What Is Phishing and How to Recognize It
What Is Phishing and How to Recognize It
Phishing is a type of online fraud in which an attacker pretends to be a legitimate person or organization to get you to reveal credentials, financial details, or to install malicious software. You can usually spot phishing by unexpected requests for sensitive data, strange or mismatched links, poor grammar, suspicious attachments, or language that pressures you to act immediately. If you are unsure, stop, verify the sender through an independent channel, and do not click links or open attachments.
How phishing typically appears
Phishing is not limited to one format. Scams show up in email, text messages, phone calls, social media messages, and even in ads or fake websites. Attackers adapt their method to the communication channel that will most likely reach the target.
Common phishing examples
- Email that claims to be from a bank, payroll provider, or colleague and asks you to sign in or confirm personal information.
- Text message (SMS) that urges you to click a link to resolve a delivery or payment problem.
- Voice call that uses caller ID spoofing and asks for a one-time code or account number.
- Social media message with a shortened link offering a too-good-to-be-true deal or asking you to review a document.
Phishing indicators to watch for
Recognizing phishing depends on spotting specific indicators. No single sign proves a message is malicious, but multiple indicators increase the likelihood that it is a scam.
- Unexpected requests - You did not initiate the conversation or transaction mentioned.
- Sender mismatch - The display name looks right but the email address or phone number is unusual or slightly altered.
- Mismatched URLs - Hovering over a link reveals a different domain than the text suggests, or the URL contains odd characters or extra words.
- Urgent language - Messages that pressure you to act now to avoid a penalty or to claim a reward.
- Attachments or unexpected files - Especially files with .exe, .scr, .zip, or macro-enabled Office documents.
- Poor spelling and grammar - Many phishing attempts contain awkward phrasing, though some are professionally written.
- Requests for credentials or codes - Legitimate organizations rarely ask you to reply with passwords, full Social Security numbers, or 2FA codes.
Worked example: evaluating a suspicious email
Scenario: You receive an email that appears to come from your payroll provider saying your direct deposit failed and asking you to "re-enter account details" using a link. Steps to evaluate:
- Pause and do not click the link or open attachments.
- Check the sender address for subtle misspellings or an unrelated domain.
- Hover over the link to preview the URL; compare it to the known payroll site domain.
- Open a new browser window and navigate to the payroll provider's website directly, or contact your HR department using a verified phone number or internal portal.
Immediate steps to take when you suspect phishing
Quick, measured actions limit harm. The following step-by-step process helps you respond safely and preserve evidence if needed.
- Stop: do not click links, download files, or reply with sensitive information.
- Verify: contact the sender using a phone number or internal message thread you already trust, not the contact information in the suspicious message.
- Contain: if you clicked a link or opened an attachment and suspect compromise, disconnect the device from the network and change passwords from another known-good device.
- Report: forward the suspicious message to your IT or security team, or use official reporting channels. See guidance in How to Report a Phishing Email.
- Document: keep a copy of the message and any screenshots to help incident responders.
Anti-phishing steps you can implement now
Prevention reduces risk. Some steps are individual practices; others are organizational controls small businesses can adopt without major expense.
- Use two-factor authentication where possible — a second factor makes stolen credentials less useful. Learn more in Two-Factor Authentication: A Practical Guide.
- Create and manage strong passwords and use a password manager to avoid reuse. See How to Create Strong Passwords.
- Keep software updated so known vulnerabilities are patched.
- Deploy email filters and anti-malware tools to block known threats and quarantine suspicious messages.
- Train staff on basic recognition and procedures; routine simulation exercises reduce click rates. For formal programs, see Security Awareness Training for Employees.
Common mistakes and how to avoid them
Even cautious people can make errors under pressure. Recognize the behaviors that increase risk and replace them with safer alternatives.
- Mistake: Replying to a suspicious message to "ask a question." Safer: Verify by contacting the supposed sender through known channels instead of replying.
- Mistake: Clicking a link to 'fix' a problem immediately. Safer: Open the service in a new browser tab by typing the known URL or using a bookmark.
- Mistake: Forwarding a suspected phishing message to coworkers without warning. Safer: Notify your IT or security team and use internal reporting so others are warned correctly.
- Mistake: Using the same password across services. Safer: Use unique passwords stored in a manager and protect accounts with 2FA.
Quick checklist you can print or share
- Does the sender match the organization? If not, be suspicious.
- Is the message urgent or threatening? Slow down and verify.
- Do links point to the expected domain? Hover before you click.
- Are there unexpected attachments? Do not open them without verification.
- Can you confirm the request through a separate, trusted channel?
Phishing remains one of the most common ways attackers gain access to accounts and systems because it targets human trust rather than technical vulnerabilities. A short pause, a verification step, and a few defensive habits will prevent most attacks. If you encounter a suspected phishing message, follow your organization’s reporting process or consult official guidance in How to Report a Phishing Email.