Skip to content

Scam Types

What is phishing? How to spot and stop it

Phishing is when someone pretends to be a trusted company or person — usually by email, text, or call — to trick you into giving up passwords, money, or personal details. The message creates urgency or fear, then asks you to click a link, share information, or transfer money. If a message you didn’t expect is pressuring you to act fast, treat it as phishing until proven otherwise.

Last reviewed: May 10, 2026  ·  Drafted with AI assistance. Reviewed and edited by a human editor before publication.

01

What is phishing? (Definition)

Phishing is a type of deception where a scammer “fishes” for your sensitive information by pretending to be a source you trust. These messages are designed to look like official communications from banks, tech companies, or government agencies.

According to the Anti-Phishing Working Group, 3.88 million phishing attacks were observed globally in 2025. This volume remains historically high, with Microsoft, Apple, and Google being the top three most-impersonated brands across 2025 and into 2026. The goal of phishing is almost always to trick you into giving up login credentials or sensitive personal data.

02

How do you spot a phishing message? (Warning signs)

As of 2026, scammers update their tactics frequently, but they generally rely on the same emotional triggers and technical tricks. The Verizon 2025 Data Breach Investigations Report found the median time to click on a phishing email is just 21 seconds — meaning recognition has to happen fast. Look for these seven warning signs:

  1. Claims of suspicious account activity — The message says there has been a security problem or unusual log-in attempt that doesn’t actually exist.
  2. Pressure to confirm personal or financial info — They ask you to “verify” your identity or update payment details via a provided link.
  3. Urgency or threats — Language like “your account will be closed” or “legal action will be taken” if you do not act immediately.
  4. Unexpected invoices or receipts — An attachment or link regarding a purchase you don’t recognize, designed to make you click out of confusion.
  5. Generic or unusual greetings — The message may use “Dear Customer” or “Valued Member” instead of your name. The FTC’s consumer guidance on phishing notes generic greetings remain a common signal even as AI improves message personalization.
  6. Too-good-to-be-true offers — Eligibility for a government refund, a free prize, or a coupon that requires a “processing fee.”
  7. Mismatched links or QR codes — A link that doesn’t match the company’s real website, or a QR code (sometimes called “quishing”), which the APWG identified as a growing attack vector through 2025.

Key Takeaway

You don’t need to recognize every type of phishing. You only need to recognize one warning sign. If anything on this list applies, treat the message as phishing until proven otherwise.

03

What are the common types of phishing?

Phishing varies by channel. Each variant uses the same underlying psychology — urgency, authority, and trust — applied to a different communication method.

TypeChannelDescription
Email phishingEmailThe most common form; uses deceptive emails and links.
SmishingText messagePhishing via SMS or messaging apps.
VishingPhone callVoice phishing; increasingly uses AI voice cloning as of 2026.
Spear phishingTargeted emailA highly personalized attack targeting a specific person.
WhalingExecutive emailTargeting high-level executives or business owners.

Definition

Smishing is phishing by text message. Vishing is phishing by phone call. They use the same psychology as email phishing — they each have their own page.

04

What does phishing actually look like? (Real examples)

Example

These examples are paraphrased from real phishing messages, not reproduced word-for-word. Real phishing messages are updated constantly — the pattern matters more than the exact wording.

Scenario 1: The bank security alert

“Your [Bank Name] account has been locked due to a suspicious login from a new device. Click here to verify your identity and unlock your account.”

What makes it phishing: It uses fear and urgency to bypass your critical thinking. The link leads to a fake login page that looks identical to your bank’s real site.

Scenario 2: The missed delivery

“We attempted to deliver your package, but the address was incomplete. A small redelivery fee is required. Pay now at [Fake Tracking Link].”

What makes it phishing: It uses a low-friction request to trick you into entering your credit card details on a scammer-controlled page.

Scenario 3: The account verification

“Your Microsoft 365 password expires in 24 hours. To keep your access, click here to ‘Keep Current Password’.”

What makes it phishing: This is a credential harvesting attack designed to gain access to your files and emails.

05

What should you do if you think you received phishing?

  1. Do not click any links. Do not open any attachments.
  2. Verify the claim independently. If the email says it is from Amazon, go to Amazon.com directly or use the official app. Never use contact info from the message.
  3. Report the message. Reporting helps authorities take down scam addresses and sites.
  4. Delete the message. Once reported, delete it to prevent accidental clicks.

Where to report phishing:

  • In the United States: The FTC directs reports to ReportFraud.ftc.gov. Forward phishing emails directly to reportphishing@apwg.org.
  • In the United Kingdom: Forward suspicious emails to the NCSC’s Suspicious Email Reporting Service at report@phishing.gov.uk. For suspicious text messages, forward them to 7726 (which spells SPAM) — this works free of charge on all major UK networks. For fraud and cybercrime incidents, report to Action Fraud.
  • In Australia: Report scam attempts to ACCC Scamwatch. For cybercrime incidents (such as a hacked account or stolen data), use ReportCyber via the ACSC.
06

What if you already clicked or replied?

If you have already entered your password, sent money, or downloaded an attachment, time is the most important factor. You must secure your accounts and devices immediately to prevent further damage. Please follow our step-by-step recovery guide for instructions on how to handle a compromised account.

07

How can you protect yourself from phishing in the future?

  • Use two-factor authentication (2FA). This is the single most effective defense. Even if a scammer gets your password, they cannot access your account without the second code. Learn how to set up 2FA.
  • Use a password manager. These tools will only auto-fill credentials on real, verified sites. If you land on a phishing site, a password manager will not offer your credentials.
  • Be skeptical of “AI-perfect” messages. Vectra AI’s 2026 analysis found AI-generated content in 82.6% of phishing emails as of 2026, with attackers able to create convincing campaigns in five minutes that previously took 16 hours of human work. Always verify the sender’s actual email address, not just the “Display Name.”
08

Sources