What is phishing?

    Phishing is a social-engineering attack that impersonates a trusted person or organization to steal information, money or access. It usually arrives as an email, text, call or direct message that creates pressure to open a link, sign in, pay, download a file or reveal sensitive details. The safest response is to pause, verify the request through a separate trusted channel and report any malicious website without interacting with it.

    14 min readUpdated September 20, 2026

    What is a phishing attack?

    A phishing attack is more than one suspicious message. It is a chain of deception designed to move a target from recognition to action. The attacker first chooses an identity the target is likely to trust: a bank, employer, delivery company, cloud-storage provider, government service, colleague or family member. The attacker then delivers a believable reason to act, such as an expiring password, disputed payment, shared document, missed parcel or security alert.

    The requested action creates the harm. A fake sign-in page captures a username, password and sometimes a one-time code. A malicious attachment installs software. A payment request redirects money to an attacker. A reply may reveal confidential business information. Some campaigns combine several stages: an email leads to a phone call, the caller asks the victim to install remote-access software, and the victim is then instructed to approve a bank transfer.

    Phishing succeeds by exploiting normal human habits rather than a technical flaw. Familiar branding reduces suspicion. Urgency discourages a second opinion. Authority makes a request feel mandatory. Curiosity makes an unexpected document tempting. A well-made message can contain correct spelling, a real logo and accurate personal context, so appearance alone is not proof.

    Broad campaigns send the same lure to many recipients. Spear phishing is tailored to a particular person or team. Voice phishing is called vishing, while deceptive text messages are commonly called smishing. The delivery channel changes, but the core method remains impersonation followed by a request that benefits the attacker.

    What is a phishing email?

    A phishing email is a deceptive message that appears to come from a legitimate sender. It may copy the colors and wording of a real service, spoof the visible sender name, or use a recently registered lookalike domain. The message normally asks the recipient to click, open, reply, pay or call.

    These three defanged examples show common patterns without providing working links:

    1. Account alert: “Unusual activity detected. Verify within 30 minutes at hxxps://secure-account-check[.]example.” The artificial deadline and unrelated registered domain are warning signs.
    2. Shared document: “A colleague shared Payroll Review.pdf. Sign in at hxxps://cloud-document-access[.]example.” The lure uses workplace context to collect Microsoft or Google credentials.
    3. Invoice change: “Our bank details changed. Please use the attached account for today's payment.” This business-email-compromise pattern may contain no link at all; the goal is an irreversible transfer.

    A legitimate organization can send an urgent message, and a phishing message can be calm and polished. Verify the request independently. Open the service from a saved bookmark or type its known address yourself. For workplace messages, contact the supposed sender using a known phone number or a fresh conversation rather than replying to the suspicious thread.

    Email headers add useful evidence. The display name is easy to fake, but the full From, Reply-To, Return-Path and authentication results show more of the route. SPF, DKIM or DMARC failure can support a phishing assessment, although a pass does not prove the content is safe: attackers can send from domains they legitimately control or from compromised accounts.

    What is a phishing text?

    A phishing text is a deceptive SMS, iMessage, WhatsApp, Signal, Telegram or other messenger message. The technique is often called smishing. Typical lures mention a missed delivery, unpaid road toll, bank alert, tax refund, job offer, account suspension or message from a senior employee.

    Text messages feel immediate, links are harder to inspect on a small screen, and sender names or conversation threads can create false familiarity. Attackers also rotate phone numbers quickly. A message appearing in an existing thread is not conclusive proof because sender identifiers can be spoofed in some networks and real accounts can be compromised.

    Do not reply, because a response confirms the number is active. Do not call a number supplied in the message. Use the number printed on a bank card, an official app, or an independently found official website. Take a screenshot, use the phone's spam-reporting function, notify the impersonated organization, and preserve the defanged destination for an infrastructure report.

    How to spot phishing emails

    No single sign proves an email is malicious, but several independent inconsistencies create a strong case. Use this checklist before interacting:

    1. Inspect the complete sender address. A familiar display name can hide an unrelated mailbox or lookalike domain.
    2. Compare Reply-To with From. An unexpected free-mail or unrelated reply address deserves scrutiny.
    3. Read the registered domain in every link. Ignore brand words placed in subdomains, paths or query strings.
    4. Pause at urgency or threats. Deadlines, penalties and fear are used to suppress careful verification.
    5. Question unexpected attachments. HTML files, archives, macro-enabled documents and disk images can lead to credential theft or malware.
    6. Check the request, not just the grammar. Modern phishing may be polished; an unusual request for secrets, payment or software is more important than spelling.
    7. Verify through a separate channel. Start a new call or chat using contact details you already trust.
    8. Use the official app or a saved bookmark. If the alert is real, it should normally appear there too.
    9. Look at authentication and routing clues. Header failures, unusual sending systems and mismatched domains add evidence.
    10. Protect credentials and one-time codes. A real support agent should not ask you to disclose a password or forward an authentication code.

    For a deeper field checklist, see how to identify phishing emails and practical phishing examples.

    What to do if you clicked

    Clicking does not always mean an account is compromised. What happened after the click determines the response. Disconnect from the page and record the URL. If you entered a password, change it immediately from a clean device and change it anywhere else it was reused. Sign out other sessions, review recovery addresses and enable multi-factor authentication.

    If you entered card or bank details, contact the financial institution using an official number and explain exactly what was submitted. Ask about blocking the card, monitoring transactions, recalling a transfer or placing an account alert. If you disclosed an identity document, follow the identity-theft guidance for your jurisdiction and monitor affected accounts.

    If you downloaded or opened a file, stop using the device for sensitive activity. Disconnect it from networks if malware is suspected, inform the workplace security team when relevant, and run the organization's approved security tools. Do not wipe the device before preserving evidence if an incident-response team needs to investigate it.

    Save the original message, headers, screenshots and approximate times. Report the sender through the mail or messaging platform, notify the impersonated organization, and report the malicious site so other people can be protected.

    How to report a phishing website

    Preserve the exact URL, including its path and query string, but do not revisit it from an everyday device. Save a screenshot with the address visible, keep the original email or text, and note which brand or service was impersonated. Never include passwords, card details, identity documents or another victim's personal information in a public description.

    Report the message to the provider that delivered it. Browser and security-list reports help warn visitors. An infrastructure report to the hosting provider or registrar addresses the site itself. Fraudpol accepts a phishing website report, checks the evidence and coordinates through legitimate abuse channels after analyst confirmation.

    A report should distinguish what was observed from what is inferred. State that a page displayed a copied sign-in form, identify where the form submitted data if safely established, and include timestamps. Avoid claims about the operator's identity unless supported by evidence.

    Phishing we have neutralized

    These records come from Fraudpol's public case data. Domains are defanged so they cannot be opened by accident, and retrospectively entered cases are excluded from elapsed-time figures.

    No matching public case records are available right now.

    View all confirmed cases

    Have a URL to report right now?

    Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report a phishing website

    Frequently asked questions

    What is phishing?

    Phishing is a social-engineering attack in which someone impersonates a trusted person or organization to make a target reveal credentials, payment details or other valuable information, install malware, or send money.

    What is a phishing attack?

    A phishing attack is the full operation behind a deceptive message: impersonation, delivery by email, text, call or direct message, a requested action, and often a fake website or malicious attachment that captures information.

    What is a phishing link?

    A phishing link is a URL that leads to a deceptive or malicious destination. It may imitate a legitimate login page, redirect through several domains, or use a lookalike spelling to hide who controls the destination.

    What is a phishing text?

    A phishing text is a deceptive SMS or messenger message, often called smishing, that uses urgency or a familiar brand to make the recipient open a link, call a number, disclose information or install an app.

    What is a phishing scam?

    A phishing scam is fraud carried out through impersonation and deception. The scam may seek passwords, card details, identity documents, money transfers, gift cards, cryptocurrency or access to a device.

    How do you spot a phishing email?

    Check the real sender address, the registered domain in every link, unexpected urgency, unusual requests, attachment type, reply-to address, authentication warnings and whether the same request appears in the organization's official app or website.

    What does phishing mean?

    Phishing means using a deceptive message or website as bait to obtain information, money or access. The spelling reflects the idea of fishing for victims with convincing lures.