Blog/Phishing

What Is Phishing? A Plain-English Explanation

Phishing is a message that pretends to be from someone you trust to trick you into giving away passwords, money or access. A plain-English explanation with everyday examples and simple defences.

CyberWatch AI30 September 2026 · 2 min read
A red fishing hook hanging against a grey background

Phishing is a message that pretends to come from someone you trust, such as your bank, a delivery company, your email provider or your boss, in order to trick you into giving away something valuable: a password, a code, card details, money or access to your device. It is the most common way accounts are broken into and one of the most common starting points for fraud.

The three parts of every phish

PartWhat it isExample
The lureA believable reason to act"Your parcel is on hold", "Unusual sign-in detected"
The hookThe thing you are asked to doClick a link, open a file, call a number, reply with details
The catchWhat the attacker getsYour password, card number, a code, or malware on your device

Everyday examples

Illustrative example · Email
Your mailbox storage is 98% full. Emails will stop arriving in 24 hours. Upgrade your storage for free: hxxps://mail-storage-upgrade[.]net/login
The catch: a fake login page that collects your email password.
Illustrative example · Text message
BANK ALERT: A payment of 740.00 was attempted from your account. If this was not you, secure your account now: hxxps://secure-bank-verify[.]co
The catch: your banking login and a one-time code.

Where phishing arrives

Simple defences that work

  1. Pause when a message creates urgency or fear.
  2. Go direct: open the app or type the website yourself, instead of using links.
  3. Never share codes or passwords because a message asked.
  4. Use two-step verification and, where possible, passkeys. See passkeys vs phishing.
  5. Report it, so others are protected.

Not sure about a message? Paste it into CyberWatch AI Scan for a free check.

For every type of phishing and how to respond, read our complete guide to phishing.

Frequently asked questions

Why is it called phishing?

It sounds like 'fishing': attackers cast out bait (a convincing message) and wait for someone to bite.

Is phishing only by email?

No. It also arrives by text message (smishing), phone call (vishing), QR codes, social media, messaging apps and fake adverts.

What is the best single defence?

Never act on a link, attachment or request in an unexpected message. Go to the organization yourself through its app or a website you type in.

Sources

  1. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
  2. Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
  3. Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.