Skip to content

Phishing

In plain terms

An email that looks like it's from your bank, the tax office, or a service you use asks you to log in. The link leads to a copy of the site, and whatever you type there goes straight to the scammer.

Definition

Phishing is a fraudulent message that imitates a legitimate sender — a bank, government agency, online service, or employer — to obtain credentials, banking details, or get a malicious attachment opened. Email is its most common channel; SMS, phone calls, and QR codes are variants covered separately.

How it works

The mechanism is the same regardless of the channel: imitate a trusted sender, manufacture a reason to act fast, and provide a path — a link, a number, an attachment — that bypasses verification. By email, the most common form, this looks like the following. The attacker sends a message reusing a known organization's visual identity: logo, layout, familiar tone. The message announces a problem to fix urgently (suspended account, unpaid invoice, held package) and offers a link. That link leads to a login page imitating the official site. Everything entered there goes straight to the attacker, who uses it immediately to log into the real service.

Warning signs

  • Sender address that doesn't match the organization's official domain
  • Request to "confirm" or "verify" credentials via a link
  • Urgency or threat of immediate consequences (suspension, penalty)
  • Impersonal wording ("Dear customer") when the organization knows your name
  • Unexpected attachment, especially a file to enable or authorize

How to verify

Don't use the link in the message. Open your browser and reach the service through a path you control: a saved bookmark, the official app, or an address you type yourself. If the message was genuine, the information will be there too.

What to do

Don't click, don't reply, don't download the attachment. Report the message as phishing in your mail client, then delete it.

If it already happened

Immediately change the password of the affected account, then any other account reusing the same password. Enable two-factor authentication. If banking details were entered, contact your bank without delay. Report the incident to the relevant authority.

Test yourself

A polished email asks you to "re-verify" your access before your account is closed.

Start the simulation

Frequently asked questions

How can I tell a real email from my bank from a fake one?
A bank never asks for your full credentials, your PIN, or a code received by SMS, regardless of the channel. If in doubt, don't use the link: go through the official app or the number on the back of your card.
Is it dangerous to have simply opened the email?
Opening an email is rarely enough to compromise a device on its own. The risk comes from what happens next: clicking the link, entering information, or opening an attachment.
I clicked the link but didn't type anything — what should I do?
The main risk stays limited if no information was entered and no file was downloaded. As a precaution, check the account's recent activity and change its password.

Official sources

This article is part of the Social engineering family. Last updated: 2026-08-31.