What Is Phishing? Types, Examples, Warning Signs & Prevention

What Is Phishing? Types, Examples, Warning Signs & Prevention

Have you ever received a message saying:

"Your account will be suspended. Click here immediately to verify it."

Or perhaps:

"Congratulations! You have won a prize. Claim it now."

Or:

"We detected a suspicious transaction. Log in now to secure your account."

These are common examples of phishing.

Phishing is one of the most common forms of social engineering. Instead of depending entirely on a technical vulnerability, attackers often try to manipulate a person into clicking a link, opening an attachment, sharing credentials, approving an action or providing sensitive information.

CISA defines phishing as a form of social engineering where a cyber threat actor poses as a trusted colleague, acquaintance or organization to persuade a victim to provide sensitive information or network access. The lure may arrive through email, text message or phone call.

Google similarly describes phishing as attempts to steal personal information or gain access to online accounts using deceptive emails, messages, advertisements or websites that imitate services people already use.

This article explains phishing in simple language, including how it works, common types, warning signs, prevention techniques, reporting steps and what to do after interacting with a suspicious message.

Important: Never provide passwords, one-time codes, banking information or other sensitive information in response to an unexpected message until you independently verify that the request is genuine.

What Is Phishing?

Phishing is a deceptive technique used to trick people into revealing information, clicking malicious links, downloading harmful files or taking actions that benefit an attacker.

The attacker often pretends to be someone trustworthy.

For example:

  • A bank
  • An employer
  • A university
  • A delivery company
  • A social-media platform
  • A cloud service
  • A colleague
  • A government organization

The objective is to create enough trust, fear, curiosity or urgency that the victim acts before checking the message carefully.


How Does Phishing Work?

A simplified phishing attack can look like this:

Attacker
   ↓
Creates Deceptive Message
   ↓
Impersonates Trusted Entity
   ↓
Victim Receives Message
   ↓
Victim Clicks / Responds / Downloads
   ↓
Attacker Attempts to Obtain Information or Access
   ↓
Possible Account or System Compromise

CISA's recent joint phishing guidance identifies credential theft and malware deployment among the primary objectives of phishing campaigns.


Why Is Phishing So Effective?

Phishing attacks target human decision-making.

Attackers may deliberately create:

  • Urgency
  • Fear
  • Curiosity
  • Authority
  • Financial pressure
  • Excitement
  • Trust

For example:

Fear: "Your account has been compromised."

Urgency: "Verify within 10 minutes."

Authority: "Your administrator requires this action."

Reward: "You have won a prize."

Google advises users to slow down when a communication creates urgency and to independently verify suspicious requests before providing information.


What Information Do Phishing Attacks Try to Steal?

Depending on the campaign, phishing messages may attempt to collect:

  • Usernames
  • Passwords
  • Banking information
  • Payment details
  • PINs
  • Identity information
  • One-time verification codes
  • Recovery information
  • Business credentials
  • Access tokens or session information

Google specifically warns users not to provide private or financial information in response to suspicious emails, texts, webpages or pop-ups.


Common Types of Phishing

Phishing is not one single attack technique.

Some common forms include:

  • Traditional email phishing
  • Spear phishing
  • Whaling
  • Smishing
  • Vishing
  • Business email compromise-related impersonation
  • Clone phishing

CISA's phishing guidance identifies spearphishing, whaling, vishing and smishing among common types.


1. Email Phishing

This is one of the most familiar forms of phishing.

The victim receives an email designed to look legitimate.

Example

From: Security Team
Subject: Urgent Account Verification

We detected unusual activity on your account.

Please verify your account immediately:
[Verify Account]

The message may imitate a real company, but the link may lead somewhere else.


2. Spear Phishing

Spear phishing is targeted phishing aimed at a particular person or organization.

The attacker may use information about the target to make the message appear more believable.

For example, the attacker might know:

  • The victim's name
  • The company they work for
  • Their job role
  • A current project
  • The name of a colleague

CISA describes spearphishing as phishing targeted at an individual using information about that person.


3. Whaling

Whaling is targeted phishing aimed at a high-profile individual, such as an executive or other person with access to sensitive information.

The objective can include:

  • Credentials
  • Financial information
  • Business information
  • Account access

CISA identifies whaling as phishing targeted at a high-profile individual to obtain sensitive or high-value information.


4. Smishing

Smishing is phishing delivered through SMS or text messages.

Example:

Your parcel could not be delivered.

Update delivery information:
https://example.invalid/verify

The message may appear to come from a shipping company even when it does not.

CISA identifies smishing as phishing delivered through text messages.


5. Vishing

Vishing is phishing conducted through voice communication, including phone calls.

For example, a caller may claim to be:

  • Bank support
  • Technical support
  • Government personnel
  • Company IT staff
  • Account-security staff

The caller may attempt to persuade you to reveal a password, verification code or other information.

CISA identifies vishing as phishing through voice communication.

Google's current guidance also warns about phone scams in which attackers impersonate Google account-security personnel and attempt to obtain passwords, codes or fraudulent approval of login prompts.


6. Clone Phishing

In clone phishing, an attacker may create a deceptive message that resembles a legitimate message the victim has previously received.

The attacker may attempt to reproduce:

  • Visual design
  • Subject line
  • Message structure
  • Sender identity
  • Link appearance

The copied message may contain a malicious replacement link or attachment.


7. Business Email Compromise

Business email compromise involves deceptive communications that attempt to manipulate employees or organizations into taking actions such as transferring money or sharing information.

These attacks can involve impersonation, compromised accounts or other forms of deception.

Because financial and business workflows are involved, organizations should verify sensitive requests using trusted communication channels.


Phishing vs Spam

People sometimes use the terms interchangeably, but they are different.

Spam Phishing
Usually unwanted messages Deceptive messages intended to manipulate the recipient
Often advertising or bulk content Often attempts to steal information or gain access
May be annoying Can cause security or financial harm

Some phishing messages can also be considered spam, but not all spam is phishing.


Phishing vs Malware

Phishing is a social-engineering technique.

Malware is malicious software.

They can be connected.

Phishing Message
      ↓
Malicious Attachment / Link
      ↓
Malware Download
      ↓
Potential System Compromise

CISA's 2025 joint guidance specifically identifies malware deployment as one of the major objectives of phishing campaigns.


Phishing vs Social Engineering

Social engineering is the broader concept of manipulating people into revealing information or taking actions that undermine security.

Phishing is one form of social engineering.

Social Engineering
       |
       +---- Phishing
       |
       +---- Impersonation
       |
       +---- Pretexting
       |
       +---- Other Manipulation Techniques

CISA describes phishing as a form of social engineering.


Common Signs of a Phishing Message

There is no single sign that proves a message is phishing, but several warning indicators can raise suspicion.

1. Suspicious Sender Address

The display name may look correct while the actual email address is different.

For example:

Display Name:
Example Bank

Actual Address:
security@example-security.invalid

Always inspect the actual sender information.

CISA specifically lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.


2. Unexpected Urgency

Be careful with messages saying:

  • "Act immediately"
  • "Your account will be closed today"
  • "Final warning"
  • "Respond within 10 minutes"

Google recommends slowing down because scams frequently use urgency to pressure people into acting without verification.


3. Suspicious Links

A message may show text such as:

Verify your account

But the actual URL may point somewhere unexpected.

On a computer, hovering over a link before clicking can reveal the destination. Google specifically recommends checking whether the displayed destination matches the expected service.

Do not assume that a link is safe merely because it contains https://. HTTPS encrypts the connection to a website, but it does not prove that the website itself is legitimate.


4. Generic Greetings

Messages that use generic greetings such as "Dear Customer" can sometimes be suspicious, especially when combined with other warning signs.

CISA includes generic greetings among indicators worth checking.


5. Spelling or Formatting Problems

Incorrect spelling, strange formatting, unusual wording or inconsistent branding can indicate phishing.

However, modern phishing messages can be professionally written, so perfect grammar does not prove legitimacy.


6. Unexpected Attachments

Be cautious when an unexpected message asks you to open a file.

Examples include:

  • Invoices
  • Documents
  • Compressed files
  • Scripts
  • Unknown installers

CISA lists suspicious attachments among common phishing indicators.


7. Requests for Private Information

Be particularly careful when an unexpected message asks for:

  • Password
  • OTP
  • PIN
  • Bank information
  • Identity information
  • Credit-card details

Google advises against responding to requests for private information through email, text or phone unless the request has been independently verified.


Phishing Example: Fake Bank Message

Imagine receiving:

URGENT: Suspicious transaction detected.

Your banking access has been restricted.

Verify your identity now:
[Secure Account]

Failure to respond within 15 minutes
may result in permanent suspension.

Warning signs include:

  • Urgency
  • Fear
  • Unexpected account action
  • Request for information
  • Unknown link destination

A safer response is to open the bank's official application or type its known website address yourself instead of using the message link.


Phishing Example: Fake Job Message

Congratulations!

You have been selected for a remote IT job.

Please pay a small registration fee and
send your ID and bank details to complete
your onboarding.

This contains several warning signs:

  • Unexpected job offer
  • Pressure to act
  • Request for money
  • Request for sensitive information
  • Potentially unverifiable employer

Always independently verify the company and application process.


Phishing Example: Fake Delivery Message

Delivery failed.

Please pay a small fee to reschedule
your delivery.

[Pay Delivery Fee]

Before clicking anything, ask:

  • Am I actually expecting a delivery?
  • Did I order anything from this company?
  • Does the message match my order information?
  • Can I verify the delivery using the official app?

How to Check a Suspicious Link Safely

Do not click first and investigate later.

Instead:

  1. Check the sender.
  2. Read the message carefully.
  3. Inspect the link destination.
  4. Look for spelling or domain inconsistencies.
  5. Open the organization's official website independently.
  6. Verify the request through a trusted channel.

Google recommends opening the legitimate site separately rather than using a suspicious email link when possible.


What Is Link Spoofing?

A phishing message can display one URL-like text while sending the victim somewhere else.

For example:

Displayed:
https://trusted-example.com

Actual destination:
https://different-example.invalid/login

This is why checking the actual destination is important.


How Attackers Use Fake Login Pages

A phishing campaign may create a fake login page that visually resembles a legitimate service.

For example:

Fake Login Page
      ↓
Username
Password
Verification Code
      ↓
Attacker Receives Credentials

Google's guidance warns that phishing sites can imitate services users already know and trust.

This is why users should verify the domain and preferably navigate directly to the official service.


Can MFA Stop Phishing?

MFA can significantly improve account security, but not every MFA method provides the same protection against phishing.

CISA's phishing guidance recommends phishing-resistant multifactor authentication as an important protection for organizations.

Phishing can sometimes attempt to trick users into:

  • Sharing a one-time code
  • Approving a fraudulent login prompt
  • Entering credentials into a fake site

For stronger protection, organizations can use phishing-resistant authentication technologies where appropriate.


What Is Phishing-Resistant MFA?

Phishing-resistant MFA is authentication designed to make it significantly harder for an attacker to use a fake website or deceptive interaction to capture reusable authentication information.

Modern methods can include cryptographic authentication technologies such as security keys and passkeys, depending on the service.

The important lesson is:

MFA is important, but the specific authentication method matters.

How Organizations Can Prevent Phishing

Phishing prevention should not rely only on individual users.

Organizations can combine technical and human controls.

Email Authentication

CISA recommends technologies such as:

  • SPF
  • DKIM
  • DMARC

These technologies can help organizations establish and enforce email-authentication policies and reduce certain types of email impersonation.

User Education

Train employees to recognize:

  • Suspicious sender addresses
  • Fake links
  • Unexpected attachments
  • Urgency
  • Requests for sensitive information

CISA recommends employee education and encourages reporting suspicious correspondence to the appropriate security team.

Technical Controls

Organizations may also use:

  • Email filtering
  • Domain reputation systems
  • Malware scanning
  • Web filtering
  • MFA
  • Endpoint protection
  • Security monitoring

What Should You Do When You Receive a Suspicious Message?

Use this simple process:

STOP
 ↓
Do Not Click
 ↓
Do Not Reply
 ↓
Verify Independently
 ↓
Report
 ↓
Delete / Follow Organization Procedure

CISA's guidance recommends reporting suspicious messages to the appropriate security team and not forwarding malicious email to other employees within an organization.


What If You Already Clicked the Link?

Do not panic.

Take action quickly.

If You Only Opened the Page

Close the page and avoid entering information.

Review what happened and consider reporting the message.

If You Entered Your Password

Change the password through the legitimate service's official website or app.

If the password was reused elsewhere, change it on those accounts too.

If You Shared a Verification Code

Immediately secure the account through its official security controls and review recent activity.

Google recommends reviewing account security activity and securing the account when unfamiliar activity is detected.

If You Downloaded a File

Do not open it again. Follow your organization's security procedure or use trusted security software to assess the device.

If Financial Information Was Shared

Contact the relevant financial institution using a trusted, independently verified contact method.


How to Report Phishing

Reporting helps organizations investigate attacks and can help prevent additional victims.

For Gmail, Google provides a Report Phishing option within Gmail.

Within organizations, follow the company's security or IT reporting process.

For suspicious websites, Google also provides a mechanism for reporting phishing pages.


Phishing and Social Media

Phishing does not only happen through email.

Attackers can use:

  • Direct messages
  • Social-media posts
  • Fake support accounts
  • Chat applications
  • SMS
  • Voice calls

CISA advises people to remain alert across communication platforms, including social media.


Phishing on Messaging Apps

A scammer may send:

Your account violated our policy.

Appeal here:
[Link]

The same principles apply:

  • Do not rush.
  • Do not trust the message automatically.
  • Verify through the official application or website.
  • Do not reveal credentials.

Phishing and QR Codes

QR codes can also be used as part of phishing attempts.

A QR code can hide the destination URL behind an image, making it harder to visually inspect before scanning.

If you receive an unexpected QR code:

  • Ask why it was sent.
  • Verify the sender.
  • Preview the destination where your device allows it.
  • Navigate directly to the official service instead.

Phishing and AI

Modern generative AI can make it easier to produce convincing text, translations and impersonation material.

This means traditional clues such as spelling mistakes may be less reliable than they once were.

A stronger defense is to focus on:

  • Unexpected requests
  • Unusual payment instructions
  • Unverified login requests
  • Domain mismatches
  • Urgency
  • Requests for confidential information
  • Independent verification

In other words:

Do not judge a message only by how professional it looks.

How to Verify a Request

Suppose your manager sends a message asking you to transfer money.

Instead of immediately responding:

Message
  ↓
Verify sender through another trusted channel
  ↓
Confirm request
  ↓
Proceed only if legitimate

For sensitive actions, independent verification is one of the most useful defenses against impersonation.


Phishing Prevention Checklist

  • □ Slow down when a message creates urgency.
  • □ Check the actual sender address.
  • □ Inspect links before opening them.
  • □ Avoid unexpected attachments.
  • □ Never share passwords through messages.
  • □ Never share one-time verification codes with unexpected callers or messages.
  • □ Verify financial requests independently.
  • □ Use MFA.
  • □ Prefer phishing-resistant authentication where available.
  • □ Keep devices and applications updated.
  • □ Report suspicious messages.

Phishing Prevention for Students

Students can be targeted with messages about:

  • Scholarships
  • Exam results
  • University accounts
  • Internships
  • Jobs
  • Certificates
  • Fees
  • Course registrations

Before clicking, ask:

Was I expecting this?

Who actually sent it?

Does the domain look correct?

Can I verify this through the official university or organization's website?

Phishing Prevention for Employees

Employees should be particularly careful with:

  • Payment requests
  • Password-reset requests
  • Cloud-storage invitations
  • Unexpected file shares
  • CEO or manager impersonation
  • Urgent IT requests
  • Vendor payment changes

Sensitive requests should follow established company procedures.


Phishing Prevention for Businesses

A business should use multiple layers of protection.

Email Authentication
       +
Email Filtering
       +
MFA
       +
Endpoint Security
       +
User Training
       +
Reporting
       +
Incident Response
       ↓
Reduced Phishing Risk

CISA's guidance similarly recommends combining technical protections, employee awareness and reporting procedures rather than relying on one control alone.


How Security Teams Respond to a Phishing Attack

A security team may follow a workflow such as:

User Reports Message
       ↓
Security Team Investigates
       ↓
Identify Indicators
       ↓
Search for Other Recipients
       ↓
Block Malicious Domains / Messages
       ↓
Investigate Any Compromise
       ↓
Contain and Remediate
       ↓
Review Lessons Learned

CISA notes that employee reporting can help incident responders determine whether an attack is isolated or widespread and identify indicators that can be used in security protections.


What Are SPF, DKIM and DMARC?

These are email-authentication technologies used to help organizations establish whether messages claiming to come from their domains are legitimate.

SPF

Sender Policy Framework allows domain owners to publish which mail servers are authorized to send mail for a domain.

DKIM

DomainKeys Identified Mail uses cryptographic signatures to help verify that a message is associated with the domain and has not been altered in transit in ways covered by the signature.

DMARC

Domain-based Message Authentication, Reporting, and Conformance builds on SPF and DKIM and lets domain owners publish policies and receive reports related to email authentication.

CISA specifically recommends SPF, DKIM and DMARC as part of organizational defenses against phishing and email impersonation.


Does HTTPS Prevent Phishing?

No.

HTTPS helps protect the connection between your browser and the website.

It does not automatically prove that the website is trustworthy.

For example:

https://legitimate-example.com
        ≠
https://malicious-example.com

Both may technically use HTTPS.

Therefore:

Look at the domain and context, not just the padlock or HTTPS.

Can Antivirus Stop Phishing?

Security software can help detect malicious files, websites or other harmful activity, but it should not be treated as a complete phishing defense.

Human verification and secure authentication remain important.

A multilayer approach is stronger than relying on one product.


Can a Phishing Email Look Completely Real?

Yes.

Attackers can imitate:

  • Logos
  • Writing style
  • Email layouts
  • Company names
  • Support messages
  • Login pages

Therefore, do not assume:

"It looks professional, so it must be legitimate."

Google warns that phishing messages can look exactly like communications from people or organizations you trust.


Phishing Awareness: A Simple Rule

Use the following rule:

STOP → CHECK → VERIFY → ACT

STOP: Do not react immediately.

CHECK: Look at the sender, link, request and context.

VERIFY: Contact the organization through an official channel.

ACT: Only continue once you know the request is legitimate.


Phishing Incident Response Checklist

If you suspect that you interacted with a phishing message:

  • Stop interacting with the message.
  • Change compromised passwords through the legitimate service.
  • Review recent account activity.
  • Revoke suspicious sessions where the service supports it.
  • Enable or strengthen MFA.
  • Contact the relevant organization or financial institution if necessary.
  • Report the phishing message.
  • Follow your company's incident-response procedure if it occurred at work.

Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.


Common Phishing Myths

Myth 1: Phishing Only Happens Through Email

False. Phishing can occur through text messages, phone calls, social media and other communication channels.

Myth 2: Bad Grammar Always Means Phishing

Not necessarily. Some phishing messages contain obvious mistakes, but sophisticated messages may be professionally written.

Myth 3: HTTPS Means a Website Is Safe

No. HTTPS protects the connection but does not prove the website is legitimate.

Myth 4: MFA Makes Phishing Impossible

No. MFA improves security, but attackers can try to trick users into sharing codes or approving fraudulent authentication requests. Phishing-resistant authentication provides stronger protection against some phishing scenarios.

Myth 5: Phishing Only Targets Large Companies

Phishing can target individuals, students, small businesses and large organizations alike.

Myth 6: Only Non-Technical People Fall for Phishing

Anyone can make a mistake, especially when a message is designed to create urgency or mimic a trusted source.


Frequently Asked Questions

1. What is phishing in simple words?

Phishing is a deception technique in which an attacker pretends to be trustworthy in order to trick someone into sharing information, clicking a malicious link, downloading harmful content or taking another action.

2. Is phishing a type of social engineering?

Yes. CISA describes phishing as a form of social engineering.

3. What is spear phishing?

Spear phishing is targeted phishing directed at a specific person or organization using information that makes the message more convincing.

4. What is smishing?

Smishing is phishing delivered through text messages or SMS.

5. What is vishing?

Vishing is phishing performed through voice communications such as phone calls.

6. What is whaling?

Whaling is targeted phishing aimed at a high-profile individual or other high-value target.

7. Can phishing steal passwords?

Yes. Credential theft is one of the major objectives of phishing campaigns.

8. Can phishing install malware?

Yes. Attackers may use malicious links or attachments to deliver malware. CISA identifies malware deployment as another major phishing objective.

9. Can I get phished through a text message?

Yes. This form is commonly called smishing.

10. Can a phone call be phishing?

Yes. Voice-based phishing is commonly called vishing.

11. Does HTTPS prevent phishing?

No. HTTPS protects communication between the browser and website but does not guarantee that the site itself is legitimate.

12. Is MFA useful against phishing?

Yes. MFA can reduce the impact of stolen passwords, and phishing-resistant MFA provides stronger protection against phishing attacks.

13. What should I do if I clicked a phishing link?

Stop interacting with the page, avoid entering further information, secure any potentially affected accounts, review recent activity and report the incident. If credentials were submitted, change the affected password through the legitimate service.

14. What should I do if I gave a scammer my password?

Change the password immediately through the legitimate service, change it anywhere else you reused it, review account activity and strengthen authentication.

15. Should I reply to a phishing email?

Generally no. Do not engage with suspicious senders. Use the appropriate reporting mechanism instead.

16. How can I verify a suspicious bank message?

Do not use the message link or reply to the message. Open the bank's official app or type its known website address yourself, or contact the institution through a trusted contact method.


Final Thoughts

Phishing works by exploiting trust, urgency and human behavior.

The attacker does not always need to defeat an advanced technical security system directly. Sometimes the easiest path is convincing a person to hand over the information or access instead.

Remember this simple process:

Suspicious Message
↓
STOP
↓
CHECK
↓
VERIFY INDEPENDENTLY
↓
REPORT IF NECESSARY

CISA recommends combining user awareness, reporting procedures, email-authentication controls and phishing-resistant authentication to reduce the effects of phishing.

Google similarly recommends not responding to unexpected requests for sensitive information and opening trusted services independently instead of relying on suspicious message links.

The most important habit is simple:

Never let a surprising message rush you into a security decision.

Slow down, verify independently and protect your credentials.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.