What phishing is
Phishing is a type of online fraud that uses convincing messages—often emails, SMS, or fake login pages—to manipulate you into doing something risky. The goal is usually to obtain sensitive information (like passwords or one-time codes) or to trigger an action (like transferring money, approving a login, or downloading a file). It relies on social engineering more than technical hacking.
How phishing typically works
A typical phishing chain looks like this:
- A target receives a message that appears legitimate (for example, it may imitate a bank, a workplace system, or a common service).
- The message creates pressure or confusion: “verify now,” “your account will be locked,” or a time-limited prompt.
- It asks you to click a link, open an attachment, or provide information directly in a form.
- If you comply, the attacker can capture credentials, tokens, or personal details, or redirect you to further scams.
Attackers frequently reuse recognizable branding, wording, and formatting to increase credibility. They may also tailor messages to the recipient, which is sometimes called “spear phishing,” making it harder to dismiss as generic spam.
Practical checks before you act
Use lightweight, repeatable checks that don’t require special tools:
- Check the sender carefully: look for mismatches in the email address, display name vs. actual address, and unusual domains.
- Avoid direct trust in urgency: attackers often push for fast action to reduce your ability to verify.
- Don’t click first: if the message claims an account issue, navigate manually by typing the organization’s known website address or using a trusted bookmark.
- Inspect links: before clicking, preview the URL and confirm the domain matches what you expect. Watch for look-alike domains and unexpected subdomains.
- Verify requests that involve secrets: legitimate services usually do not ask for passwords or one-time codes via unsolicited messages.
- Check for file attachments: if you weren’t expecting a document, treat unexpected attachments as high-risk.
If something doesn’t pass multiple checks, assume it’s suspicious and stop the interaction.
Differences, limitations, and related concepts
Phishing is often discussed alongside malware and account compromise, but they are not the same.
- Phishing vs. malware: phishing can deliver malware (for example, via a malicious link or attachment), but phishing can also be “information-only,” aiming for credentials or approvals without needing malware.
- Phishing vs. phishing-by-phone (vishing): both use the same persuasion goal, but one happens over voice calls.
- Phishing vs. smishing: both are message-based, but smishing uses SMS/text.
- Limitations of phishing attempts: attackers need your interaction—clicking, entering secrets, or approving a login. If you verify identity and avoid entering credentials into untrusted pages, phishing often loses much of its effectiveness.
A related concept is brand impersonation and credential harvesting: phishing pages are designed to mimic real login portals so that entered information is captured by the attacker.
A quick checklist to decide “stop or proceed”
Before you click or enter anything, apply a short decision filter:
- Does the message ask for passwords, verification codes, or urgent action?
- Does the sender domain and link destination match what you expect?
- Can you verify the claim by going to the official site yourself?
- Are there language, formatting, or context inconsistencies?
- Did you expect this exact request from that specific sender?
If the answer raises doubts on any of these, stop and verify through trusted channels rather than responding to the message directly.
