Phishing is one of the most common ways criminals steal passwords, money, and personal information. Instead of hacking into systems directly, attackers trick people into handing over what they want — by clicking a malicious link, opening an infected attachment, entering login details on a fake website, or sending money to the wrong person.
Phishing attacks are getting more convincing, especially as criminals use AI to write polished messages and even imitate voices. This guide explains the most common types of phishing, the warning signs to look for, and what to do if you’ve already clicked.
What Is Phishing?
Phishing is a type of scam in which attackers pretend to be a trusted person or organization — such as a bank, delivery company, government agency, employer, or well-known brand — to manipulate you into taking an action that benefits them.
Common Types of Phishing
Email phishing
The classic form: mass emails that impersonate a company and ask you to “verify your account,” “confirm a payment,” or “review a document.”
Spear phishing
Targeted messages aimed at a specific person or organization, often using personal details found online to appear more believable.
Business email compromise (BEC)
Attackers impersonate executives, suppliers, or colleagues to request wire transfers, gift cards, or changes to payment details. These scams can cost businesses large sums.
Smishing (SMS phishing)
Fake text messages, such as notices about a missed delivery, unpaid toll, suspicious bank activity, or a prize you’ve “won.”
Vishing (voice phishing)
Phone calls from someone pretending to be your bank, tech support, the tax authority, or the police. Increasingly, criminals use AI voice cloning to impersonate family members or executives.
Quishing (QR code phishing)
Malicious QR codes placed in emails, on flyers, or even stuck over legitimate codes on parking meters, leading to fake payment or login pages.
Social media and messaging app scams
Fake accounts, hacked friend profiles, investment scams, and fake customer support accounts on platforms like WhatsApp, Instagram, Facebook, and Telegram.
10 Warning Signs of a Phishing Attempt
- Urgency or threats: “Your account will be closed in 24 hours,” “Immediate action required,” or “Legal action will be taken.”
- Requests for sensitive information: Legitimate companies rarely ask for passwords, full card numbers, or one-time codes by email, text, or phone.
- Mismatched sender addresses: The display name says “PayPal” but the email address is from an unrelated or misspelled domain.
- Suspicious links: Hover over a link (or long-press on mobile) to see the real address. Watch for misspellings, extra words, or unfamiliar domains.
- Unexpected attachments: Especially invoices, ZIP files, or documents that ask you to “enable content.”
- Generic greetings: “Dear customer” instead of your name — though targeted attacks may use your real name.
- Too-good-to-be-true offers: Prizes, refunds, investment returns, or job offers you didn’t apply for.
- Unusual payment requests: Gift cards, cryptocurrency, or wire transfers are common scam payment methods.
- Changes to payment details: A “supplier” suddenly asks you to send money to a new bank account.
- Requests for secrecy: “Don’t tell anyone” or “Keep this confidential” is a major red flag.
Note: Spelling mistakes used to be a common giveaway, but AI tools now help criminals write polished messages. Don’t assume a well-written message is safe.
Real-World Examples
| Scenario | Red flags | Safe response |
|---|---|---|
| Text says a package is held and you must pay a small fee | Unexpected, urgent, asks for card details | Check tracking directly on the courier’s official website or app |
| Email from “your bank” asks you to log in to stop suspicious activity | Link in the email, urgency | Open the bank’s app or type its address yourself |
| “CEO” emails asking you to buy gift cards urgently | Unusual request, secrecy, gift cards | Verify with the CEO through a known phone number or in person |
| A family member calls in distress asking for money | Urgency, emotional pressure, unusual payment method | Hang up and call them back on a number you know; use a family code word |
| Supplier emails new bank details for an invoice | Changed payment info | Call the supplier using contact details you already have on file |
How to Protect Yourself
1. Go directly to the source
Instead of clicking links in messages, open the official app or type the website address yourself. Call organizations using phone numbers from their official website or the back of your card.
2. Use two-factor authentication
2FA adds a second layer of protection even if your password is stolen. Phishing-resistant methods like passkeys and security keys offer the strongest protection. See 2FA methods ranked from weakest to strongest.
3. Use a password manager
Password managers typically autofill only on the genuine website. If your password manager doesn’t offer to fill in your login, that’s a warning sign you may be on a fake site. Learn more in our guide to password managers.
4. Keep software updated
Updates for your operating system, browser, and apps fix security flaws that attackers could exploit through malicious links or attachments.
5. Be careful with QR codes
Check the website address that appears before opening it, and be wary of QR codes on stickers placed over signs or in unexpected emails.
6. Limit what you share publicly
Details on social media — your job, family members, travel plans — can be used to make targeted phishing more convincing.
7. Agree on a family code word
With AI voice cloning on the rise, a secret word known only to family members can help verify emergency calls.
What to Do If You Clicked a Phishing Link
Don’t panic — acting quickly can limit the damage.
- Disconnect from the internet if you downloaded a file or suspect malware.
- Change your password for the affected account — and any others that use the same password — from a trusted device.
- Enable 2FA if you haven’t already.
- Contact your bank immediately if you shared financial details, and ask about freezing or replacing your card.
- Run a security scan with reputable antivirus software.
- Check your accounts for unfamiliar activity, forwarding rules, or new devices.
- Tell your IT team right away if it happened on a work device or account.
- Report it to the relevant authorities in your country and to the organization being impersonated.
How to Report Phishing
- Emails: Use your email provider’s “Report phishing” button.
- Text messages (U.S.): Forward scam texts to 7726 (SPAM) to alert your mobile carrier.
- U.S. authorities: Report fraud to the FTC at ReportFraud.ftc.gov, and cybercrime to the FBI’s Internet Crime Complaint Center (IC3).
- Other countries: Check your national cybersecurity or consumer protection agency for reporting options.
- Impersonated companies: Many brands have dedicated addresses for reporting phishing that uses their name.
Phishing Protection for Businesses
- Run regular security awareness training and phishing simulations.
- Set up email authentication (SPF, DKIM, and DMARC) to reduce spoofing of your domain.
- Require verbal verification for any change in payment details.
- Enforce MFA on all accounts.
- Make it easy — and blame-free — for employees to report suspicious messages.
For more on business protection, see our guide to AI cybersecurity tools.
Frequently Asked Questions
Can I get hacked just by opening a phishing email?
Simply opening an email is usually low risk on up-to-date software. The main danger comes from clicking links, opening attachments, or replying with information.
Why do I get so many phishing messages?
Email addresses and phone numbers are often exposed in data breaches or collected from public sources. Scammers send huge volumes hoping a small percentage will respond.
Will my bank ever ask for my one-time code?
Banks generally warn customers never to share one-time codes with anyone, including bank staff. Anyone asking for one is a major red flag.
Final Thoughts
Phishing works by exploiting trust, urgency, and emotion. The best defense is a simple habit: pause, verify, and go directly to the source. Combine that habit with two-factor authentication, a password manager, and up-to-date software, and you’ll be protected against the vast majority of phishing attacks.
This article is for general educational purposes. Reporting options vary by country.