Phishing Myths That Put People at Risk
Common beliefs about phishing that leave people exposed, from spelling mistakes and padlocks to two-step verification and 'I would never fall for it', and what is actually true.

Some of the most widespread beliefs about phishing are out of date or simply wrong, and they give people false confidence. Here are the common myths and what is actually true.
Myth: Phishing emails are full of spelling mistakes
Truth: many are fluent, especially with AI writing tools. See AI-written phishing.
Myth: The padlock means the site is safe
Truth: the padlock means the connection is encrypted, not that the site is honest. See does HTTPS mean safe?
Myth: Two-step verification makes me phishing-proof
Truth: codes and approvals can be relayed by fake sites in real time. Passkeys and security keys resist this. See why some two-step verification can be phished.
Myth: It came from a real company address, so it is real
Truth: display names are easily faked, lookalike domains are common, and real accounts get compromised. See reply-chain phishing.
Myth: I would never fall for it
Truth: careful, experienced people are phished when busy or when a message fits their routine. See why phishing works.
Myth: Opening an email infects your device
Truth: reading an email is generally safe. The risk comes from clicking links, opening attachments, or following instructions.
Myth: Phishing is only by email
Truth: it arrives by text, phone, QR codes, social media and search adverts. See types of phishing.
Myth: If I report it, I will get in trouble
Truth: good organizations want quick reports, even after a click. Speed limits damage. See why reporting quickly matters.
Want a second opinion on a message? Paste it into CyberWatch AI Scan for a free check.
For more, read our complete guide to phishing.
Frequently asked questions
Does a padlock mean a website is safe?
No. It means the connection is encrypted. Phishing sites commonly use padlocks too.
Does two-step verification stop all phishing?
No. Code-based methods can be phished in real time. Passkeys and security keys resist phishing much better.
Can I be phished on a Mac or iPhone?
Yes. Phishing targets people, not operating systems.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre


