Phishing is one of the oldest tricks on the internet, and it still works because it targets people rather than machines. Instead of breaking through a firewall, an attacker sends you a message that looks like it came from a name you trust and asks you to do something ordinary: log in, confirm a payment, open a document. The moment you comply, you hand over the keys yourself.

What phishing actually is

Phishing is a form of social engineering. The attacker impersonates a trusted person or organization to trick you into revealing sensitive information or taking an action that benefits them. That information is usually a password, a one-time verification code, card details, or access to a work account. Sometimes the goal is money directly, through a fake invoice or a request to move funds.

The name is a play on fishing: the message is bait, and the attacker is hoping someone bites. Most phishing is sent in bulk to thousands of inboxes at once, counting on a small percentage of people to react without checking. According to the FBI’s Internet Crime Complaint Center, phishing and spoofing were the single most reported type of cybercrime in the US in 2025, generating more complaints than any other category.

How a phishing attack works

Nearly every phishing attempt follows the same simple pattern, whatever channel it arrives through.

  1. The hook. A message claims to be from a bank, a delivery company, your employer, a streaming service, or a government agency.
  2. The pressure. It creates urgency or fear. Your account will be closed, a payment failed, a package is stuck, someone logged in from a strange location.
  3. The ask. It tells you to click a link, open an attachment, call a number, or scan a code to fix the problem.
  4. The trap. The link leads to a fake login page that looks real. Whatever you type there goes straight to the attacker.

The fake page is the heart of the con. It can be a near-perfect copy of a genuine site, right down to the logo and layout. If you enter your username and password, the attacker captures them. If the real account is protected by a code, the page may even ask for that too, then use it within seconds before it expires. This is why a stolen password often leads straight to a data breach affecting far more than one account.

The main types of phishing

Phishing is no longer just email. Attackers reach you wherever you pay attention.

  • Email phishing is the classic form: a message in your inbox with a link or attachment. It is still the most common channel.
  • Smishing is phishing by SMS or messaging apps. A text claims a package needs a small fee, or your bank spotted fraud, and links to a fake site. Links in texts are easy to disguise and hard to inspect on a phone.
  • Vishing is voice phishing, done by phone call. A caller poses as your bank’s fraud team or tech support and talks you into reading out a code or installing software. Scammers now use caller-ID spoofing and even AI-generated voices to sound convincing.
  • Spear phishing targets a specific person with details that make the message feel personal, such as your name, employer, or a real project. It is slower to build but far more effective, and it is the method behind many costly attacks on businesses.
  • Clone phishing copies a real email you already received, then swaps the link or attachment for a malicious one and resends it, often claiming to be a resend or an update.
  • Quishing is QR-code phishing. The attacker puts a code in an email, a flyer, or a sticker placed over a legitimate one. Scanning it opens a phishing site on your phone. Because the malicious address is hidden inside an image, many email filters never see it, and QR-based attacks grew sharply through 2025 according to the Anti-Phishing Working Group.

Red flags that give a phish away

Most phishing shares the same tells. Any one of these should slow you down, and two or more together is a strong warning.

  • Urgency and threats. Real companies rarely demand that you act within minutes or lose your account.
  • A mismatched sender address. The display name says your bank, but the actual email address is a jumble or a lookalike domain.
  • Links that do not match. Hover over a link on a computer, or press and hold on a phone, to preview the real destination before tapping.
  • Requests for secrets. Any message asking for a password, full card number, PIN, or verification code is suspect by default.
  • Generic greetings like “Dear customer” from a company that knows your name.
  • Odd spelling and grammar, though polished scams exist too, so clean writing is not proof of safety.
  • Unexpected attachments, especially files that ask you to enable content or log in to view them.
  • Payment by unusual methods, such as gift cards, wire transfers, or cryptocurrency.

How to verify a suspicious message

When something feels off, do not use anything inside the message to check it. The whole message could be fake, including its phone numbers and links. Verify through a channel you already trust.

  • Go to the source yourself. Open a new tab and type the company’s web address by hand, or use its official app. Never log in through a link you were sent. This single habit defeats most phishing.
  • Call the number you already have. Use the phone number printed on your card, statement, or the back of a product, not the one in the message.
  • Check the real sender. Expand the sender’s full email address rather than trusting the display name.
  • Ask directly if the message claims to be from a colleague or boss. A quick call or in-person check beats a reply to a possibly spoofed address.

A password manager quietly helps here too. Because it fills your login only on the exact web address it saved, it will stay silent on a lookalike phishing page, which is a useful hint that the site is not genuine.

What to do if you clicked or entered your password

If you realize too late that you fell for a phish, act quickly and in order. Speed limits the damage.

  1. Change the password for the affected account right away, going to the real site directly. If you reused that password anywhere else, change it there too.
  2. Turn on two-factor authentication if it was not already active, so a stolen password alone cannot get in.
  3. Contact your bank if you entered card or account details, and watch for charges you do not recognize.
  4. Scan your device with security software if you downloaded or opened an attachment, and keep your system updated.
  5. Check account activity and recovery settings. Attackers often add a new email or phone number so they can lock you out later. Remove anything you did not set up.

Do not panic, and do not pay anyone who contacts you afterward offering to “recover” your money, since that is a common follow-up scam.

How to report phishing

Reporting takes a minute and helps shut down scams faster for everyone. In the US, there are a few clear routes.

  • Suspicious emails: forward them to the Anti-Phishing Working Group at reportphishing@apwg.org, and report the scam to the Federal Trade Commission at reportfraud.ftc.gov.
  • Suspicious texts: forward the message to 7726 (which spells SPAM), which flags it to your mobile carrier, then report it to the FTC as well.
  • Financial loss or a serious attack: file a complaint with the FBI’s Internet Crime Complaint Center at IC3.gov.
  • At work: use your employer’s report button or forward it to your IT or security team, since one reported message can protect the whole organization.

If you were impersonated or a specific brand was faked, let that company know too, as most have a dedicated abuse or fraud address.

How to lower your risk before the next attempt

You cannot stop scammers from sending messages, but you can make yourself a much harder target.

  • Turn on two-factor authentication everywhere it is offered, especially for email, banking, and work accounts.
  • Use unique passwords for every account so one leak does not unlock the rest.
  • Keep devices and apps updated, which closes the security holes that malicious attachments try to exploit.
  • Slow down with any message that creates urgency. That pause is where most scams fall apart.
  • Be careful what you share publicly, since personal details make spear phishing easier to craft.

A VPN is worth understanding too, though it is important to be clear about its limits: it protects your connection on untrusted networks but does not detect or block phishing, so it is no substitute for the habits above.

Why no filter catches everything

It is tempting to assume your email provider or phone will catch the bad messages for you. They catch a great deal, but not all of it. Attackers test their messages against popular filters, register fresh web addresses daily, and increasingly use AI to write cleaner, more personal lures. Quishing in particular is built to dodge filters by hiding the dangerous link inside an image.

So treat every security tool as one layer among several, never as a guarantee. The habits that protect you most are boringly simple and completely within your control: never enter your credentials through a link, open sites and apps yourself, turn on two-factor authentication, and give yourself a few seconds to think whenever a message is pushing you to hurry. Those few seconds are the real defense, and no scammer can take them from you.