Phishing is a type of scam that tries to make you trust a message long enough to click, reply, open something or give away information.
The message might arrive by email, text message, social media, chat app or another communication service. It may pretend to come from a bank, delivery company, school, workplace, government service, online store, friend or family member.
Modern phishing can look convincing. A message does not need bad spelling, strange colours or an obviously fake logo to be dangerous.
The most useful habit is simple:
Pause before you act, then verify important requests through a route you already trust.
What is phishing?
Phishing is an attempt to trick you into doing something that benefits a scammer.
The scammer may want you to reveal a password, payment information, bank details, a verification code or other personal information.
They may also try to persuade you to open a harmful attachment, visit a fake website or install software.
The message is the bait. Your reaction is what the scammer is trying to control.
1. Be careful with unexpected urgency
Many phishing messages try to make you act before you have time to think.
You might be told that your account will be locked, a payment failed, a delivery cannot be completed, a refund is waiting or someone has logged into your account.
Some messages use fear. Others use excitement, curiosity or the fear of missing out.
Urgency does not prove that a message is fake. Real organisations sometimes send urgent notices.
It is a reason to slow down and verify before acting.
2. Be suspicious of unexpected requests for information
A phishing message may ask for information that should be treated carefully.
Examples include passwords, bank details, card information, verification codes, account recovery information or personal identity details.
A message may say that you need to confirm your identity or update your account.
Do not provide sensitive information simply because a message looks official.
If the request might be real, independently open the organisation's official website or app and check there.
3. Do not trust a message just because it looks professional
Older scam messages were often easy to notice because of poor spelling, strange layouts or obvious mistakes.
That is no longer a reliable test.
Modern scams can use professional writing, familiar logos, realistic account names and convincing layouts.
Some may even include personal information about you.
A polished message can still be fraudulent.
4. Check what the message wants you to do
Focus on the action being requested.
Does the message want you to click a link, open an attachment, call an unfamiliar number, reply with information, approve a login or send money?
These actions deserve extra attention when the message was unexpected.
Instead of asking only, "Does this message look real?" ask:
"Can I safely verify this request without using anything supplied in the message?"
5. Be cautious with links
A link can send you somewhere different from where you expect.
The visible words in a message may mention a familiar company while the actual destination belongs to someone else.
On some devices you can inspect a destination before opening it, but examining links is not a perfect safety test. Fake addresses can still be designed to look convincing.
For important accounts, a safer habit is to open the service yourself.
Use your normal bookmark, trusted app or an address you already know instead of entering through an unexpected message.
6. Treat unexpected attachments carefully
Attachments can be used to deliver harmful software or lead you into another scam.
A file may pretend to be an invoice, receipt, delivery notice, document, photo or form.
If you were not expecting the attachment, verify it with the sender through another trusted route before opening it.
Do not assume a file is safe simply because it appears to come from someone you know. A compromised account can be used to send malicious messages to real contacts.
7. Verify the sender independently
If a message claims to come from an organisation, do not rely on the contact information inside that message when you are trying to confirm whether it is genuine.
Find the organisation's official website yourself, use its official app, use a phone number printed on a trusted statement or card, or use another contact method you already know.
If the message appears to come from a friend, relative or colleague, contact that person separately.
This simple step breaks an important part of the scam because the attacker no longer controls the communication route.
8. Watch for unusual payment or account requests
Be especially careful when a message asks you to make a payment, change bank details, buy gift cards, send money, provide a security code or approve an unexpected sign in.
A familiar name is not enough proof.
Verify unusual financial and account requests independently before taking action.
9. QR codes can also be used for phishing
Phishing does not require a normal clickable link.
A scam message can include a QR code that takes your phone to a fake website.
The same rule applies: do not assume the destination is safe because the message looks official.
For an important service, open the official website or app yourself.
10. New scam techniques keep appearing
Phishing tactics continue to change.
For example, the FTC warned in 2026 about fake CAPTCHA screens that tell people to run commands on their computers. A genuine CAPTCHA should not require you to open a command window and run copied commands.
This is why memorising a list of old scam tricks is not enough.
The stronger skill is learning to pause when an unexpected message asks you to take a risky action.
A simple phishing check
When a message feels unusual, use these questions.
- Was I expecting this message?
- Is it creating pressure to act quickly?
- Is it asking for sensitive information?
- Does it want me to click a link or open a file?
- Does it ask for money, a code or an account change?
- Can I verify the request using a trusted route instead?
You do not need to prove that a message is phishing before deciding not to interact with it.
If you are unsure, verify first.
Worked example: the urgent account warning
Imagine receiving a message that says your streaming account will be suspended today because your payment failed.
The message includes a button labelled "Update payment now."
Do not use the button.
Instead:
- Pause and do not reply.
- Open the real service using its trusted app, bookmark or known website.
- Check the account directly for any genuine warning.
- If necessary, contact customer support using details from the official service.
- Report or delete the suspicious message as appropriate.
This method works even when the phishing message looks convincing.
What if the message really was genuine?
That is fine.
Opening the legitimate service yourself should still allow you to see a genuine account problem or notification.
You lose very little by checking independently.
You may prevent a serious problem by refusing to let an unexpected message choose where you log in or who you contact.
What if you already clicked?
Do not panic, but take the situation seriously.
If you only opened a page and did not provide information, close it and avoid further interaction.
If you downloaded something, follow trusted device security guidance and scan the device where appropriate.
If you entered a password on a suspicious page, change that password through the real service. If the same password was reused elsewhere, replace it there too.
If you supplied financial information, contact the relevant financial institution using official contact information.
If an account may have been compromised, review its security settings and active sessions.
Report suspicious messages when appropriate
Reporting can help service providers and security organisations investigate malicious messages and websites.
The exact reporting method depends on your country and the service you use.
Email providers, messaging platforms, banks and other organisations often provide a built in report option.
Use official local reporting services where appropriate.
The main idea
You do not need to become an expert at identifying every fake logo, domain name or technical trick.
Instead, develop a repeatable habit:
Pause. Check the request. Verify through a trusted route. Then act.
This approach is useful because phishing methods change, but the scammer still needs you to take an action.
Quick phishing safety checklist
- Pause when a message creates urgency or fear.
- Be careful with unexpected links and attachments.
- Do not provide passwords or verification codes because a message asks for them.
- Open important services independently.
- Verify unusual requests using contact details you already trust.
- Be cautious with unexpected payment requests.
- Remember that professional looking messages can still be fake.
- Report suspicious messages through appropriate official channels.
Related HubEgg learning
For a wider online safety framework, read Complete Guide to Staying Safe Online.
If a phishing attempt is trying to steal a password, the guidance in How Strong Passwords and Passphrases Work explains why unique passwords can limit the damage if one credential is exposed.