How to spot phishing and respond safely

    Phishing is social engineering: the attacker creates urgency, trust or curiosity so you act before verifying the request. Modern messages may be grammatically convincing and personalised, so appearance alone is no longer a dependable test.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Start with the request, not the logo

    Ask what the message wants you to do. Requests to sign in, approve a payment, move money, disclose a code or open an unexpected file deserve independent verification. A familiar logo and correct spelling can be copied in seconds.

    Urgency is a warning signal, especially when the sender claims an account will close, a parcel will be returned or a payment will fail. Pause and open the organisation's known app or type its address yourself.

    • Unexpected login or payment request
    • Pressure to act immediately
    • Request for a password or one-time code
    • Conversation moved to an unusual channel

    Inspect the sender and destination

    The visible sender name can differ from the actual email address. Expand the details and examine the complete domain, reading from right to left before the first slash. Similar characters, added words and misleading subdomains are common.

    On a computer, hover over a link without clicking. On mobile, press and hold carefully to preview it. Do not rely on a padlock: HTTPS encrypts a connection but does not prove that the site belongs to the company being imitated.

    Treat attachments and QR codes cautiously

    Unexpected archives, HTML files, office documents and installers can deliver malware or open a fake sign-in page. Cloud-storage links can also lead to harmful content even when the hosting domain itself is legitimate.

    QR codes hide their destination from casual inspection. Scan only when you understand who placed the code and why, then inspect the preview before opening it.

    Verify through a separate channel

    Contact the organisation through its official app, a bookmarked site or a number printed on a physical card or statement. Do not use contact details supplied inside the suspicious message.

    For an apparent request from a colleague or relative, use an established channel and ask a question that an impersonator would not easily answer. Voice cloning means a familiar voice is no longer conclusive evidence.

    If you entered details

    Use a clean device to change the affected password and any reused passwords. End active sessions, review recovery email and phone settings, enable phishing-resistant multifactor authentication where available and save screenshots or message headers.

    Contact the bank immediately if payment information, a card number or an authorisation code was exposed. Report the incident through the relevant national cybercrime or fraud channel; official services differ by country.

    • Change compromised and reused passwords
    • Revoke sessions and unknown app access
    • Call the bank using a trusted number
    • Preserve evidence before deleting messages

    Reduce future risk

    A password manager helps because autofill normally recognises the real domain and will not fill credentials on a lookalike site. Software updates and reputable web protection can block some known pages, but neither replaces verification.

    Prefer passkeys or hardware-backed authentication where supported. Never approve an unexpected push notification, and never read a one-time code to someone who contacted you.

    The main phishing formats you will meet

    Email remains the highest-volume channel, but text messages, messaging apps, phone calls and social media now carry a large share of successful attacks. Smishing works because a short message looks routine on a small screen, where the full web address is usually hidden and the sender is only a number. Voice phishing succeeds because a live conversation removes thinking time and because caller identification can be forged cheaply.

    A second family of attacks skips the fake website entirely. Callback phishing sends a plausible invoice or subscription-renewal notice and asks you to telephone a number to cancel a charge. The call centre is operated by the attacker, who then talks you through installing remote-access software or transferring money to a supposedly safe account. Because no malicious link is involved, these messages routinely pass through filters.

    Business email compromise targets organisations of every size. The attacker studies public information about suppliers, invoices or a manager's absence, then requests a change of bank details or an urgent payment. The single most effective defence is a mandatory verification call to a number already held on file before any payment details change.

    • Email and attachment lures
    • Smishing by text or messaging app
    • Voice calls and fake support desks
    • Callback and fake-invoice schemes
    • Advertising and search-result impersonation

    How attackers defeat two-factor authentication

    Attackers assume most valuable accounts are protected by a second factor, so modern phishing kits are built to capture it. A reverse-proxy kit shows you the genuine login page in real time, relays your password and one-time code to the real service within seconds, and then steals the resulting session cookie. From that point the attacker is signed in and your code has already expired, so changing a password alone may not evict them.

    Push fatigue is a simpler variation. The attacker, already holding your password, triggers repeated approval prompts until someone taps accept to stop the noise. Treat every unexpected prompt as evidence that your password is known and needs changing immediately.

    Passkeys and hardware security keys resist these techniques because the credential is bound to the real domain and cannot be replayed on a copycat site. Where a service still offers only codes, prefer an authenticator application over text messages, which remain vulnerable to SIM-swap fraud.

    Building a family or team routine

    Individual vigilance fails eventually, so agree on rules that do not depend on spotting a clever message. Establish that nobody in the household or team will ever be asked for a code by phone, that payment details are changed only after a call to a stored number, and that a request to move money to a new account always requires a second person's confirmation.

    Agree a spoken safe word with close family. It costs nothing and neutralises cloned-voice emergency calls, which are now cheap to produce from a few seconds of public audio. Explain it to older relatives and teenagers in the same conversation, because both groups are targeted disproportionately.

    Finally, make reporting comfortable. Most losses grow because the person who clicked waited hours before admitting it. State clearly that there is no blame for reporting a mistake quickly; the first sixty minutes are when a bank transfer can still be recalled and a session can still be revoked.

    • No codes shared by phone, ever
    • Bank details verified by callback
    • Two-person approval for payments
    • A spoken family safe word
    • Blame-free, immediate reporting

    Frequently asked questions

    Can a phishing email come from a real address?

    Yes. An account may be compromised, or email authentication may be weak. Judge the request and verify independently even when the address looks familiar.

    Does HTTPS mean a website is genuine?

    No. HTTPS protects data in transit to that domain. Attackers can obtain certificates for deceptive domains.

    Should I reply to test whether the sender is real?

    No. Use a separate trusted channel. Replying can confirm that your address is active and keep you inside the attacker's conversation.

    Is two-factor authentication enough to stop phishing?

    It helps, but modern phishing kits relay one-time codes in real time and steal the resulting session. Passkeys or a hardware security key are far stronger because they are tied to the genuine domain and cannot be replayed on a fake one.

    What should I do first if I clicked a link but entered nothing?

    Close the page, do not enter data, and run a scan with your installed security software. Watch the related account for unexpected login alerts over the following days, and change the password if you are unsure what was typed.