What Is Phishing?
Phishing is a social engineering attack where criminals send fraudulent emails, messages, or texts that appear to come from legitimate organizations or people you know. The goal is usually to trick you into:
- Clicking a malicious link
- Downloading a dangerous attachment
- Entering your personal information or credentials
- Sending money or gift cards
- Revealing sensitive information about your employer
Phishing attacks are effective because they exploit our trust. They often feel urgent and personal, making us more likely to act quickly without thinking critically about what we're doing.
Red Flags: Signs of a Phishing Email
While phishing emails can be sophisticated, most contain at least one warning sign. Learn to spot these common red flags:
Unexpected Requests for Information
Legitimate companies rarely ask for sensitive information via email. Be suspicious of any message asking you to:
- Confirm your password or username
- Verify your banking details or credit card number
- Click a link to "update" your account
- Provide your social security number
- Confirm your address or phone number "for security"
If you receive such a request, go directly to the company's official website (type the address yourself—don't click links in the email) and log into your account to check if action is needed.
Urgency and Pressure
Phishing emails often create a false sense of urgency to bypass your critical thinking. Watch for language like:
- "Your account will be closed in 24 hours"
- "Urgent action required immediately"
- "Unusual activity detected on your account"
- "Your payment method has expired"
- "Click here now before it's too late"
Scammers want you to panic and click before you have time to verify whether the message is real. Legitimate security alerts usually give you reasonable time to respond.
Suspicious Links and Misleading URLs
One of the most common phishing tactics is including links that look legitimate but actually go to fake websites. Here's how to check:
- Hover (don't click): Move your mouse over the link to see where it actually goes (most email clients show this at the bottom of the screen)
- Look for misspellings: Fake URLs often use similar but slightly different addresses (applepay.verify.com instead of apple.com)
- Check for HTTPS: The website should start with "https://" (the 's' means encrypted/secure)
- Be wary of IP addresses: Legitimate links usually have a domain name, not just numbers like "http://192.168.1.1"
Poor Grammar and Spelling
While phishing emails are increasingly polished, many still contain grammar or spelling errors. This often happens because they're sent in bulk or translated from other languages. Examples include:
- Awkward phrasing like "Please to confirm your information"
- Inconsistent capitalization or punctuation
- Misspelled company names or words
Professional companies proofread their communications. Errors are usually a red flag.
Generic or Unusual Greetings
Many phishing emails start with generic greetings because scammers don't know your real name:
- "Dear Valued Customer"
- "Dear User"
- "Hello there"
Legitimate emails from companies you do business with usually include your actual name, as they have this information in their systems.
Suspicious Attachments
Never open attachments from unexpected sources. Common malicious attachment types include:
- .exe files (executable programs)
- .zip or .rar archives (which may contain hidden malware)
- Documents with macro-enabled formats (.docm, .xlsm)
Even if an attachment appears to come from someone you know, be cautious if you weren't expecting it. It's safe to ask the sender via phone or another method to confirm they sent it.
How to Verify a Sender's Address
Scammers often create email addresses that look similar to legitimate companies. Here's how to check the real sender:
- Check the full email address: Not just the display name. A message might show "Amazon Support" but come from randomname@phishing-site.com
- Verify the domain: The part after the @ symbol should be the official company domain (amazon.com for Amazon, not amazom.com)
- Look for official company domains: Be aware of the real domain names of companies you do business with
- Use your email client's verification features: Some email services show a checkmark or verified badge for legitimate senders
Fake Login Pages
A common phishing tactic is getting you to click a link that takes you to a fake website designed to look exactly like the real service. If you log in, your credentials go straight to the scammers.
Before entering your username and password anywhere:
- Check the URL in your browser's address bar (not the link text in the email)
- Look for HTTPS and a lock icon
- Notice any unusual differences in the website's appearance
- If you're unsure, close the page and go directly to the company's website by typing the address yourself
What to Do Before Clicking Anything
When you receive a suspicious email, follow these steps before taking any action:
- Stop and think: Did you expect this email? Is the timing unusual?
- Check the sender's address: Verify it's from the legitimate organization
- Look for red flags: Urgency, requests for information, suspicious links
- Hover over links (don't click): See where they actually lead
- Call the company directly: Use a phone number from your records or the official website—not from the email
- Go directly to the website: Log into your account by typing the address yourself to see if action is needed
What to Do After Accidentally Clicking
If you've clicked a suspicious link or downloaded an attachment, don't panic. Here's what to do:
- Close the page immediately: Stop and don't enter any information
- Don't download or open anything: Stop any downloads and close any opened files
- Run a security scan: Use your computer's built-in security tools or trusted antivirus software to scan for malware
- Change your passwords: If you entered credentials anywhere, change those passwords immediately, starting with your email
- Enable two-factor authentication: Add this extra layer of security to critical accounts if you haven't already
- Monitor your accounts: Watch for suspicious activity in your bank, credit card, and email accounts
- Consider a credit freeze: If you provided financial information, you may want to place a fraud alert with credit bureaus
- Report it: Forward the email to the company's abuse/phishing report address (usually abuse@company.com)
Quick Phishing Awareness Checklist
Frequently Asked Questions
Is it safe to hover over links without clicking them?
Yes, hovering over links is safe. Hovering simply displays the URL in most email clients and doesn't interact with the link. However, clicking is what activates the link and takes you to the destination.
What should I do if I provided my password to a phishing site?
Change your password immediately on the real website. If you used the same password on other accounts, change those too. Enable two-factor authentication if available. If it's your email or banking password, consider changing passwords on related accounts as well.
Should I reply to phishing emails to tell them to stop?
No. Replying confirms to scammers that your email address is active, which leads to more phishing attempts. Simply delete the email or use your email client's report phishing/spam feature.
Can phishing happen through text messages or social media?
Yes. Phishing isn't limited to email. Criminals also send suspicious text messages (called "smishing") and direct messages on social media. The same principles apply: be suspicious of unexpected messages, verify sender information, and don't click links from untrusted sources.
How can I report phishing emails?
Most email services have a built-in report phishing or report spam option (usually in the email menu). You can also forward suspicious emails to the real company's abuse email address. Your email provider uses these reports to improve their spam filters.
Conclusion
Phishing attacks succeed because they exploit our trust and sense of urgency. By learning to recognize red flags—unusual requests, pressure tactics, suspicious links, and sender address issues—you can avoid most phishing attempts.
Remember: legitimate companies rarely ask for sensitive information via email, and it's always safe to verify requests by going directly to the official website or calling the company's main phone number. Taking a few extra seconds to think before clicking can protect you from serious consequences.