← BACK TO PHISHING
How to Spot a Phishing Attack
Phishing is the #1 way people get hacked. Here's what to watch for and how to not take the bait.
What is phishing
Phishing is when someone pretends to be a company or person you trust to trick you into giving up passwords, credit card numbers, or access to your accounts. It usually comes through email, text, or a fake website.
It works because it preys on emotion — fear, urgency, curiosity. Not stupidity.
Red flags
- Urgency or threats — “Your account will be closed in 24 hours!” Real companies don’t do this.
- Generic greetings — “Dear Customer” instead of your actual name
- Mismatched links — the text says
paypal.combut the actual URL goes somewhere else. Hover before you click. - Spelling and grammar errors — big companies have editors. Scammers don’t.
- Requests for sensitive info — no legitimate company will email you asking for your password or full SSN
- Unexpected attachments — especially .zip, .exe, or macro-enabled Office files
- Too good to be true — you didn’t win a lottery you didn’t enter
Common phishing scenarios
- Fake bank alerts — “suspicious activity detected, click here to verify”
- Package delivery — “UPS has a package for you, confirm your address”
- Account verification — “your Netflix subscription is suspended, log in to restore”
- Tech support — “we detected a virus on your PC, call this number”
- Invoice scams — “attached invoice for your recent purchase” with a malicious attachment
How to verify
- Don’t click links in suspicious emails. Go directly to the website by typing the URL yourself.
- Check the sender’s actual email address, not just the display name.
- Look at the URL bar —
paypal-secure-login.comis notpaypal.com. - If it’s a text from a “bank” you don’t use, it’s phishing.
- When in doubt, contact the company through their official website or app — not the contact info in the suspicious message.
What to do if you clicked
Don’t panic. Do this immediately:
- Change the password for the affected account — and anywhere else you reused it
- Enable two-factor authentication if it wasn’t on already
- Check for unauthorized activity — logins, transactions, new devices
- Report it — forward phishing emails to the FTC at reportphishing@apwg.org, and to the company being impersonated
- Run a malware scan if you downloaded anything
The bottom line
Phishing isn’t going away. The scams get more convincing every year. The single best defense is slowing down — don’t click first and think later. When something feels off, it probably is.