What "phishing" actually is
Phishing (said like "fishing") is a stranger sending you a message while pretending to be someone you trust — your bank, a delivery company, your workplace, even a family member — so that you hand over something valuable.
Put it in the physical world. Someone knocks on your door in a convincing uniform and says there is a gas leak and they must come in right now. The uniform is fake. The urgency is fake. But in the moment, you open the door.
A phishing message is that same trick delivered to your phone. The "uniform" is a familiar logo and a sender name that looks right.
What they are actually after
Your password
They send you to a fake copy of a real login page. You type your password, and it goes to them instead of the company.
Your money
A fake invoice, a fake customs fee, a refund that needs your card details first. Usually a small, believable amount.
Your security code
The six digits your bank texts you. Handing that over is handing over the key. No real company will ever ask you for it.
Control of your device
They talk you into installing a program so they can "fix" a problem. Now they see your screen and everything you type.
The four ways it reaches you
The classic. A fake alert, receipt, or password reset.
Text message
Missed deliveries, unpaid tolls, "Hi Mum, this is my new number."
Phone call
Someone claiming to be your bank's fraud team, or technical support.
QR codes
A sticker stuck over the real code on a parking meter or a restaurant table.
The five warning signs
Nearly every scam message carries at least two of these. Spot two, and stop — you are almost certainly looking at a fake.
-
It is urgent, and there is a threat
"Your account closes in 24 hours." "Respond immediately or face legal action." Panic stops people thinking, so scammers manufacture it. Real organisations give you time and are happy for you to call them back.
If a message is rushing you, that is the scam.
-
You were not expecting it
A parcel you did not order. A refund you did not request. An invoice from a company you have never used. Unexpected, plus asking you to act, equals suspicious.
-
It asks for something no real company asks for
Your full password. The six-digit code texted to your phone. Payment in gift cards, crypto, or a transfer to a "safe account". Remote access to your computer. Every one of those is a scam, every time, no exceptions.
-
The sender's address is slightly wrong
The name says "Apple Support" but the address is
support@apple-account-verify.co. Scammers cannot use the real address, so they use one that looks close. Tap or hover the sender name to reveal the true address. -
The link does not go where it says
A button reading "Visit your bank" can point anywhere. On a computer, hover the link without clicking and the real address appears at the bottom of the screen. On a phone, press and hold it to preview.
Read an address from the left. Everything before the first single slash is the real destination.
[ the one habit that beats all of this ]
Never use the contact details inside the message. If "your bank" contacts you, close it and reach the bank the way you always would — the number on the back of your card, the app on your phone, the address you type yourself. A real message survives that check. A fake one cannot.
Take a real scam apart
Three scam messages, rebuilt safely. The orange ⚑ marks are the parts that give the game away — select one and the explanation appears underneath.
SIMULATED — every example below is a harmless recreation. The companies are invented. Nothing here is clickable.
We have detected unusual activity on your account originating from a device we do not recognise. For your protection, access has been temporarily limited.
Verify My Account Now
→ resolves to
▸ show the raw technical headers (optional — you do not need these)
Return-Path: <bounce-8827@mail-relay-04.vps-host-cheap.ru> Received: from mail-relay-04.vps-host-cheap.ru ([45.147.x.x]) From: "NorthPoint Bank Security" <security@northpoint-bank-alerts.com> Reply-To: recovery.dept.9931@gmail.com SPF: fail (domain does not authorise this sender) DKIM: none (message is not signed) DMARC: fail
Plain English: the mail was sent from a rented server in another country, the reply would go to a free Gmail address, and all three automatic authenticity checks failed. You never have to read this. The From address and the link told you the same thing in two seconds.
6 warning signs marked in this email.
Your package #DH4471 could not be delivered due to an
5 warning signs marked. The biggest one is not marked at all: were you expecting a parcel?
"Good afternoon, I'm calling from the fraud team at NorthPoint Bank. "
"To confirm I'm speaking to the account holder, "
"Now, your account has been compromised, so "
" And stay on the line, don't hang up."
5 warning signs marked. The fix never changes: hang up, wait five minutes, then dial the number printed on your bank card yourself.
> awaiting selection — choose any ⚑ mark above
Real or scam?
Eight messages. Some are genuine — the goal is not to distrust everything, it is to know the difference. You get an explanation either way.
You clicked it. Now what?
First: this happens to careful, intelligent people every day. Embarrassment makes people wait, and waiting is the only thing that genuinely makes it worse. Work down this list.
[ do these in order ]
-
Call your bank if money or card details were involved
Use the number on the back of your card. Say "I think I have been scammed" — banks have a team for exactly this, and acting within hours dramatically improves your chances of getting money back.
-
Change the password you typed in
From a different device if you can. If you used that same password anywhere else, change it there too. That is the step people skip, and it is how one mistake becomes five.
-
Turn on two-step login for that account
It means a stolen password alone is no longer enough to get in. In settings it is called "two-factor authentication", "2FA", or "two-step verification".
-
If you installed anything, or let someone control your screen
Disconnect from the internet, uninstall the program, and run a full scan with the security software already on the machine. Not confident doing that? Take it to a repair shop — this is a routine, unembarrassing request for them.
-
Warn the people it can spread to
Work account? Tell IT immediately — they will not be angry, they would far rather know in the first hour. Personal account? Tell family, because scammers use a stolen account to target the contacts inside it.
-
Report it
US: reportfraud.ftc.gov. UK: Action Fraud, and forward scam texts to 7726. Elsewhere, search for your country's national cyber security centre. Reporting is how these networks get shut down.
[ if you clicked but typed nothing ]
You are very probably fine. Simply opening a link or an email rarely does damage on a device that is kept up to date. The harm comes from what you enter afterwards. Do not panic — close it, and do not go back.
Four things that protect you in advance
Set these up once and most attacks simply stop working on you.
Turn on two-step login
The most valuable thirty minutes you will ever spend. Even with your password, a scammer cannot get in without the second step. Do your email account first — whoever controls your email can reset everything else you own.
Use a password manager
It remembers a different password for every site, so one leak cannot unlock the rest. It also quietly protects you from fake pages: it will not offer to fill in your password on a lookalike site, because it checks the address exactly.
Accept the updates
Those "update available" prompts are mostly repairs to holes criminals are already using. Switch on automatic updates for your phone, computer and browser, then stop thinking about it.
Agree a family safe word
Pick a word only your household knows. If a call or text claims to be a relative in trouble and needing money now, ask for the word. It defeats "Hi Mum, this is my new number" and AI voice-cloning alike.
[ and the one that costs nothing ]
Give yourself five minutes. Scams are engineered for someone reacting instantly. Almost nothing genuine is destroyed by waiting five minutes and checking through a channel you chose yourself. That single pause defeats the majority of what is on this page.
Questions people actually ask
The email had the correct logo. Doesn't that prove it's real?
No. A logo is a picture, and anyone can copy one off a website in seconds. Same for the layout, the colours, the small print, and the unsubscribe link. Scam messages are often pixel-perfect copies. Judge the sender address and the link, never the artwork.
It knew my name and the last four digits of my card. How?
Almost certainly from a data breach at some company you once used — those lists are bought and sold in bulk. It feels deeply personal, which is exactly why it works. Personal details prove your information leaked somewhere, not that the sender is genuine.
My phone showed my bank's actual number when they called.
Caller ID can be set to display any number the caller chooses, and nobody verifies it. That is why the advice is always to hang up and dial back yourself. On a landline, wait a minute or use a different phone first, because the original call can stay connected.
Isn't the padlock in the address bar a sign the site is safe?
It only means the connection is private, not that the owner is honest. Fake sites get that padlock in minutes, for free. A padlock on a scam page means your details are being sent to the criminal securely.
Why would anyone target me? I'm not rich or important.
You are not being targeted personally. These go out to millions of addresses at essentially zero cost, so a success rate of one in ten thousand is still profitable. It is not about you — which also means being caught says nothing about your intelligence.
The message was written perfectly. I thought scams had bad spelling.
That advice is out of date. Poor spelling used to be a filter the scammers wanted, because it weeded out cautious people early. Today plenty of scam messages are flawless. Good English is no reassurance at all — check the address and the link instead.
What if I reply just to ask whether it's real?
Don't. A reply confirms your address or number is live and read by a real person, which makes you more valuable and gets you more of them. It also starts a conversation, and conversations are where scammers do their best work. Delete it, then check with the company directly.
Someone I know sent me a strange link. Is their account hacked?
Very possibly, and it is worth telling them — through a different channel. Call them, or message them on another app. If the account really is compromised, the person replying to you in that chat may not be them.