Security

What Is Phishing and How to Spot It

The three common forms of phishing, the red flags worth memorizing, and how to verify and report it safely.

Onuorah Nnamdi Martins

Jul 25, 2026 · 9 min read

A message designed to trick you

Phishing is a scam message crafted to trick you into revealing a password, clicking a malicious link, downloading malware, or sending money, usually by impersonating someone or something you trust: a bank, a delivery service, a coworker, or a government agency. It is one of the most common ways accounts and devices get compromised, precisely because it targets human judgment rather than a technical weakness in software. Attackers rely on a small set of psychological levers that work regardless of how much technology changes: urgency, authority, fear of loss, and the desire to be helpful. Understanding those levers, rather than memorizing a specific scam wording, is what lets you recognize a phishing attempt you have never seen before.

Key terms

  • Phishing: a fraudulent message impersonating a trusted sender to steal information or money.
  • Smishing: phishing delivered by text message rather than email.
  • Vishing: phishing delivered by a phone call, often impersonating a bank, tech support, or a government agency.
  • Spoofing: disguising a message's sender address or phone number so it appears to come from someone else.
  • Urgency tactic: language designed to make you act quickly without verifying, such as a threatened deadline or account suspension.

The three common forms

Phishing is not limited to suspicious emails anymore. Recognizing all three forms helps you stay alert across every channel:

  1. Email phishing typically imitates a company or service you actually use, asking you to "verify your account," "confirm a payment," or "reset your password" through a link that leads to a fake login page designed to steal your credentials.
  2. Smishing arrives as a text message, often claiming a package delivery issue, a bank alert, or a prize, with a shortened or unfamiliar link attached.
  3. Vishing is a live or recorded phone call, sometimes using a spoofed caller ID that displays a real company or government name, pressuring you to share information or make a payment immediately.

Red flags worth learning by heart

No single signal proves a message is fake, but several together are a strong warning:

  1. Unexpected urgency, such as "act within 24 hours" or "your account will be suspended" language designed to short-circuit careful thinking.
  2. A mismatch between the sender's actual email address or phone number and the organization it claims to represent.
  3. A request to click a link or call a number to "verify" information you did not initiate contact about.
  4. A request for a password, one-time code, or gift card; legitimate organizations do not ask for these through a message.
  5. Generic greetings such as "Dear Customer" combined with specific-sounding threats, or conversely, a message using personal details it should not have.

Modern phishing can be well written and use a real company's logo convincingly, so treat these behavioral red flags as more reliable than spelling and grammar alone.

▶ Watch: How to Recognize a Phishing Scam (open on YouTube)

How to verify a suspicious message safely

  1. Do not click the link or call the number included in the message.
  2. Open the organization's official app, or type its known website address directly into your browser.
  3. Log in normally there and check for genuine account notifications or alerts.
  4. If you're unsure about a claimed call, hang up and call the number printed on your card or a past statement instead.
  5. When in doubt, ask a trusted person to look at the message with you before acting.

Phishing aimed at businesses and job seekers

Two increasingly common variations deserve specific mention. Business email compromise targets employees, often impersonating a manager, vendor, or executive to request an urgent wire transfer or a change to banking details; a quick phone call to a known number before processing any changed payment instruction stops the vast majority of these attempts. Job scam phishing targets job seekers with a fake recruiter offering remote work, then asks for personal information, a fee for "training materials," or a check to deposit before sending equipment money back; a legitimate employer will never ask a candidate to pay for a job or deposit funds on the company's behalf. Both variations rely on the same underlying tactic as consumer phishing: creating urgency and exploiting trust in a role or relationship to bypass normal caution.

What to do if you already clicked something

If you entered a password on a suspicious page, change that password immediately on the real site and enable multi-factor authentication if you have not already. If you downloaded a file, do not open it, and run a reputable security scan instead. If you shared a one-time code, contact the real organization's official support line right away, since some accounts can still be secured quickly after a code is misused. Monitor your accounts and statements for unfamiliar activity over the following weeks.

Reporting phishing helps everyone

Reporting suspicious messages helps providers block similar attacks against other people. Most email providers have a "report phishing" button built into the interface. In the United States, you can forward phishing emails to reportphishing@apwg.org and file a report with the FTC's official scam-reporting page, and the Cybersecurity and Infrastructure Security Agency publishes updated guidance on current phishing trends worth bookmarking.

The mindset that actually protects you

Phishing succeeds by creating urgency and short-circuiting your normal caution. The single most reliable defense is a personal rule: never act on a link, call, or code request from an unexpected message without independently verifying it through a channel you already trust. That one habit blocks the vast majority of phishing attempts, regardless of how convincing the message looks.

A beginner's verification checklist

Good advice about phishing awareness should be practical, specific, and easy to undo when it is wrong for your situation. Before changing a setting, installing an app, or sharing information, identify the official source. An official source is the organization that runs the service, makes the product, or is responsible for the policy—not a sponsored search result, a social-media reply, or an unknown download mirror. Read the page address carefully and use a bookmark or manually typed address for important accounts.

Keep a small record

Write down the date, the device involved, and the exact setting you changed. Take a screenshot of the old setting if it is safe to do so. This gives you a rollback plan and makes it easier to ask qualified support for help. Do not include passwords, recovery codes, full account numbers, or private addresses in screenshots you share.

When a guide asks you to enter credentials, understand the difference between signing in and giving away a secret. Sign in only on the known service page or its official app. A password, one-time code, recovery code, and security-key approval are secrets: support staff, friends, and legitimate companies should not need you to send them in chat. If someone creates urgency—“act in five minutes,” “your account will be deleted,” or “keep this secret”—pause and independently verify the claim.

Make changes one at a time

Changing several things at once makes troubleshooting difficult. Use this simple method:

  1. State the problem in one sentence and note when it happens.
  2. Choose the least invasive official fix first.
  3. Change one item, then test the original problem.
  4. Keep the change only if it helps and does not create a new risk.
  5. Revert it or seek official support if the result is unclear.

For example, if an app suddenly behaves differently, check its update notes and account-security page before installing a “fix” from a video comment. If a device asks for an update, install it from the device's own settings or the maker's site. An update is a vendor-provided software change that repairs defects or adds features. Updates are especially important when they fix security vulnerabilities—mistakes in software that an attacker could exploit.

Use trustworthy help

Prefer a manufacturer's manual, a government consumer-protection agency, a recognized library, or the platform's help center. Check the publication date because menus and policies change. Independent reviews can be useful for experience and comparisons, but they do not override product documentation or local law. Be skeptical of pages that make guaranteed promises, hide who operates them, or demand payment before explaining the issue.

Protect your accounts and devices

Most everyday online safety begins with a few repeatable habits. Use a password manager to create a unique password for every important account. Turn on multi-factor authentication wherever available. Keep automatic updates enabled for your operating system, browser, apps, and router. Back up important files and periodically confirm you can restore one. A backup is a separate copy that lets you recover from loss, damage, or ransomware; copies kept only on the same device do not protect against device failure.

Treat unexpected links, attachments, QR codes, login prompts, and payment requests as things to verify rather than obey. If a message claims to be from a company, open the official app or call the number on a statement you already have. Never solve an urgent digital problem by installing remote-control software for a stranger.

Know when to stop

Stop and contact official support, a trusted local professional, or the relevant authority when a step could expose private data, money, an account, or someone else's equipment. If you believe fraud or a crime is happening, preserve lawful evidence such as dates, screenshots, and receipts, then report it through the proper channel. Do not retaliate, “hack back,” or publish accusations without reliable proof.

The goal is informed, lawful control of your own technology. Small, documented steps are safer and more effective than shortcuts.

Onuorah Nnamdi Martins

Backend-focused software developer building practical products and writing about engineering, APIs, and shipping cleaner systems.

Follow / view profile

Discussion (0)

Log in to join the discussion.

    Keep reading