Atlas record

Phishing

Phishing is a method in which an attacker behaves like a trusted institution or person in order to persuade you to hand over data such as passwords and card details yourself. It targets human trust rather than a technical hole.

In briefPhishing is a fraud in which someone poses as a trusted institution or person in order to persuade you to share data such as passwords and card details.
How it works
  • The attacker prepares a fake but convincing email or message in the name of a bank, a courier firm or a well-known service.
  • The message contains a scenario that hurries you (an account closure, a fine, a refund) and a link.
  • The link leads to a fake sign-in page closely resembling the genuine one.
  • The username, password or card details entered on that page go straight to the attacker.
  • The captured details are used to sign in to accounts, to transfer money or to attack further targets.
Warning signs
  • Language that hurries you, frightens you or promises an unusual reward
  • A sender address that does not match the institution's real domain
  • A link that goes somewhere different from the text shown when you hover over it
  • Generic greetings ('Dear customer') or personalisation that does not fit the context
  • A request for a password, card details or an approval code
  • Spelling errors and visual details inconsistent with the institution's template
How to protect yourself
  • Sign in by opening the application or the site yourself, not through links in messages.
  • Turn on two-step verification for all your important accounts.
  • Use a different, strong password for each account; a password manager makes that load lighter.
  • Verify unexpected requests by calling the institution yourself on its official number.
  • Build a deliberate habit of pausing at every scenario in an email or message that hurries you.
  • Do not put off device and browser updates.
If it happens to you
  • Change the password of the account whose details you entered straight away, and update any other accounts using the same password.
  • If you gave card details, call your bank to have the card stopped and start the dispute process.
  • Check the account's session history and connected devices and remove any you do not recognise.
  • Report the incident to the institution's official channels and, where necessary, to the legal authorities.
  • Watch your account activity and any incoming 'verification' messages closely over the following weeks.

Why does it still work?

Phishing messages make skilful use of two feelings: haste and fear. Messages such as 'your account will be closed', 'a suspicious sign-in has been detected' or 'your payment will be refunded' aim to produce a tap before there is time to think. Because the messages imitate genuine institutional templates and can be decorated with personal details such as your name or a recent purchase, appearance has stopped being a measure of trustworthiness.

The soundest habit

A single habit renders the great majority of phishing attempts ineffective: signing in by opening the application or the site yourself rather than by tapping a link in a message. If your bank really does want to reach you, you will see the message in the application's own notification area as well. Following this route with every message that hurries you reduces the whole burden of decision to one rule.

What institutions ask for, and what they never ask for

No bank or official body asks you by message or by telephone for your password, all the details of your card, or the approval code sent to your phone. Being asked for that information is proof enough about who you are dealing with. In cases of doubt you can verify by calling the institution's official call centre yourself; the Account Takeover record complements this with safe account habits.

Related terms: Fake Text Messages, Account Takeover, Malware

From the same atlas

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error