Definition and what phishers want
Phishing is a type of online scam where someone impersonates a trustworthy person, organization, or service to get you to do something unsafe—such as entering a password, sharing personal information, or clicking a malicious link. The goal is usually to steal credentials, access your accounts, or obtain information that can be used for fraud.
A common pattern is: (1) the message looks like it came from a legitimate source, (2) it includes an instruction that creates pressure or confusion, and (3) it directs you toward an action that benefits the attacker.
A simple model of how phishing works
Think of phishing as a “trust + urgency” test. Attackers try to bypass your normal checking process by making the message feel urgent or routine.
- They use convincing language and branding to appear legitimate.
- They send links or attachments designed to capture your input or move you to a fraudulent page.
- They may claim account problems (for example, unexpected login attempts) to push you to act quickly.
Even when the message is well written, phishing typically relies on you skipping verification steps.
Common warning signs
You can’t rely on one sign alone, but these are frequent indicators:
- Sender details don’t match what you expect (name, email address, or domain).
- The message asks for credentials, one-time codes, or sensitive personal data.
- It urges immediate action (“act now,” “urgent,” or “your account will be locked”).
- The link text looks normal, but the destination is suspicious or unclear.
- Spelling errors, odd wording, or an unusual tone compared with messages from the real sender.
If something feels “off” even slightly, treat it as a prompt to verify before interacting.
Limits and exceptions that matter
Not every suspicious message is phishing, and not every phishing attempt is obvious. For example:
- Some scams are “social” rather than technically malicious: they may ask you to pay money or provide information without a link.
- Attackers may use compromised accounts, making the message appear to come from a real contact.
- Security warnings and authentication prompts can be legitimate—context matters.
Because of these variations, the safest approach is to verify any unexpected request through a known, trusted channel rather than relying on the message itself.
Practical ways to avoid phishing
You can reduce your exposure with a combination of habits and defenses:
- Verify requests that involve logins, codes, payments, or account changes using a separate channel (for example, by visiting the official website you already know, or contacting the sender through a trusted method).
- Hover/inspect links to check where they go; don’t assume the visible text is the real destination.
- Turn on multi-factor authentication (MFA) for important accounts to limit damage if credentials are stolen.
- Keep your operating system, browsers, and security software updated.
- Use spam/phishing filters and be cautious with attachments, especially when the message is unexpected.
If you clicked a suspicious link or entered credentials, take action immediately by changing the password from a trusted device and reviewing account activity. If there’s evidence of compromise, consider notifying the relevant service provider.
