Phishing is a scam in which attackers pose as a trusted person or organization to trick you into handing over passwords, money, or personal information.
The name plays on fishing: criminals cast out bait, usually a convincing message, and wait for someone to take it. It is one of the most common ways online accounts are compromised, and the tactics keep evolving.
How phishing works
A typical phishing attempt impersonates something you trust, such as your bank, an employer, a delivery company, or a well-known service like Gmail or Microsoft. The message creates a reason to act quickly and includes a link to a fake website or an attachment. The fake site looks like the real login page, so when you type your username and password, they go straight to the attacker. In other cases the message asks you to reply with sensitive details, pay a fake invoice, or install malicious software.
The core trick is psychological: attackers rely on urgency, fear, curiosity, or authority to get you to act before you think. A message claiming your account will be closed in 24 hours is designed to make you skip your usual caution.
The main types of phishing
Phishing comes in several forms depending on the channel and target. The table below outlines the most common ones.
| Type | Channel | Description |
|---|---|---|
| Email phishing | Mass fake emails impersonating a brand or service | |
| Spear phishing | Targeted at a specific person using personal details | |
| Smishing | SMS text | Fake texts with malicious links, often fake deliveries |
| Vishing | Phone call | Scam calls posing as banks, support, or agencies |
| Clone phishing | A copy of a real message with links swapped for fakes |
How to spot a phishing message
According to CISA and the FTC, several red flags show up repeatedly:
- Urgency or threats: claims that your account will be suspended or you owe money immediately.
- Unexpected links or attachments: especially from senders you did not contact first.
- Requests for credentials or payment: real companies do not ask for your password by email or text.
- Mismatched sender details: a display name that does not match the actual email address or domain.
- Generic greetings: vague openings like Dear Customer instead of your name.
Be aware that grammar mistakes are no longer reliable; many modern phishing messages are well written and visually convincing. Hovering over a link to preview the real destination, without clicking, can reveal a suspicious address.
What to do if you receive one
If a message looks suspicious, do not click links, open attachments, or reply. Instead, verify the request by contacting the organization through a phone number or website you already trust, not the contact details in the message. Delete the message, and report it: in the United States you can forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org and report scams to the FTC at ReportFraud.ftc.gov. Suspicious texts can be forwarded to 7726 (SPAM).
Why phishing keeps working
Phishing persists because it targets people rather than software. A well-patched device with strong antivirus can still be compromised if the user is convinced to type their password into a fake page or approve a login they did not start. Attackers also scale their efforts cheaply, sending millions of messages so that even a tiny success rate is profitable. Increasingly they use current events, real company branding, and personal details harvested from data breaches or social media to make messages feel legitimate. Some campaigns even set up fake sites that pass through your real login to the genuine service, capturing your password and two-factor code in transit. This is why healthy skepticism, rather than technology alone, is the frontline defense.
What to do if you already clicked
Act quickly. If you entered a password, change it right away, and change it anywhere you reused the same password. Turn on two-factor authentication so a stolen password alone will not let an attacker in. If you shared financial information, contact your bank or card issuer immediately and watch for unauthorized charges. Run a security scan if you downloaded anything. Keep an eye on your accounts over the following weeks for unexpected logins, password-reset emails you did not request, or messages sent from your account, all of which can signal that access was gained.
How to reduce your risk
A few habits sharply cut your exposure. Enable two-factor authentication on important accounts so a phished password is not enough on its own. Keep your devices and browsers updated, and use a password manager, which refuses to autofill your credentials on a fake domain, giving you a built-in warning. If you check saved logins on your phone, our guide to how to see saved passwords on iPhone shows where they live. Using a VPN protects your connection on public networks, though it does not stop phishing by itself, since the goal is to trick you rather than intercept traffic. It also helps to understand related tools like what ChatGPT is, because attackers increasingly use AI to write more convincing messages.
The single most effective defense is a habit of pausing before you act on any message that pressures you to log in, pay, or share information. When something feels urgent and unexpected, slow down and verify through a channel you already trust. Treat any request for a password, a one-time code, or a payment as a reason to stop and check directly with the organization, because legitimate companies do not ask for those over an unsolicited message. Building that reflex, and helping less technical friends and family recognize the same warning signs, does more to keep accounts safe than any single tool.
