The Complete Guide to Phishing: How to Recognize and Stop Email, SMS and Online Attacks
What phishing is, every common type, how to read a link and check an email, why passkeys help, how to report phishing, and what to do if you clicked.

It is Monday morning. An email from "IT Support" says your mailbox is 98% full and will stop receiving messages today unless you verify your account. The logo is right, the tone is polite, and there is a blue button labelled "Verify now". You click, a familiar sign-in page appears, and you type your password. Nothing seems to happen. By lunchtime, someone else is reading your email.
That is phishing: a message that imitates someone you trust so that you hand over something valuable yourself. It is the most common way attackers get into email accounts, bank accounts and company networks, and it arrives by email, text, phone, social media and messaging apps.
This guide explains how phishing works, every common type, how to check a sender and read a link like a professional, which protections actually stop it, how to report it, and what to do if you have already clicked. It is written for anyone, anywhere, whether you are protecting your own accounts or your whole organization.
What is phishing?
Phishing is a deceptive message designed to make you click a link, open a file, reply with information, call a number or make a payment, by pretending to come from a trusted person or organization. The name comes from fishing: the attacker casts a lure and waits for someone to bite.
Phishing is usually the first step, not the whole attack. What the attacker does next depends on what they catch:
- Passwords and codes, used to take over email, banking, social media or work accounts.
- Card and bank details, used for fraud.
- A foothold on your device through a malicious file, which can lead to data theft or ransomware.
- A payment, made to the attacker directly.
How a phishing attack works
- The lure. A message that looks like it comes from a bank, a delivery company, your IT department, a colleague, a government agency or a well-known brand.
- The reason to act. A problem (your account is locked), an opportunity (a refund is waiting) or a routine task (a document has been shared with you).
- The hook. A link to a fake page, an attachment, a phone number to call, or a request to reply.
- The catch. You enter a password, a code or card details, open the file, or send the payment.
The psychology behind it, authority, urgency, fear and curiosity, is explained in the six levers attackers pull on people. Phishing is one delivery method for the wider family of tricks covered in our complete guide to online scams.
Types of phishing
Email phishing
The classic version: a mass email copying a bank, a streaming service, a parcel company or an email provider. Our step-by-step guide how to spot a phishing email covers the basics.
Spear phishing and whaling
Targeted messages written for a specific person or team, using real names, projects and details found online. Whaling targets senior people such as directors and finance heads.
Business email compromise
An attacker impersonates, or takes over, the email of an executive or supplier to redirect payments. It is one of the most costly forms of phishing for organizations. See business email compromise.
Smishing (SMS phishing)
Text messages about parcels, tolls, banks or tax refunds that carry a link. The sender name can be faked. See smishing.
Vishing (voice phishing)
Phone calls from someone posing as a bank, a government office or IT support. Read fake IT support calls.
Callback phishing
An email with no link at all, just a fake invoice or subscription renewal and a phone number to call "to cancel". The person who answers talks you into installing remote access software or paying a "refund" fee.
QR code phishing
A QR code in an email or on a poster that leads to a fake login or payment page. See QR code phishing.
Clone phishing
A copy of a real email you received earlier, resent with the link or attachment swapped for a malicious one, often "resending" a document.
Search engine and ad phishing
Paid adverts or fake results that appear above the real site when you search for your bank, a support number or popular software.
Social media and messaging app phishing
Direct messages that claim your account will be suspended, fake brand support accounts, and links sent from friends' hacked accounts. WhatsApp versions are covered in our guide to WhatsApp scams.
Code-stealing pages and consent phishing
More advanced phishing pages pass your password and two-step code to the real site as you type, logging the attacker in at the same moment. Another variant asks you to "allow" a malicious app access to your email or files, so no password is needed at all. Both look like normal sign-in screens.
Anatomy of a phishing message
| Part | What to check | Common tricks |
|---|---|---|
| Sender | The actual email address, not just the display name | "Microsoft Support" sent from a random address; lookalike domains with one letter changed |
| Subject | Urgency or alarm | "Final notice", "Account suspended", "Payment failed" |
| Greeting | Generic or odd | "Dear customer", "Dear user", or your email address instead of your name |
| Request | What it asks you to do | Sign in, confirm details, pay a small fee, open a file, call a number |
| Links | Where they really go | Button text says one thing, the address says another |
| Attachments | Whether you expected them | "Invoice", "Payment advice", "Scanned document", zipped or password-protected files |
| Tone and design | Anything that feels slightly off | Modern phishing is often perfectly written; good grammar is not proof of safety |
How to read a link
This is the most useful skill in this guide. On a computer, hover over a link to see its address at the bottom of the window. On a phone, press and hold the link to preview it. Then find the domain: the part just before the first single slash after https://. Read it from right to left.
https://www.examplebank.com/loginis examplebank.com.hxxps://examplebank.com.account-verify[.]net/loginis account-verify.net. Everything before it is decoration.hxxps://www.examp1ebank[.]comuses the number 1 instead of the letter l.hxxps://examplebank-security[.]comis a different domain from examplebank.com, however official the words sound.- Shortened links hide the destination entirely. Treat them with extra caution in unexpected messages.
The addresses above are illustrative and deliberately broken so they cannot be clicked. The safest habit of all: if a message asks you to sign in or pay, do not use the link. Open the app, or type the address you already know.
Illustrative examples, with the red flags explained
These examples are fictional and written for this guide.
hxxps://login-office.secure-mailboxes[.]co/keep- The sender's domain is not your organization's.
- A deadline measured in hours, and a link to "keep" a password.
- What to do: do not click. Report it to your IT team with the report button.
- A charge you do not recognise, designed to make you call in a panic.
- No link, so filters may not catch it. The phone number is the hook.
- What to do: check your bank or card statement and the real account yourself. Never call the number in the message.
hxxps://secure-bank-check[.]info- Alarm about a problem, and a link to fix it.
- A generic "BANK" and an address unrelated to any bank.
- What to do: open your banking app directly to check for new devices.
Unsure about a message? Paste it or the link into CyberWatch AI Scan, or upload a screenshot. It is free, works in any language and explains what looks suspicious. Then verify through an official channel before acting.
Dangerous attachments
Attachments are a common way to deliver malware. Be especially careful with:
- Files you did not expect, even from people you know, since their account may be compromised.
- Office documents that ask you to "enable content" or "enable editing" to view them.
- Zipped or password-protected files, which filters cannot inspect.
- Files ending in unusual extensions, or with a double extension such as
invoice.pdf.exe. - HTML attachments that open a sign-in page in your browser.
- "Shared document" messages linking to file-sharing sites that then ask for your password.
If you are unsure, confirm with the sender through a separate channel before opening.
Two-step verification and phishing-resistant sign-in
Two-step verification, also called multi-factor authentication, stops most attacks that rely on a stolen password, so turn it on everywhere. But some phishing pages relay codes in real time, and attackers can bombard you with approval prompts, as described in MFA fatigue.
The strongest option is phishing-resistant sign-in: passkeys and physical security keys. They are tied to the genuine website, so they simply refuse to work on a fake one, however convincing it looks. The US Cybersecurity and Infrastructure Security Agency recommends phishing-resistant methods, especially for administrators and high-risk accounts. Where your email, bank or work accounts offer passkeys, use them.
Why phishing is harder to spot on a phone
Many people now read most of their email and messages on a phone, and attackers design for it.
- Addresses are hidden. Mail apps often show only the sender's name, not the full address. Tap the name to reveal it.
- Links are harder to inspect. There is no hover, so press and hold to preview the address before opening anything.
- Screens are small. A lookalike domain is easy to miss when only part of it fits in the address bar.
- We read on the move, between meetings or while walking, which is exactly when careful checking slips.
A simple rule for your phone: if a message wants you to sign in or pay, close it and open the official app instead.
Phishing themes to watch for
The disguises change with the calendar and the news, but a handful of themes appear again and again, in every country.
- Account security alerts: "unusual sign-in", "your password expires", "verify your account".
- Deliveries and customs fees, especially around holidays and big shopping events.
- Tax refunds and government payments during tax season or after new schemes are announced.
- Invoices, receipts and payment failures aimed at people who handle money.
- Shared documents and e-signature requests that lead to fake sign-in pages.
- Job offers and HR messages, such as salary reviews or new policies to "acknowledge".
- Current events: disasters, elections, health scares and major sporting events.
How to protect yourself from phishing
Habits
- Go direct. For sign-ins and payments, use the app or a bookmark, never a link in an unexpected message.
- Verify requests through another channel, especially anything involving money, passwords or codes.
- Slow down on urgency. The more urgent a message feels, the more carefully you should check it.
- Never share codes or approve sign-ins you did not start.
Tools
- A password manager. It fills in passwords only on the exact site they belong to. If it does not offer to fill in, stop and check the address. See passwords your staff will remember.
- Passkeys and two-step verification on every important account.
- Updates for your operating system, browser and apps.
- Your email provider's protections and the browser's built-in warnings, which block many known phishing sites.
How to report phishing
| Where | How to report |
|---|---|
| Your email app | Use the "Report phishing" or "Report" option. In Gmail it is in the More menu next to Reply. |
| At work | Use your organization's report button, or forward the message to your IT or security team, then delete it. |
| Anywhere | Forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org. Report phishing websites to Google Safe Browsing. |
| United Kingdom | Forward emails to report@phishing.gov.uk and texts to 7726. |
| United States | Report to the FTC at reportfraud.ftc.gov. CISA also accepts phishing reports. |
| Other countries | If you lost money or data, report to your national service. Our online scams guide lists them for several countries, and Europol lists them for each EU member state. |
If you clicked, entered details or opened a file
- Stop. Close the page and do not enter anything else.
- Password entered? Change it from a trusted device, and anywhere you reused it. Check that two-step verification is still on and no new devices have been added.
- Code entered or sign-in approved? Tell the provider or your IT team at once so they can end the attacker's session.
- File opened? Disconnect from the network and get help before using the device again.
- Card or bank details? Call your bank on the number on your card.
- Report it, quickly and honestly. At work, a fast report can protect your colleagues.
Our step-by-step article clicked a phishing link at work? covers each situation in more detail.
Phishing and organizations
For organizations, phishing is the front door to account takeover, payment fraud and ransomware. No single control stops it, so it is handled in layers:
- Email authentication (SPF, DKIM and DMARC) makes it harder for attackers to send email pretending to be your domain.
- Filtering removes many known phishing messages before anyone sees them.
- Phishing-resistant sign-in for administrators and finance first, then everyone.
- People who spot and report. Short training and realistic practice turn staff into an early warning system. See how to run phishing simulations your staff won't resent.
CyberWatch AI helps organizations with the people layer: realistic phishing simulations, short training where it is needed, one-step reporting for every employee, and a security score that shows whether it is working.
Common myths about phishing
- "Phishing emails are full of spelling mistakes." Many are flawless, especially now that AI writes them.
- "The padlock means it's safe." Phishing sites use padlocks too.
- "It came from a real company address." Accounts get compromised, and display names are easy to fake.
- "I have two-step verification, so I'm safe." It helps enormously, but codes can be phished. Passkeys are stronger.
- "Only careless people fall for it." Well-crafted phishing catches experienced people on busy days. Reporting quickly matters more than never clicking.
Frequently asked questions
What is phishing in simple terms?
Phishing is a message designed to trick you into clicking a link, opening a file, entering details or making a payment by pretending to come from someone you trust. It can arrive by email, text message, phone call, social media or a messaging app.
How can I tell if an email is phishing?
Check the sender's actual address, not just the name. Look for urgency, threats or unusual requests, and check where links really go before clicking. If a message asks you to sign in or pay, go to the service yourself through its app or a bookmarked address instead of the link.
Is it dangerous to just open a phishing email?
Opening an email is usually low risk on an up-to-date device. The danger comes from clicking links, opening attachments, replying with information or calling numbers in the message. Delete or report it without interacting.
Does the padlock mean a link is safe?
No. The padlock only means the connection is encrypted. Phishing sites routinely use padlocks. Check the domain name in the address bar instead.
Can phishing get past two-step verification?
Some phishing pages pass your password and code to the real site in real time, so ordinary codes can be stolen. Phishing-resistant methods such as passkeys and security keys are designed to refuse to work on fake sites, which is why security agencies recommend them.
What should I do if I clicked a phishing link?
Close the page and do not enter anything more. If you entered a password, change it from a trusted device and anywhere you reused it. If you opened a file, disconnect from the network. Report it to your IT team or email provider straight away.
Where do I report a phishing email?
Use the report phishing button in your email app. You can also forward phishing emails to reportphishing@apwg.org, and in the UK to report@phishing.gov.uk. At work, report it to your IT or security team. Report phishing websites to Google Safe Browsing.
What is the difference between phishing, smishing and vishing?
They are the same trick through different channels. Phishing usually means email, smishing uses SMS text messages, and vishing uses voice calls. Many attacks combine them, for example a text followed by a call.
Why do password managers help against phishing?
A password manager fills in your password only on the exact website it was saved for. If it does not offer to fill in your details, the site may be a fake with a lookalike address. That hesitation is a useful warning.
Can CyberWatch AI check a phishing email or text?
Yes. Paste the message or link, or upload a screenshot, into CyberWatch AI Scan for free. It explains what looks suspicious and what to do next. It is a second opinion, so still verify anything important through an official channel.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Recognize and report phishing, US Cybersecurity and Infrastructure Security Agency
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- Phishing: Spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Reporting a scam email, UK National Cyber Security Centre
- Suspicious email actions, UK National Cyber Security Centre
- Report phishing, Anti-Phishing Working Group
- Avoid and report phishing emails, Gmail Help
- Report a phishing page, Google Safe Browsing
- Report cybercrime online, Europol


