachment called “Job Description.docx” | Unexpected attachment from unknown sender. Word documents can contain macros that execute malware. | Don’t open. Request a PDF link to an official company page instead. |
If you’ve already clicked — what to do now
If you clicked a phishing link and then realised it was suspicious:
- Did you enter credentials? If yes: change the password on that account immediately from a different device or browser. Enable 2FA if it wasn’t already active. Check login history for unauthorised access.
- Did you enter payment details? Call your bank or card issuer immediately. Dispute any fraudulent charges. Request a new card number.
- Did you open an attachment? If yes: disconnect from the internet. Run a full scan with Malwarebytes and Windows Defender. If the device is at work, report to IT immediately — malware from a phishing attachment can spread to networked systems.
- Did you only click the link without entering anything? Close the tab. Run a browser safety check. Monitor the relevant account for suspicious activity over the next 24-48 hours. Many phishing sites attempt to exploit browser vulnerabilities on page load, so run a malware scan regardless.
Reporting the phishing to the organisation being impersonated helps them take action: most major companies and banks have dedicated email addresses for phishing reports (e.g., [email protected], [email protected]). The Anti-Phishing Working Group accepts reports at [email protected], which aggregates data for law enforcement and security researchers.
Phishing succeeds because it’s optimised to exploit the moment of inattention rather than sustained vulnerability. Building the reflex of a three-second pause — checking the sender domain and hovering over links before clicking — catches the majority of phishing attempts that would otherwise succeed. The habit costs seconds per suspicious message; the protection it provides is against account compromises that can take hours or days to resolve. Our guide on Data Loss Prevention covers an adjacent issue.







