Phishing Attacks Explained: The Complete Avoidance Guide
Every 11 seconds, a business falls victim to a cyberattack. Phishing is the method criminals rely on most — and it keeps getting harder to spot.
This isn’t a problem reserved for large corporations. In 2024, phishing was involved in over a third of all data breaches worldwide, according to Verizon’s annual Data Breach Investigations Report. Ordinary people — checking emails on a lunch break or clicking a text that appears to be from their bank — get caught out every day.
This guide explains exactly what a phishing attack is, how each type works, how to spot the warning signs, and the practical steps you can take today to protect yourself. No jargon. No fluff. Just clear, actionable information.
What Is a Phishing Attack?
A phishing attack is a type of scam where a cybercriminal impersonates a trusted source — a bank, a delivery company, a government agency — to trick you into clicking a malicious link, downloading a harmful file, or handing over sensitive information like passwords or payment details.
The term “phishing” is deliberate wordplay on “fishing” — criminals cast a wide net hoping someone takes the bait. Unlike technical exploits that break through software defences, phishing works by deceiving you. It exploits human psychology: urgency, fear, trust, and curiosity. That’s precisely what makes it so effective.
A phishing attempt typically has one of these goals:
- Steal your login credentials (username and password)
- Obtain your financial details (bank account number, card details)
- Install malware via a malicious link or attachment
- Gain access to a business network through a single employee
The scam can arrive by email, text message, phone call, social media, or through a convincing fake website. The delivery method varies. The intent never does.
What Are the Different Types of Phishing Attacks?
Phishing isn’t limited to email. Criminals now use SMS, phone calls, and messaging apps to target victims. Knowing the main types makes each one significantly easier to recognise — and refuse.
Email Phishing (Standard Phishing)
This remains the most common form. You receive an email that appears to be from a legitimate organisation — HMRC, PayPal, Amazon, your bank — asking you to click a link and verify your account, update your payment details, or claim a refund.
These emails often use the company’s real logo and closely mimic its house style. The tells, when you look carefully, are a suspicious sender address, subtle grammatical errors, or a link pointing somewhere unexpected.
Spear Phishing
Standard phishing is a mass campaign — sent to thousands, hoping a small percentage bite. Spear phishing is targeted. The criminal researches you specifically: your name, employer, job title, and sometimes a recent event sourced from LinkedIn or social media.
The result is a highly personalised, convincing message. “Hi Sarah, regarding the Q2 supplier invoices — could you review this updated document before end of day?” Sarah’s guard is lower because the message feels relevant and real. This type of attack has a substantially higher success rate.
Smishing (SMS Phishing)
Smishing uses text messages. You’ve almost certainly seen these: “Your Royal Mail parcel has a delivery exception. Pay £2.99 to reschedule your delivery.” Or a message impersonating your bank about a suspicious transaction on your account.
The UK’s National Cyber Security Centre (NCSC) reported a significant increase in smishing attacks during and after the COVID-19 pandemic, with campaigns impersonating NHS contact tracers, HMRC, and courier services.
Vishing (Voice Phishing)
Vishing happens over the phone. A caller claims to be from your bank’s fraud prevention team, HMRC, or even the police. They manufacture urgency — “your account has been compromised, we need to act now” — and pressure you into transferring funds or confirming your PIN.
These calls can be highly convincing. Criminals often already hold some real information about you (obtained from a prior data breach or public records) to establish credibility before the ask comes.
Whaling
Whaling targets senior executives — the “big fish.” Criminals pose as board members, legal representatives, or regulators and pressure a finance director to authorise an urgent bank transfer. These attacks are less frequent but far more damaging. A single successful whale phishing attempt has cost some organisations hundreds of thousands of pounds.
Clone Phishing
In clone phishing, an attacker takes a legitimate email you’ve previously received — from a newsletter, a supplier, or an internal team — and sends a near-identical copy with one change: a malicious link or attachment replacing the genuine one.
It’s particularly effective because the victim recognises the email’s format and assumes it’s trustworthy.
Phishing Attack Types at a Glance
| Type | Delivery Method | Who It Targets | Primary Goal |
|---|---|---|---|
| Email Phishing | Mass audience | Credentials, card data | |
| Spear Phishing | Specific individual | Account access, data theft | |
| Smishing | SMS / Text | Mass audience | Payment fraud, credentials |
| Vishing | Phone call | Individuals, elderly | Bank transfers, PIN theft |
| Whaling | Senior executives | Large financial transfers | |
| Clone Phishing | Prior email recipients | Malware installation, credentials |
How to Spot a Phishing Email or Message
Most phishing attempts share recognisable warning signs. Learning to pause before clicking — and knowing exactly what to look for — is one of the most effective defences available to you.
In my experience reviewing suspicious messages, these are the red flags that appear most consistently:
1. The Sender’s Email Address Doesn’t Match
The display name might say “PayPal Support,” but look at the actual email address behind it. It may read something like support@paypal.account-verify.com or noreply@paypa1.com (note the numeral “1” replacing the letter “l”).
Legitimate organisations send exclusively from their own verified domain. If the domain in the email address doesn’t match the company’s official website exactly, treat the message as suspicious.
2. Artificial Urgency or Threats
“Your account will be suspended in 24 hours.” “Immediate action required.” “Your recent payment has failed.”
Urgency is a psychological lever. Criminals want you to react before you think. Whenever a message pressures you to act immediately or threatens consequences, slow down deliberately. Legitimate companies do not lock accounts without prior notice and always provide clear, official channels for resolving disputes.
3. Generic Greetings
“Dear Customer,” “Dear Account Holder,” “Dear User.” Any service you have an account with knows your name. A generic greeting is a standard sign of a mass phishing campaign.
4. Suspicious or Misleading Links
Before clicking any link, hover over it on a desktop computer to preview the actual URL in your browser’s status bar. On a mobile device, press and hold the link to see where it leads.
If the URL reads http://amazon-login.verify-now.net instead of https://www.amazon.co.uk, do not click it.
Watch for these link warning signs:
- HTTP (not HTTPS) — no encryption
- Misspelled domain names (
amaz0n,g00gle,paypa1) - Excessively long URLs containing random characters
- Link shorteners concealing the real destination
5. Unexpected Attachments
If you weren’t expecting a file, don’t open it. Attachments with extensions like .exe, .zip, .docm, or .xlsm can execute malicious code the moment you open them. Even PDF files can carry embedded scripts. When uncertain about an attachment, contact the sender through a verified, separate channel before opening anything.
6. Requests for Sensitive Information
Legitimate banks, government agencies, and major platforms will never ask you to confirm your full password, PIN, or complete payment card details via email or text message. If any message asks for this, it is a scam — without exception.
How to Protect Yourself from Phishing: Proven Steps
Protecting yourself from phishing comes down to a small number of consistent habits. These steps work best in combination — each one reduces your risk, but together they make you a significantly harder target.
Step 1: Enable Two-Factor Authentication on Every Important Account
Two-factor authentication (2FA) means that even if a criminal steals your password, they cannot access your account without a second verification step — typically a time-sensitive code from an app on your phone.
Set up 2FA on your email, banking, social media, and any account that holds personal or financial data. Authenticator apps (Google Authenticator, Authy, Microsoft Authenticator) are more secure than SMS codes, though either option is far better than relying on a password alone.
Step 2: Never Click Links Inside Unsolicited Messages
If you receive an unexpected email or text message asking you to log in, verify your details, or take urgent action — do not click the link inside it. Instead, open a new browser tab and go directly to the organisation’s official website yourself, or use their verified app.
This single habit neutralises the majority of phishing attempts before they have any chance to succeed.
Step 3: Use a Password Manager
A password manager does two important things: it creates strong, unique passwords for every site you use, and it autofills credentials only on websites it recognises. If you land on a convincing fake version of your bank’s website, your password manager won’t recognise it and won’t offer to fill in your details — an immediate and reliable warning sign.
Reliable options include Bitwarden (free and open source), 1Password, and Dashlane.
Step 4: Keep All Software and Devices Updated
Security updates patch vulnerabilities that phishing attacks — especially those delivering malware through links or attachments — are designed to exploit. Keep your operating system, browser, and applications current. Enable automatic updates wherever possible and don’t delay installing them.
Step 5: Use Your Browser’s Built-In Phishing Protection
Modern browsers including Chrome, Safari, Edge, and Firefox have built-in phishing protection that warns you before visiting known malicious sites. Verify this feature is enabled in your browser’s security settings. Your email provider (Gmail, Outlook) also filters a large proportion of phishing emails before they reach your inbox — though not all of them make it to the bin.
Step 6: Verify Unexpected Requests Through a Separate Channel
If you receive an urgent message claiming to be from your bank, HMRC (In the US: the IRS), your employer, or any organisation asking you to transfer money or confirm personal details — verify it through an independent channel. Call the organisation using the phone number listed on their official website, not any number provided in the suspicious message.
This extra step takes two minutes and can save you from losing thousands.
Step 7: Report What You Receive
Reporting phishing attempts isn’t just good for you — it helps shut down active criminal campaigns and protects other potential victims.
- UK: Forward suspicious emails to
report@phishing.gov.uk. Text suspicious SMS messages to 7726 (free on all networks). - Australia: Report to the Australian Cyber Security Centre (ACSC) at cyber.gov.au
- Canada: Report to the Canadian Anti-Fraud Centre at antifraudcentre.ca
- New Zealand: Report to CERT NZ at cert.govt.nz
- American readers: report to the FTC
Phishing Myths That Still Put People at Risk
The most dangerous misconceptions about phishing are the ones that create false confidence. These myths account for a disproportionate number of successful attacks.
Myth 1: “I’d Easily Spot a Phishing Email”
This is the most common — and most costly — misconception. Phishing emails have become dramatically more sophisticated. Many pass spell-check, use exact company branding, and arrive from spoofed domains that look virtually identical to the real thing at a glance.
A 2023 security study by Hoxhunt found that untrained employees missed a significant proportion of phishing simulations — and even security professionals are successfully targeted. Overconfidence is a genuine vulnerability.
Myth 2: “Only Careless or Older People Get Caught”
Phishing success has nothing to do with intelligence or technical literacy. Security researchers, IT professionals, and senior executives have all been successfully phished. These attacks are engineered to trigger psychological responses — urgency, authority, fear — that affect everyone regardless of age, education, or experience.
Myth 3: “I’m Not Important Enough to Be Targeted”
Standard phishing doesn’t select for importance — it targets everyone with an inbox. Criminals send millions of messages and only need a tiny percentage to succeed. You don’t need to be noteworthy; you just need an email address or a phone number.
Myth 4: “My Antivirus Will Catch It”
Antivirus software catches many threats but provides no defence against social engineering. A phishing page designed to steal your password doesn’t install software — it tricks you into surrendering information voluntarily. There is nothing for antivirus to detect. Your own judgement and the habits outlined above are the relevant defence here.
Myth 5: “Phishing Only Happens Over Email”
SMS, phone calls, WhatsApp, Instagram direct messages, LinkedIn connection requests, fake job ads — phishing now arrives through any digital channel where someone can send you a link or make contact. Email is still the most common vector, but it’s far from the only one.
Frequently Asked Questions About Phishing Attacks
What should I do if I accidentally clicked a phishing link?
Don’t panic — a single click doesn’t automatically mean you’re compromised. Disconnect from the internet immediately, then run a full scan with your security software. Change the passwords for any accounts you may have accessed or entered details for on the page, starting with your email and banking accounts. Enable 2FA on each. If it happened on a work device, notify your IT or security team straight away so they can assess the risk.
Can phishing attacks target mobile phones?
Yes, absolutely. Smishing (SMS phishing) and vishing (voice phishing) are specifically designed for mobile users. Phishing links sent through WhatsApp, Instagram DMs, or other messaging apps are increasingly common. Mobile users can be more vulnerable because smaller screens make URL inspection more difficult and the fast-paced nature of mobile browsing can reduce natural caution.
How did the scammers get my email address or phone number?
Through data breaches from sites you’ve used, scraped public information (professional directories, forums, social media), purchased lists traded on the dark web, or automated guessing of common email formats. If you’ve ever registered with any online service that later suffered a breach, your details are likely circulating online. You can check your email address at to see if it appears in any known breaches.
Is phishing a criminal offence?
Yes. Phishing is illegal in the UK, Australia, Canada, Ireland, New Zealand, and the US, among many other countries. In the UK, it typically falls under the Fraud Act 2006 and the Computer Misuse Act 1990, carrying potential prison sentences. Many phishing operations are based overseas, which complicates prosecution, but reporting remains valuable and contributes to ongoing law enforcement efforts.
What is the difference between phishing and pharming?
Phishing tricks you into visiting a fake website via a deceptive link or message. Pharming goes a step further — it manipulates your device or the DNS system to redirect you to a fraudulent website even when you type the correct address into your browser. Both aim to steal credentials, but pharming doesn’t require you to click anything suspicious, making it considerably harder to detect without technical protections in place.
How can I verify whether a website is safe before entering my details?
Confirm the URL starts with https:// (look for the padlock icon in the address bar). Verify the domain is spelled precisely correctly. Check that the site includes legitimate contact information, a privacy policy, and consistent branding. For any site you’re unsure about, Google’s Safe Browsing transparency report allows you to check URLs for known threats at safebrowsing.google.com. When something feels slightly off about a website, trust that instinct.
Do legitimate companies ever send links in emails?
Yes — but they won’t pressure you to click immediately, threaten account closure, or ask for your full password or PIN via email. When in doubt about any link in an email, ignore it and navigate to the company’s website directly by typing the address yourself. This is always the safer path.
Protect Yourself Starting Today
Phishing attacks succeed because they’re engineered to bypass rational thinking and trigger immediate, instinctive responses. Understanding how they work puts the advantage back with you.
Three habits will protect most people from most attacks:
- Enable two-factor authentication on every important account — especially email and banking.
- Never click links in unsolicited messages — navigate directly to the website instead.
- Verify any unusual request through an independent channel — a two-minute phone call can save you thousands.
You don’t need to become a cybersecurity expert. You need to slow down, question what you’re looking at, and apply a few consistent practices every time you’re online.
If this guide was useful, consider sharing it with someone who might benefit — family members less familiar with online threats, colleagues who handle financial transactions, or anyone who’s recently received a suspicious message and wasn’t sure what to do.
Curated with care: articles designed to deliver valuable insights and practical solutions.