Start with the request, not the logo
Ask what the message wants you to do. Requests to sign in, approve a payment, move money, disclose a code or open an unexpected file deserve independent verification. A familiar logo and correct spelling can be copied in seconds.
Urgency is a warning signal, especially when the sender claims an account will close, a parcel will be returned or a payment will fail. Pause and open the organisation's known app or type its address yourself.
- Unexpected login or payment request
- Pressure to act immediately
- Request for a password or one-time code
- Conversation moved to an unusual channel
Inspect the sender and destination
The visible sender name can differ from the actual email address. Expand the details and examine the complete domain, reading from right to left before the first slash. Similar characters, added words and misleading subdomains are common.
On a computer, hover over a link without clicking. On mobile, press and hold carefully to preview it. Do not rely on a padlock: HTTPS encrypts a connection but does not prove that the site belongs to the company being imitated.
Treat attachments and QR codes cautiously
Unexpected archives, HTML files, office documents and installers can deliver malware or open a fake sign-in page. Cloud-storage links can also lead to harmful content even when the hosting domain itself is legitimate.
QR codes hide their destination from casual inspection. Scan only when you understand who placed the code and why, then inspect the preview before opening it.
Verify through a separate channel
Contact the organisation through its official app, a bookmarked site or a number printed on a physical card or statement. Do not use contact details supplied inside the suspicious message.
For an apparent request from a colleague or relative, use an established channel and ask a question that an impersonator would not easily answer. Voice cloning means a familiar voice is no longer conclusive evidence.
If you entered details
Use a clean device to change the affected password and any reused passwords. End active sessions, review recovery email and phone settings, enable phishing-resistant multifactor authentication where available and save screenshots or message headers.
Contact the bank immediately if payment information, a card number or an authorisation code was exposed. Report the incident through the relevant national cybercrime or fraud channel; official services differ by country.
- Change compromised and reused passwords
- Revoke sessions and unknown app access
- Call the bank using a trusted number
- Preserve evidence before deleting messages
Reduce future risk
A password manager helps because autofill normally recognises the real domain and will not fill credentials on a lookalike site. Software updates and reputable web protection can block some known pages, but neither replaces verification.
Prefer passkeys or hardware-backed authentication where supported. Never approve an unexpected push notification, and never read a one-time code to someone who contacted you.
The main phishing formats you will meet
Email remains the highest-volume channel, but text messages, messaging apps, phone calls and social media now carry a large share of successful attacks. Smishing works because a short message looks routine on a small screen, where the full web address is usually hidden and the sender is only a number. Voice phishing succeeds because a live conversation removes thinking time and because caller identification can be forged cheaply.
A second family of attacks skips the fake website entirely. Callback phishing sends a plausible invoice or subscription-renewal notice and asks you to telephone a number to cancel a charge. The call centre is operated by the attacker, who then talks you through installing remote-access software or transferring money to a supposedly safe account. Because no malicious link is involved, these messages routinely pass through filters.
Business email compromise targets organisations of every size. The attacker studies public information about suppliers, invoices or a manager's absence, then requests a change of bank details or an urgent payment. The single most effective defence is a mandatory verification call to a number already held on file before any payment details change.
- Email and attachment lures
- Smishing by text or messaging app
- Voice calls and fake support desks
- Callback and fake-invoice schemes
- Advertising and search-result impersonation
How attackers defeat two-factor authentication
Attackers assume most valuable accounts are protected by a second factor, so modern phishing kits are built to capture it. A reverse-proxy kit shows you the genuine login page in real time, relays your password and one-time code to the real service within seconds, and then steals the resulting session cookie. From that point the attacker is signed in and your code has already expired, so changing a password alone may not evict them.
Push fatigue is a simpler variation. The attacker, already holding your password, triggers repeated approval prompts until someone taps accept to stop the noise. Treat every unexpected prompt as evidence that your password is known and needs changing immediately.
Passkeys and hardware security keys resist these techniques because the credential is bound to the real domain and cannot be replayed on a copycat site. Where a service still offers only codes, prefer an authenticator application over text messages, which remain vulnerable to SIM-swap fraud.
Building a family or team routine
Individual vigilance fails eventually, so agree on rules that do not depend on spotting a clever message. Establish that nobody in the household or team will ever be asked for a code by phone, that payment details are changed only after a call to a stored number, and that a request to move money to a new account always requires a second person's confirmation.
Agree a spoken safe word with close family. It costs nothing and neutralises cloned-voice emergency calls, which are now cheap to produce from a few seconds of public audio. Explain it to older relatives and teenagers in the same conversation, because both groups are targeted disproportionately.
Finally, make reporting comfortable. Most losses grow because the person who clicked waited hours before admitting it. State clearly that there is no blame for reporting a mistake quickly; the first sixty minutes are when a bank transfer can still be recalled and a session can still be revoked.
- No codes shared by phone, ever
- Bank details verified by callback
- Two-person approval for payments
- A spoken family safe word
- Blame-free, immediate reporting
