What is Phishing?
Phishing (a term derived from "fishing") is a fraud technique where criminals create fake web pages, emails, or messages that mimic legitimate institutions — banks, social networks, streaming services, government agencies — to trick victims into revealing passwords, banking information, or personal data.
The attacker "fishes" for credentials using convincing bait: urgency ("your account will be blocked"), offers ("you won a prize"), or fear ("someone tried to access your account"). According to security reports, more than 3.4 billion phishing emails are sent daily worldwide. The FBI's Internet Crime Complaint Center consistently ranks phishing as the number one reported cybercrime.
What makes phishing so effective is its simplicity. Unlike sophisticated hacking techniques that require deep technical knowledge, phishing relies entirely on human psychology. A well-crafted phishing email can fool even experienced professionals. The attacker doesn't need to break through firewalls or exploit software vulnerabilities — they just need one person to click a link and enter their credentials.
Common Phishing Examples
Phishing attacks adapt to context and geography. The most common types include:
Fake emails or SMS claiming account suspension, the need to update information, or to confirm transactions. The link leads to a page identical to the online banking site where the victim enters their username and password. These pages often replicate the entire login flow, including security questions and one-time password prompts, making them extremely convincing.
Links in DMs or comments that lead to fake login pages for Instagram, Facebook, or WhatsApp. After "logging in," the criminal captures the credentials and can take over the account. These attacks often come from already-compromised accounts of friends or family, making them more trustworthy at first glance.
Urgent messages requesting instant payments to "unblock" something, fake job offers, or fraudulent tech support requests. The goal is to convince the victim to transfer money or reveal financial credentials. Cryptocurrency phishing has surged, with fake exchange login pages and wallet connection scams becoming increasingly common.
Unlike mass phishing, spear phishing targets specific individuals using personalized information gathered from social media, data breaches, or corporate websites. The email may reference your real name, job title, recent purchases, or colleagues. This personalization dramatically increases success rates and is the primary attack vector used against corporations and high-value targets.
How to Identify Phishing
There are clear signs that help distinguish legitimate communications from phishing attempts:
- Suspicious URL: Check the address carefully. Banks and legitimate companies use official domains (e.g., bankofamerica.com). Phishing uses variations like bankofamerica-secure.com, b4nkofamerica.com, or bankofamerica.xyz. Always look for misspellings, extra characters, or unusual domain extensions.
- Excessive urgency: "Your account will be blocked in 24 hours" or "Confirm now or lose access" are tactics designed to prevent you from thinking clearly and verifying the source.
- Grammar and spelling errors: Many scams contain grammatical mistakes, unusual formatting, or awkward phrasing that wouldn't appear in professional communications.
- Strange sender: Emails from "your bank" coming from @gmail.com addresses or unknown domains. Check the actual email address, not just the display name.
- Request for sensitive data: No legitimate institution asks for your full password, verification code, or Social Security number via email or SMS. Ever.
- Generic greetings: "Dear customer" or "Dear user" instead of your actual name often indicates a mass phishing campaign.
Protection Measures
Protecting yourself from phishing requires conscious habits and the right tools:
Two-factor authentication (2FA)
Enable 2FA on all important accounts. Even if someone obtains your password through phishing, they won't be able to log in without the second factor (authenticator app or physical key). Use authenticator apps like Google Authenticator, Authy, or Microsoft Authenticator rather than SMS-based 2FA whenever possible.
Password manager
Use a password manager. It won't auto-fill credentials on fake sites because the domain will be different from the legitimate one — providing a valuable warning signal. If your password manager doesn't offer to fill in your credentials, the site is likely not what it claims to be.
Verify before clicking
Hover over links to see the real destination before clicking. On mobile devices, press and hold a link to preview the URL before opening it. Check for HTTPS and verify the domain matches the expected website.