What Is Phishing and How Do You Spot It?

Phishing is when someone pretends to be a trusted organisation in order to get you to hand over information — passwords, bank details, personal information — or to click a link that installs malware. It is one of the most common forms of online fraud and it does not require any technical sophistication on the attacker’s part.

What Phishing Looks Like

Most phishing arrives by email, but it also comes via text message (sometimes called smishing), phone calls (vishing), and increasingly through messaging apps.

A typical phishing email claims to be from a recognisable organisation: a bank, HMRC, Royal Mail, Amazon, PayPal, or a streaming service. The message creates urgency: your account has been suspended, there is an undelivered parcel, you owe tax, your payment failed. You are asked to click a link and log in.

The link goes to a page that looks like the real website but is controlled by the attacker. When you enter your credentials, they are captured. Sometimes there is a second step asking for payment details or personal information.

Warning Signs

Urgency and pressure — Phishing messages typically try to make you act quickly before you think carefully. Legitimate organisations rarely threaten immediate suspension without warning or demand action within hours.

The sender address does not match the organisation — Look at the actual email address, not just the display name. A message appearing to be from Amazon might come from a domain like amazon-support.com or amaz0n.net. The display name can say anything; the domain is harder to fake convincingly.

The link does not go where it says — Hover over a link (on desktop) before clicking to see the actual URL. A link that says paypal.com but shows a different URL in the status bar is a red flag. On mobile, press and hold a link to see its destination.

Generic greeting — Phishing emails often use Dear Customer or Dear User because the attackers do not know your name. Your bank and most services you have an account with know your name.

Requests for sensitive information by email — Legitimate organisations do not ask you to email them your password, national insurance number, or full payment details.

What to Do If You Clicked

If you clicked a link but did not enter any information, the risk is lower but not zero. Run a malware scan on your device.

If you entered a password, change it immediately on the real website — use the address you know, not any link from the suspicious email. If you use the same password elsewhere, change it on those accounts too. Enable two-factor authentication if you have not already.

If you entered payment details, contact your bank. They can flag the card for fraud monitoring or issue a replacement.

Reporting Phishing

In the UK, you can forward phishing emails to [email protected], which is run by the National Cyber Security Centre. Suspicious texts can be forwarded to 7726. Reporting helps identify and take down phishing sites faster.

Phishing works because it exploits trust and creates pressure. Slowing down and checking before clicking is the most effective defence.