What Is Phishing and How to Recognize It

What Is Phishing and How to Recognize It

Phishing is a type of online fraud in which an attacker pretends to be a legitimate person or organization to get you to reveal credentials, financial details, or to install malicious software. You can usually spot phishing by unexpected requests for sensitive data, strange or mismatched links, poor grammar, suspicious attachments, or language that pressures you to act immediately. If you are unsure, stop, verify the sender through an independent channel, and do not click links or open attachments.

How phishing typically appears

Phishing is not limited to one format. Scams show up in email, text messages, phone calls, social media messages, and even in ads or fake websites. Attackers adapt their method to the communication channel that will most likely reach the target.

Common phishing examples

Phishing indicators to watch for

Recognizing phishing depends on spotting specific indicators. No single sign proves a message is malicious, but multiple indicators increase the likelihood that it is a scam.

Worked example: evaluating a suspicious email

Scenario: You receive an email that appears to come from your payroll provider saying your direct deposit failed and asking you to "re-enter account details" using a link. Steps to evaluate:

  1. Pause and do not click the link or open attachments.
  2. Check the sender address for subtle misspellings or an unrelated domain.
  3. Hover over the link to preview the URL; compare it to the known payroll site domain.
  4. Open a new browser window and navigate to the payroll provider's website directly, or contact your HR department using a verified phone number or internal portal.

Immediate steps to take when you suspect phishing

Quick, measured actions limit harm. The following step-by-step process helps you respond safely and preserve evidence if needed.

  1. Stop: do not click links, download files, or reply with sensitive information.
  2. Verify: contact the sender using a phone number or internal message thread you already trust, not the contact information in the suspicious message.
  3. Contain: if you clicked a link or opened an attachment and suspect compromise, disconnect the device from the network and change passwords from another known-good device.
  4. Report: forward the suspicious message to your IT or security team, or use official reporting channels. See guidance in How to Report a Phishing Email.
  5. Document: keep a copy of the message and any screenshots to help incident responders.

Anti-phishing steps you can implement now

Prevention reduces risk. Some steps are individual practices; others are organizational controls small businesses can adopt without major expense.

Common mistakes and how to avoid them

Even cautious people can make errors under pressure. Recognize the behaviors that increase risk and replace them with safer alternatives.

Quick checklist you can print or share

Phishing remains one of the most common ways attackers gain access to accounts and systems because it targets human trust rather than technical vulnerabilities. A short pause, a verification step, and a few defensive habits will prevent most attacks. If you encounter a suspected phishing message, follow your organization’s reporting process or consult official guidance in How to Report a Phishing Email.