What Is Phishing? Types, Examples, Warning Signs & Prevention
Have you ever received a message saying:
Or perhaps:
Or:
These are common examples of phishing.
Phishing is one of the most common forms of social engineering. Instead of depending entirely on a technical vulnerability, attackers often try to manipulate a person into clicking a link, opening an attachment, sharing credentials, approving an action or providing sensitive information.
CISA defines phishing as a form of social engineering where a cyber threat actor poses as a trusted colleague, acquaintance or organization to persuade a victim to provide sensitive information or network access. The lure may arrive through email, text message or phone call.
Google similarly describes phishing as attempts to steal personal information or gain access to online accounts using deceptive emails, messages, advertisements or websites that imitate services people already use.
This article explains phishing in simple language, including how it works, common types, warning signs, prevention techniques, reporting steps and what to do after interacting with a suspicious message.
What Is Phishing?
Phishing is a deceptive technique used to trick people into revealing information, clicking malicious links, downloading harmful files or taking actions that benefit an attacker.
The attacker often pretends to be someone trustworthy.
For example:
- A bank
- An employer
- A university
- A delivery company
- A social-media platform
- A cloud service
- A colleague
- A government organization
The objective is to create enough trust, fear, curiosity or urgency that the victim acts before checking the message carefully.
How Does Phishing Work?
A simplified phishing attack can look like this:
Attacker ↓ Creates Deceptive Message ↓ Impersonates Trusted Entity ↓ Victim Receives Message ↓ Victim Clicks / Responds / Downloads ↓ Attacker Attempts to Obtain Information or Access ↓ Possible Account or System Compromise
CISA's recent joint phishing guidance identifies credential theft and malware deployment among the primary objectives of phishing campaigns.
Why Is Phishing So Effective?
Phishing attacks target human decision-making.
Attackers may deliberately create:
- Urgency
- Fear
- Curiosity
- Authority
- Financial pressure
- Excitement
- Trust
For example:
Urgency: "Verify within 10 minutes."
Authority: "Your administrator requires this action."
Reward: "You have won a prize."
Google advises users to slow down when a communication creates urgency and to independently verify suspicious requests before providing information.
What Information Do Phishing Attacks Try to Steal?
Depending on the campaign, phishing messages may attempt to collect:
- Usernames
- Passwords
- Banking information
- Payment details
- PINs
- Identity information
- One-time verification codes
- Recovery information
- Business credentials
- Access tokens or session information
Google specifically warns users not to provide private or financial information in response to suspicious emails, texts, webpages or pop-ups.
Common Types of Phishing
Phishing is not one single attack technique.
Some common forms include:
- Traditional email phishing
- Spear phishing
- Whaling
- Smishing
- Vishing
- Business email compromise-related impersonation
- Clone phishing
CISA's phishing guidance identifies spearphishing, whaling, vishing and smishing among common types.
1. Email Phishing
This is one of the most familiar forms of phishing.
The victim receives an email designed to look legitimate.
Example
From: Security Team Subject: Urgent Account Verification We detected unusual activity on your account. Please verify your account immediately: [Verify Account]
The message may imitate a real company, but the link may lead somewhere else.
2. Spear Phishing
Spear phishing is targeted phishing aimed at a particular person or organization.
The attacker may use information about the target to make the message appear more believable.
For example, the attacker might know:
- The victim's name
- The company they work for
- Their job role
- A current project
- The name of a colleague
CISA describes spearphishing as phishing targeted at an individual using information about that person.
3. Whaling
Whaling is targeted phishing aimed at a high-profile individual, such as an executive or other person with access to sensitive information.
The objective can include:
- Credentials
- Financial information
- Business information
- Account access
CISA identifies whaling as phishing targeted at a high-profile individual to obtain sensitive or high-value information.
4. Smishing
Smishing is phishing delivered through SMS or text messages.
Example:
Your parcel could not be delivered. Update delivery information: https://example.invalid/verify
The message may appear to come from a shipping company even when it does not.
CISA identifies smishing as phishing delivered through text messages.
5. Vishing
Vishing is phishing conducted through voice communication, including phone calls.
For example, a caller may claim to be:
- Bank support
- Technical support
- Government personnel
- Company IT staff
- Account-security staff
The caller may attempt to persuade you to reveal a password, verification code or other information.
CISA identifies vishing as phishing through voice communication.
Google's current guidance also warns about phone scams in which attackers impersonate Google account-security personnel and attempt to obtain passwords, codes or fraudulent approval of login prompts.
6. Clone Phishing
In clone phishing, an attacker may create a deceptive message that resembles a legitimate message the victim has previously received.
The attacker may attempt to reproduce:
- Visual design
- Subject line
- Message structure
- Sender identity
- Link appearance
The copied message may contain a malicious replacement link or attachment.
7. Business Email Compromise
Business email compromise involves deceptive communications that attempt to manipulate employees or organizations into taking actions such as transferring money or sharing information.
These attacks can involve impersonation, compromised accounts or other forms of deception.
Because financial and business workflows are involved, organizations should verify sensitive requests using trusted communication channels.
Phishing vs Spam
People sometimes use the terms interchangeably, but they are different.
| Spam | Phishing |
|---|---|
| Usually unwanted messages | Deceptive messages intended to manipulate the recipient |
| Often advertising or bulk content | Often attempts to steal information or gain access |
| May be annoying | Can cause security or financial harm |
Some phishing messages can also be considered spam, but not all spam is phishing.
Phishing vs Malware
Phishing is a social-engineering technique.
Malware is malicious software.
They can be connected.
Phishing Message
↓
Malicious Attachment / Link
↓
Malware Download
↓
Potential System Compromise
CISA's 2025 joint guidance specifically identifies malware deployment as one of the major objectives of phishing campaigns.
Phishing vs Social Engineering
Social engineering is the broader concept of manipulating people into revealing information or taking actions that undermine security.
Phishing is one form of social engineering.
Social Engineering
|
+---- Phishing
|
+---- Impersonation
|
+---- Pretexting
|
+---- Other Manipulation Techniques
CISA describes phishing as a form of social engineering.
Common Signs of a Phishing Message
There is no single sign that proves a message is phishing, but several warning indicators can raise suspicion.
1. Suspicious Sender Address
The display name may look correct while the actual email address is different.
For example:
Display Name: Example Bank Actual Address: security@example-security.invalid
Always inspect the actual sender information.
CISA specifically lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.
2. Unexpected Urgency
Be careful with messages saying:
- "Act immediately"
- "Your account will be closed today"
- "Final warning"
- "Respond within 10 minutes"
Google recommends slowing down because scams frequently use urgency to pressure people into acting without verification.
3. Suspicious Links
A message may show text such as:
Verify your account
But the actual URL may point somewhere unexpected.
On a computer, hovering over a link before clicking can reveal the destination. Google specifically recommends checking whether the displayed destination matches the expected service.
Do not assume that a link is safe merely because it contains https://. HTTPS encrypts the connection to a website, but it does not prove that the website itself is legitimate.
4. Generic Greetings
Messages that use generic greetings such as "Dear Customer" can sometimes be suspicious, especially when combined with other warning signs.
CISA includes generic greetings among indicators worth checking.
5. Spelling or Formatting Problems
Incorrect spelling, strange formatting, unusual wording or inconsistent branding can indicate phishing.
However, modern phishing messages can be professionally written, so perfect grammar does not prove legitimacy.
6. Unexpected Attachments
Be cautious when an unexpected message asks you to open a file.
Examples include:
- Invoices
- Documents
- Compressed files
- Scripts
- Unknown installers
CISA lists suspicious attachments among common phishing indicators.
7. Requests for Private Information
Be particularly careful when an unexpected message asks for:
- Password
- OTP
- PIN
- Bank information
- Identity information
- Credit-card details
Google advises against responding to requests for private information through email, text or phone unless the request has been independently verified.
Phishing Example: Fake Bank Message
Imagine receiving:
URGENT: Suspicious transaction detected. Your banking access has been restricted. Verify your identity now: [Secure Account] Failure to respond within 15 minutes may result in permanent suspension.
Warning signs include:
- Urgency
- Fear
- Unexpected account action
- Request for information
- Unknown link destination
A safer response is to open the bank's official application or type its known website address yourself instead of using the message link.
Phishing Example: Fake Job Message
Congratulations! You have been selected for a remote IT job. Please pay a small registration fee and send your ID and bank details to complete your onboarding.
This contains several warning signs:
- Unexpected job offer
- Pressure to act
- Request for money
- Request for sensitive information
- Potentially unverifiable employer
Always independently verify the company and application process.
Phishing Example: Fake Delivery Message
Delivery failed. Please pay a small fee to reschedule your delivery. [Pay Delivery Fee]
Before clicking anything, ask:
- Am I actually expecting a delivery?
- Did I order anything from this company?
- Does the message match my order information?
- Can I verify the delivery using the official app?
How to Check a Suspicious Link Safely
Do not click first and investigate later.
Instead:
- Check the sender.
- Read the message carefully.
- Inspect the link destination.
- Look for spelling or domain inconsistencies.
- Open the organization's official website independently.
- Verify the request through a trusted channel.
Google recommends opening the legitimate site separately rather than using a suspicious email link when possible.
What Is Link Spoofing?
A phishing message can display one URL-like text while sending the victim somewhere else.
For example:
Displayed: https://trusted-example.com Actual destination: https://different-example.invalid/login
This is why checking the actual destination is important.
How Attackers Use Fake Login Pages
A phishing campaign may create a fake login page that visually resembles a legitimate service.
For example:
Fake Login Page
↓
Username
Password
Verification Code
↓
Attacker Receives Credentials
Google's guidance warns that phishing sites can imitate services users already know and trust.
This is why users should verify the domain and preferably navigate directly to the official service.
Can MFA Stop Phishing?
MFA can significantly improve account security, but not every MFA method provides the same protection against phishing.
CISA's phishing guidance recommends phishing-resistant multifactor authentication as an important protection for organizations.
Phishing can sometimes attempt to trick users into:
- Sharing a one-time code
- Approving a fraudulent login prompt
- Entering credentials into a fake site
For stronger protection, organizations can use phishing-resistant authentication technologies where appropriate.
What Is Phishing-Resistant MFA?
Phishing-resistant MFA is authentication designed to make it significantly harder for an attacker to use a fake website or deceptive interaction to capture reusable authentication information.
Modern methods can include cryptographic authentication technologies such as security keys and passkeys, depending on the service.
The important lesson is:
How Organizations Can Prevent Phishing
Phishing prevention should not rely only on individual users.
Organizations can combine technical and human controls.
Email Authentication
CISA recommends technologies such as:
- SPF
- DKIM
- DMARC
These technologies can help organizations establish and enforce email-authentication policies and reduce certain types of email impersonation.
User Education
Train employees to recognize:
- Suspicious sender addresses
- Fake links
- Unexpected attachments
- Urgency
- Requests for sensitive information
CISA recommends employee education and encourages reporting suspicious correspondence to the appropriate security team.
Technical Controls
Organizations may also use:
- Email filtering
- Domain reputation systems
- Malware scanning
- Web filtering
- MFA
- Endpoint protection
- Security monitoring
What Should You Do When You Receive a Suspicious Message?
Use this simple process:
STOP ↓ Do Not Click ↓ Do Not Reply ↓ Verify Independently ↓ Report ↓ Delete / Follow Organization Procedure
CISA's guidance recommends reporting suspicious messages to the appropriate security team and not forwarding malicious email to other employees within an organization.
What If You Already Clicked the Link?
Do not panic.
Take action quickly.
If You Only Opened the Page
Close the page and avoid entering information.
Review what happened and consider reporting the message.
If You Entered Your Password
Change the password through the legitimate service's official website or app.
If the password was reused elsewhere, change it on those accounts too.
If You Shared a Verification Code
Immediately secure the account through its official security controls and review recent activity.
Google recommends reviewing account security activity and securing the account when unfamiliar activity is detected.
If You Downloaded a File
Do not open it again. Follow your organization's security procedure or use trusted security software to assess the device.
If Financial Information Was Shared
Contact the relevant financial institution using a trusted, independently verified contact method.
How to Report Phishing
Reporting helps organizations investigate attacks and can help prevent additional victims.
For Gmail, Google provides a Report Phishing option within Gmail.
Within organizations, follow the company's security or IT reporting process.
For suspicious websites, Google also provides a mechanism for reporting phishing pages.
Phishing and Social Media
Phishing does not only happen through email.
Attackers can use:
- Direct messages
- Social-media posts
- Fake support accounts
- Chat applications
- SMS
- Voice calls
CISA advises people to remain alert across communication platforms, including social media.
Phishing on Messaging Apps
A scammer may send:
Your account violated our policy. Appeal here: [Link]
The same principles apply:
- Do not rush.
- Do not trust the message automatically.
- Verify through the official application or website.
- Do not reveal credentials.
Phishing and QR Codes
QR codes can also be used as part of phishing attempts.
A QR code can hide the destination URL behind an image, making it harder to visually inspect before scanning.
If you receive an unexpected QR code:
- Ask why it was sent.
- Verify the sender.
- Preview the destination where your device allows it.
- Navigate directly to the official service instead.
Phishing and AI
Modern generative AI can make it easier to produce convincing text, translations and impersonation material.
This means traditional clues such as spelling mistakes may be less reliable than they once were.
A stronger defense is to focus on:
- Unexpected requests
- Unusual payment instructions
- Unverified login requests
- Domain mismatches
- Urgency
- Requests for confidential information
- Independent verification
In other words:
How to Verify a Request
Suppose your manager sends a message asking you to transfer money.
Instead of immediately responding:
Message ↓ Verify sender through another trusted channel ↓ Confirm request ↓ Proceed only if legitimate
For sensitive actions, independent verification is one of the most useful defenses against impersonation.
Phishing Prevention Checklist
- □ Slow down when a message creates urgency.
- □ Check the actual sender address.
- □ Inspect links before opening them.
- □ Avoid unexpected attachments.
- □ Never share passwords through messages.
- □ Never share one-time verification codes with unexpected callers or messages.
- □ Verify financial requests independently.
- □ Use MFA.
- □ Prefer phishing-resistant authentication where available.
- □ Keep devices and applications updated.
- □ Report suspicious messages.
Phishing Prevention for Students
Students can be targeted with messages about:
- Scholarships
- Exam results
- University accounts
- Internships
- Jobs
- Certificates
- Fees
- Course registrations
Before clicking, ask:
Who actually sent it?
Does the domain look correct?
Can I verify this through the official university or organization's website?
Phishing Prevention for Employees
Employees should be particularly careful with:
- Payment requests
- Password-reset requests
- Cloud-storage invitations
- Unexpected file shares
- CEO or manager impersonation
- Urgent IT requests
- Vendor payment changes
Sensitive requests should follow established company procedures.
Phishing Prevention for Businesses
A business should use multiple layers of protection.
Email Authentication
+
Email Filtering
+
MFA
+
Endpoint Security
+
User Training
+
Reporting
+
Incident Response
↓
Reduced Phishing Risk
CISA's guidance similarly recommends combining technical protections, employee awareness and reporting procedures rather than relying on one control alone.
How Security Teams Respond to a Phishing Attack
A security team may follow a workflow such as:
User Reports Message
↓
Security Team Investigates
↓
Identify Indicators
↓
Search for Other Recipients
↓
Block Malicious Domains / Messages
↓
Investigate Any Compromise
↓
Contain and Remediate
↓
Review Lessons Learned
CISA notes that employee reporting can help incident responders determine whether an attack is isolated or widespread and identify indicators that can be used in security protections.
What Are SPF, DKIM and DMARC?
These are email-authentication technologies used to help organizations establish whether messages claiming to come from their domains are legitimate.
SPF
Sender Policy Framework allows domain owners to publish which mail servers are authorized to send mail for a domain.
DKIM
DomainKeys Identified Mail uses cryptographic signatures to help verify that a message is associated with the domain and has not been altered in transit in ways covered by the signature.
DMARC
Domain-based Message Authentication, Reporting, and Conformance builds on SPF and DKIM and lets domain owners publish policies and receive reports related to email authentication.
CISA specifically recommends SPF, DKIM and DMARC as part of organizational defenses against phishing and email impersonation.
Does HTTPS Prevent Phishing?
No.
HTTPS helps protect the connection between your browser and the website.
It does not automatically prove that the website is trustworthy.
For example:
https://legitimate-example.com
≠
https://malicious-example.com
Both may technically use HTTPS.
Therefore:
Can Antivirus Stop Phishing?
Security software can help detect malicious files, websites or other harmful activity, but it should not be treated as a complete phishing defense.
Human verification and secure authentication remain important.
A multilayer approach is stronger than relying on one product.
Can a Phishing Email Look Completely Real?
Yes.
Attackers can imitate:
- Logos
- Writing style
- Email layouts
- Company names
- Support messages
- Login pages
Therefore, do not assume:
"It looks professional, so it must be legitimate."
Google warns that phishing messages can look exactly like communications from people or organizations you trust.
Phishing Awareness: A Simple Rule
Use the following rule:
STOP: Do not react immediately.
CHECK: Look at the sender, link, request and context.
VERIFY: Contact the organization through an official channel.
ACT: Only continue once you know the request is legitimate.
Phishing Incident Response Checklist
If you suspect that you interacted with a phishing message:
- Stop interacting with the message.
- Change compromised passwords through the legitimate service.
- Review recent account activity.
- Revoke suspicious sessions where the service supports it.
- Enable or strengthen MFA.
- Contact the relevant organization or financial institution if necessary.
- Report the phishing message.
- Follow your company's incident-response procedure if it occurred at work.
Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.
Common Phishing Myths
Myth 1: Phishing Only Happens Through Email
False. Phishing can occur through text messages, phone calls, social media and other communication channels.
Myth 2: Bad Grammar Always Means Phishing
Not necessarily. Some phishing messages contain obvious mistakes, but sophisticated messages may be professionally written.
Myth 3: HTTPS Means a Website Is Safe
No. HTTPS protects the connection but does not prove the website is legitimate.
Myth 4: MFA Makes Phishing Impossible
No. MFA improves security, but attackers can try to trick users into sharing codes or approving fraudulent authentication requests. Phishing-resistant authentication provides stronger protection against some phishing scenarios.
Myth 5: Phishing Only Targets Large Companies
Phishing can target individuals, students, small businesses and large organizations alike.
Myth 6: Only Non-Technical People Fall for Phishing
Anyone can make a mistake, especially when a message is designed to create urgency or mimic a trusted source.
Frequently Asked Questions
1. What is phishing in simple words?
Phishing is a deception technique in which an attacker pretends to be trustworthy in order to trick someone into sharing information, clicking a malicious link, downloading harmful content or taking another action.
2. Is phishing a type of social engineering?
Yes. CISA describes phishing as a form of social engineering.
3. What is spear phishing?
Spear phishing is targeted phishing directed at a specific person or organization using information that makes the message more convincing.
4. What is smishing?
Smishing is phishing delivered through text messages or SMS.
5. What is vishing?
Vishing is phishing performed through voice communications such as phone calls.
6. What is whaling?
Whaling is targeted phishing aimed at a high-profile individual or other high-value target.
7. Can phishing steal passwords?
Yes. Credential theft is one of the major objectives of phishing campaigns.
8. Can phishing install malware?
Yes. Attackers may use malicious links or attachments to deliver malware. CISA identifies malware deployment as another major phishing objective.
9. Can I get phished through a text message?
Yes. This form is commonly called smishing.
10. Can a phone call be phishing?
Yes. Voice-based phishing is commonly called vishing.
11. Does HTTPS prevent phishing?
No. HTTPS protects communication between the browser and website but does not guarantee that the site itself is legitimate.
12. Is MFA useful against phishing?
Yes. MFA can reduce the impact of stolen passwords, and phishing-resistant MFA provides stronger protection against phishing attacks.
13. What should I do if I clicked a phishing link?
Stop interacting with the page, avoid entering further information, secure any potentially affected accounts, review recent activity and report the incident. If credentials were submitted, change the affected password through the legitimate service.
14. What should I do if I gave a scammer my password?
Change the password immediately through the legitimate service, change it anywhere else you reused it, review account activity and strengthen authentication.
15. Should I reply to a phishing email?
Generally no. Do not engage with suspicious senders. Use the appropriate reporting mechanism instead.
16. How can I verify a suspicious bank message?
Do not use the message link or reply to the message. Open the bank's official app or type its known website address yourself, or contact the institution through a trusted contact method.
Final Thoughts
Phishing works by exploiting trust, urgency and human behavior.
The attacker does not always need to defeat an advanced technical security system directly. Sometimes the easiest path is convincing a person to hand over the information or access instead.
Remember this simple process:
↓
STOP
↓
CHECK
↓
VERIFY INDEPENDENTLY
↓
REPORT IF NECESSARY
CISA recommends combining user awareness, reporting procedures, email-authentication controls and phishing-resistant authentication to reduce the effects of phishing.
Google similarly recommends not responding to unexpected requests for sensitive information and opening trusted services independently instead of relying on suspicious message links.
The most important habit is simple:
Slow down, verify independently and protect your credentials.
Recommended Reading on CodeWithAV
- Cybersecurity Roadmap for Beginners
- 50 Linux Commands for Cybersecurity Beginners
- Nmap Tutorial for Beginners
- What Is Ethical Hacking?
- What Is Penetration Testing?
- What Is a Vulnerability?
- Vulnerability vs Threat vs Risk
Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV articles after publication.
Official Resources
- CISA — Phishing Resources
- CISA/NSA/FBI/MS-ISAC — Phishing Guidance
- Google — Avoid & Report Phishing Emails
- Google — Prevent & Report Phishing Attacks
- Google — Suspicious Sign-In and Account Security
Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.