Phishing
In plain terms
An email that looks like it's from your bank, the tax office, or a service you use asks you to log in. The link leads to a copy of the site, and whatever you type there goes straight to the scammer.
Definition
Phishing is a fraudulent message that imitates a legitimate sender — a bank, government agency, online service, or employer — to obtain credentials, banking details, or get a malicious attachment opened. Email is its most common channel; SMS, phone calls, and QR codes are variants covered separately.
How it works
The mechanism is the same regardless of the channel: imitate a trusted sender, manufacture a reason to act fast, and provide a path — a link, a number, an attachment — that bypasses verification. By email, the most common form, this looks like the following. The attacker sends a message reusing a known organization's visual identity: logo, layout, familiar tone. The message announces a problem to fix urgently (suspended account, unpaid invoice, held package) and offers a link. That link leads to a login page imitating the official site. Everything entered there goes straight to the attacker, who uses it immediately to log into the real service.
Warning signs
- Sender address that doesn't match the organization's official domain
- Request to "confirm" or "verify" credentials via a link
- Urgency or threat of immediate consequences (suspension, penalty)
- Impersonal wording ("Dear customer") when the organization knows your name
- Unexpected attachment, especially a file to enable or authorize
How to verify
Don't use the link in the message. Open your browser and reach the service through a path you control: a saved bookmark, the official app, or an address you type yourself. If the message was genuine, the information will be there too.
What to do
Don't click, don't reply, don't download the attachment. Report the message as phishing in your mail client, then delete it.
If it already happened
Immediately change the password of the affected account, then any other account reusing the same password. Enable two-factor authentication. If banking details were entered, contact your bank without delay. Report the incident to the relevant authority.
Test yourself
A polished email asks you to "re-verify" your access before your account is closed.
Start the simulationFrequently asked questions
- How can I tell a real email from my bank from a fake one?
- A bank never asks for your full credentials, your PIN, or a code received by SMS, regardless of the channel. If in doubt, don't use the link: go through the official app or the number on the back of your card.
- Is it dangerous to have simply opened the email?
- Opening an email is rarely enough to compromise a device on its own. The risk comes from what happens next: clicking the link, entering information, or opening an attachment.
- I clicked the link but didn't type anything — what should I do?
- The main risk stays limited if no information was entered and no file was downloaded. As a precaution, check the account's recent activity and change its password.
Related attacks
- Smishing (SMS phishing)
- Typosquatting
- Credential stuffing
- Homoglyph attack
- Fake refund
- Fake wire transfer order (CEO fraud)
- Fake bank details change
- Quishing (fraudulent QR code)
- Fake invoice
- Vishing (voice phishing)
- Baiting
- Fake website
- AI-generated phishing
- Data breach
- Ransomware
- Computer Virus
- Malicious Captive Portal
Official sources
This article is part of the Social engineering family. Last updated: 2026-08-31.