Blog/Phishing

Phishing Myths That Put People at Risk

Common beliefs about phishing that leave people exposed, from spelling mistakes and padlocks to two-step verification and 'I would never fall for it', and what is actually true.

CyberWatch AI1 October 2026 · 2 min read
Letter tiles spelling the word email on a grey surface

Some of the most widespread beliefs about phishing are out of date or simply wrong, and they give people false confidence. Here are the common myths and what is actually true.

Myth: Phishing emails are full of spelling mistakes

Truth: many are fluent, especially with AI writing tools. See AI-written phishing.

Myth: The padlock means the site is safe

Truth: the padlock means the connection is encrypted, not that the site is honest. See does HTTPS mean safe?

Myth: Two-step verification makes me phishing-proof

Truth: codes and approvals can be relayed by fake sites in real time. Passkeys and security keys resist this. See why some two-step verification can be phished.

Myth: It came from a real company address, so it is real

Truth: display names are easily faked, lookalike domains are common, and real accounts get compromised. See reply-chain phishing.

Myth: I would never fall for it

Truth: careful, experienced people are phished when busy or when a message fits their routine. See why phishing works.

Myth: Opening an email infects your device

Truth: reading an email is generally safe. The risk comes from clicking links, opening attachments, or following instructions.

Myth: Phishing is only by email

Truth: it arrives by text, phone, QR codes, social media and search adverts. See types of phishing.

Myth: If I report it, I will get in trouble

Truth: good organizations want quick reports, even after a click. Speed limits damage. See why reporting quickly matters.

Want a second opinion on a message? Paste it into CyberWatch AI Scan for a free check.

For more, read our complete guide to phishing.

Frequently asked questions

Does a padlock mean a website is safe?

No. It means the connection is encrypted. Phishing sites commonly use padlocks too.

Does two-step verification stop all phishing?

No. Code-based methods can be phished in real time. Passkeys and security keys resist phishing much better.

Can I be phished on a Mac or iPhone?

Yes. Phishing targets people, not operating systems.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
  3. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.