← BACK TO PHISHING

How to Spot a Phishing Attack

Phishing is the #1 way people get hacked. Here's what to watch for and how to not take the bait.

What is phishing

Phishing is when someone pretends to be a company or person you trust to trick you into giving up passwords, credit card numbers, or access to your accounts. It usually comes through email, text, or a fake website.

It works because it preys on emotion — fear, urgency, curiosity. Not stupidity.

Red flags

  • Urgency or threats — “Your account will be closed in 24 hours!” Real companies don’t do this.
  • Generic greetings — “Dear Customer” instead of your actual name
  • Mismatched links — the text says paypal.com but the actual URL goes somewhere else. Hover before you click.
  • Spelling and grammar errors — big companies have editors. Scammers don’t.
  • Requests for sensitive info — no legitimate company will email you asking for your password or full SSN
  • Unexpected attachments — especially .zip, .exe, or macro-enabled Office files
  • Too good to be true — you didn’t win a lottery you didn’t enter

Common phishing scenarios

  • Fake bank alerts — “suspicious activity detected, click here to verify”
  • Package delivery — “UPS has a package for you, confirm your address”
  • Account verification — “your Netflix subscription is suspended, log in to restore”
  • Tech support — “we detected a virus on your PC, call this number”
  • Invoice scams — “attached invoice for your recent purchase” with a malicious attachment

How to verify

  1. Don’t click links in suspicious emails. Go directly to the website by typing the URL yourself.
  2. Check the sender’s actual email address, not just the display name.
  3. Look at the URL bar — paypal-secure-login.com is not paypal.com.
  4. If it’s a text from a “bank” you don’t use, it’s phishing.
  5. When in doubt, contact the company through their official website or app — not the contact info in the suspicious message.

What to do if you clicked

Don’t panic. Do this immediately:

  1. Change the password for the affected account — and anywhere else you reused it
  2. Enable two-factor authentication if it wasn’t on already
  3. Check for unauthorized activity — logins, transactions, new devices
  4. Report it — forward phishing emails to the FTC at reportphishing@apwg.org, and to the company being impersonated
  5. Run a malware scan if you downloaded anything

The bottom line

Phishing isn’t going away. The scams get more convincing every year. The single best defense is slowing down — don’t click first and think later. When something feels off, it probably is.