Guide

How to spot phishing

Phishing is less a technical attack than a game of persuasion: a fake message that leads you to hand over your password, your card or your approval yourself. The good news is that most of these games give themselves away through a few recognisable signs.

Short answer

The main signs that give phishing away are these: manufactured urgency, a sender address made to resemble the real one but not quite matching, links pushing you to sign in, and unexpected attachments. When you suspect a message, click nothing in it; verify through the organisation's official app or a number you already know.

How phishing works

Phishing is an attacker posing as an organisation or person you trust in order to extract information or an action from you: an email that appears to come from your bank, a text sent in the name of a delivery company, or a message from the compromised account of someone you know.

The target is usually one of three things: your sign-in details (through a fake login page), your card details (through a fake payment screen), or infecting your device with malware (through an attachment or a link). Because the attack is psychological rather than technical, anyone can be a target.

First sign: urgency and fear

The shared signature of phishing messages is time pressure: “Your account will be closed within 24 hours”, “Suspicious sign-in detected, verify now”, “Your prize expires today”. The aim is to get you clicking before you have a chance to think.

Genuine organisations send warnings too; the difference is that legitimate warnings usually direct you to their own official channels and do not use the language of panic. If a message quickens your heartbeat, put at least a minute between you and it: a sense of urgency is a warning sign in its own right.

Take an example: “Unusual activity has been detected on your account; if you do not verify within 24 hours your access will be closed” carries three traps at once — fear (unusual activity), time pressure (24 hours) and a link presented as the only way out. Genuine warnings generally do not hurry you; they leave you free to open the app and check for yourself.

Second sign: the sender and the link address

A display name is easily faked; the place to look is the address itself. Sender addresses commonly carry mangled versions of the organisation's name — a missing letter, an added character, an unrelated ending. With links, hovering over them (or holding them down on a phone) shows the real address: the organisation's name may appear at the start while the actual domain is something else entirely.

Shortened links also hide the real address. When in doubt, the cleanest route is to leave the link untouched and go to the organisation's site by typing the address yourself, or to open its official app.

Other signs: language, attachments and requests

Clumsy, translated-sounding sentences, generic greetings (“Dear customer”) and inconsistent graphics are classic clues; but with AI tools, fraudulent text can now read more fluently, so polished language alone is no reassurance.

What really decides it is the request: no legitimate organisation will ask you by message for your password, your full card details, or the one-time code sent to your phone. Attachments you were not expecting — especially files that look like invoices, receipts or orders — deserve suspicion before they are opened. For traps arriving by text message, see the fake SMS guide.

Be ready for a variety of channels too: a phone call from someone playing a bank employee, building trust and then asking for a code or card details, is the spoken version of the same game. QR codes encountered in cafés or on posters can also lead to fake pages; give the address that opens after scanning a code the same attention you would give a link you clicked.

When you suspect, and when you have clicked

Do not touch the reply, the link or the attachment of a suspicious message; verify with the organisation through its official app or the number on the back of your card. Marking the message as spam and deleting it also helps similar ones get filtered.

If you clicked the link and entered information, do not lose time: change the password concerned at once, update any other accounts using the same password, and turn on two-factor authentication. If you entered card details, call your bank and have the card stopped. All the following steps are set out in the hacked account guide.

People who use a password manager have a hidden advantage: the manager fills a saved password only on the genuine address. If a sign-in screen that always fills itself is one day blank, you may be on a fake copy; take that silent warning seriously and check the address carefully.

Checklist

  • Put a minute between you and any message applying time pressure
  • Check the sender address and the link's real address
  • Treat messages asking for passwords, card details or codes as fake
  • Do not open attachments you were not expecting
  • Always verify through the official app or a number you already know
  • Mark suspicious messages as spam and delete them

Frequently asked questions

I clicked the link but entered nothing; am I at risk?

In most cases the real danger lies in entering information; even so, if the page tried to download something, do not open the file and run a security scan on your device. Stay alert to unusual activity on your accounts over the following days.

The message appears to come from my bank's real number; can it still be fake?

Yes; sender names and numbers can be imitated, and fake messages can even land inside a genuine message thread. So base your judgement not on the displayed name but on what is being asked and on the link's real address.

Does phishing only arrive by email?

No; text messages, phone calls, social media messages and QR codes are used as well. The channel changes but the game is the same: win trust, create urgency, ask for information or a click.

How do I tell a genuine warning from a fake one?

The most reliable method is to take the message out of the equation: instead of clicking the link, open the organisation's app or site yourself. If the warning is genuine, it will appear there too.

This guide draws on the phishing warnings issued by national cyber security bodies and on the publicly available security guidance of banks.

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error