Phishing
Phishing is the technique of tricking you with a fake message that looks like it comes from a trusted institution, to capture your password or details. It is not a technical attack but a deception — so the defence rests not on technology but on recognising patterns.
Foundation · 12 min
In this lesson you will learn
- Explain what phishing is and why it is so widespread
- Recognise the shared patterns of fake messages
- Apply the right response sequence to a suspicious message
- Know the damage-limitation steps if you have been caught
An attack on people, not technology
Phishing is the method by which the attacker targets not systems but you directly: they send a message that looks like your bank, a courier firm, the tax office or a service you use, and pull you onto a fake page where you hand over your password, card details or verification code with your own hands. It is widespread because it is cheap and it works: if even a small percentage of thousands of recipients fall for a message, the attacker profits. Nor is email the only channel: SMS, messaging apps and phone calls serve the same purpose.
The patterns that never change
The messages keep looking better; the language errors have faded and institutional templates are imitated skilfully. But the behavioural patterns cannot change, because the deception needs them. The first pattern is urgency: "within 24 hours", "your account will be suspended", "final warning". The rush exists to stop you thinking. The second is fear or reward: threat of a penalty, or an unexpected refund, gift, prize. The third is a demand for action: you are asked to click a link, open an attachment, supply a code or details. The fourth clue is technical: the sender address and the link's real destination do not quite match the imitated institution — and you can see a link's true target by hovering over it without clicking (or long-pressing on a phone).
As the channel changes, so does the name: over SMS it is called smishing, by phone call vishing; in the corporate world there are targeted variants that impersonate an executive to request a money transfer. The names differ, but the patterns above are the same in all of them.
The golden rule: verify through your own channel
All the pattern knowledge serves one rule: click no link and call back no number inside a suspicious message. If the message claims to be from your bank, open the bank's app yourself or type its address yourself; if it is a delivery notice, go to the courier's site yourself and look the tracking number up there. If a real problem exists, it will show in the official channel too; if it does not show there, the message was fake. This rule works regardless of how convincing the message looks — which is what makes it valuable: even when you miss the patterns, the rule protects you. Your password manager declining to autofill on a fake site is a silent warning pointing the same way.
If you were caught: speed shrinks the damage
Anyone can be caught — in a tired moment, by a message that happens to match a delivery you were expecting, anyone can click. Falling for it is not incompetence; what matters is the minutes that follow. The sequence: one, change the affected account's password immediately — and everywhere else the same password was used. Two, if two-factor authentication is not on for that account, switch it on. Three, if you gave card details, call your bank on its official number and have the card blocked. Four, if the account's session history shows logins you do not recognise, sign out of all sessions. Hiding the incident out of embarrassment is the worst response; speed shrinks the damage.
Common mistake: The confidence of "I would never fall for it"
The riskiest group in phishing awareness is the people certain they cannot be fooled. That confidence produces two errors: processing messages quickly without checking the patterns, and discounting tailored attacks — messages that mention your name, your employer, a real order of yours. Modern phishing is not always a hastily written mass mail; sometimes it carries context that fits you exactly. The right stance is trust in the rule, not in yourself: whatever the source, the transaction always goes through the official channel you open yourself.
Today's practice
Open your email spam folder and safely examine two or three messages there: without clicking any link, identify the urgency phrases, the sender address and what is being demanded. Then share the golden rule with someone in your family or circle: "Trust the app you open yourself, not the link in the message." Teaching it is the best way to make it stick.
Summary
- Phishing is a human attack, not a technical one: imitating institutions to make you hand over your details
- The unchanging patterns: urgency pressure, fear or reward, a click/details demand, mismatched addresses
- The golden rule: verify through the official channel you open yourself, not the message's link
- Anyone can be caught; a fast password change and card block shrink the damage
- What protects you is the rule applied every time — not "I would never fall for it"
Check your understanding
Questions and answer order are shuffled on every attempt. Results stay in your browser.