What Is Phishing? A Plain-English Explanation
Phishing is a message that pretends to be from someone you trust to trick you into giving away passwords, money or access. A plain-English explanation with everyday examples and simple defences.

Phishing is a message that pretends to come from someone you trust, such as your bank, a delivery company, your email provider or your boss, in order to trick you into giving away something valuable: a password, a code, card details, money or access to your device. It is the most common way accounts are broken into and one of the most common starting points for fraud.
The three parts of every phish
| Part | What it is | Example |
|---|---|---|
| The lure | A believable reason to act | "Your parcel is on hold", "Unusual sign-in detected" |
| The hook | The thing you are asked to do | Click a link, open a file, call a number, reply with details |
| The catch | What the attacker gets | Your password, card number, a code, or malware on your device |
Everyday examples
hxxps://mail-storage-upgrade[.]net/loginhxxps://secure-bank-verify[.]coWhere phishing arrives
- Email, the classic route. See how to spot phishing emails.
- Text messages. See smishing.
- Phone calls. See vishing.
- QR codes. See QR code phishing.
- Social media, messaging apps and search adverts.
Simple defences that work
- Pause when a message creates urgency or fear.
- Go direct: open the app or type the website yourself, instead of using links.
- Never share codes or passwords because a message asked.
- Use two-step verification and, where possible, passkeys. See passkeys vs phishing.
- Report it, so others are protected.
Not sure about a message? Paste it into CyberWatch AI Scan for a free check.
For every type of phishing and how to respond, read our complete guide to phishing.
Frequently asked questions
Why is it called phishing?
It sounds like 'fishing': attackers cast out bait (a convincing message) and wait for someone to bite.
Is phishing only by email?
No. It also arrives by text message (smishing), phone call (vishing), QR codes, social media, messaging apps and fake adverts.
What is the best single defence?
Never act on a link, attachment or request in an unexpected message. Go to the organization yourself through its app or a website you type in.
Sources
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency


