What Is Phishing? And How to Spot It Before You Fall for It
📷 Gustavo Fring · Pexels✦ Key takeaways
- Phishing is an attack that relies on tricking you psychologically, not on a technical hack.
- It impersonates a trusted party (bank, company, colleague) to steal passwords or money.
- Its signs: manufactured urgency, language errors, suspicious links, requests for sensitive data.
- Protection: verify the sender, don't click suspicious links, and enable two-factor authentication.
Phishing is a type of cyberattack that relies on deception rather than technical hacking. The attacker sends a message that appears to come from a trusted source — your bank, a shipping company, a platform you know, or even a colleague — to push you into revealing sensitive data like a password or card number, transferring money, or downloading a malicious file. The name comes from "fishing": the attacker casts bait to a large audience and waits for someone to bite.
The core of the trick is psychological: the attacker creates a sense of urgency, fear, or greed to make you act fast without thinking. "Your account will be closed within an hour," "You have a pending transfer," "You've won a prize." When you rush, you stop noticing the details that would expose the scam.
🌐 Download Time
How long any file takes to download at your speed — instantly.
Phishing takes several forms depending on channel and target. The table below shows the main ones:
| Type | Channel | Target |
|---|---|---|
| Bulk phishing | Mass email | Any victim who falls for it |
| Spear phishing | Email tailored to a person | A specific employee or official |
| Whaling | Messages to top executives | A CFO or CEO |
| Smishing | SMS text messages | Links or codes |
| Vishing | Phone calls | Impersonating support or a bank |
How do you spot a phishing message? Look for these signs: a strange sender address that doesn't exactly match the organization (an extra letter or a different domain), unusual urgency or threats, language errors or poor design, a link that doesn't match the text when you hover over it, and a request for sensitive data that serious institutions never ask for by email anyway (a full password or a verification code).
A practical example: you get an email "from the bank" saying there was a suspicious login attempt, asking you to "confirm your identity" via a link. The link takes you to a page that looks exactly like the bank's site but has a slightly different address. The moment you enter your details, they go straight to the attacker. The golden rule: never enter your data through a link in a message; open the bank's site yourself from the browser or official app.
To protect yourself, follow simple habits: verify the sender before any interaction, don't click unexpected links or attachments, never share verification codes (OTPs) with anyone no matter what they claim, enable two-factor authentication (2FA) on important accounts so a password alone isn't enough to break in, and when in doubt contact the organization through its known official channel — not through the details in the message itself.
Bottom line: phishing targets the human, not the device, which is why the strongest defense isn't software but your awareness and patience. Remember that sudden urgency and a request for sensitive data are the two clearest danger signs — and when you slow down and verify, most phishing attempts fall apart on their own.
