How to Recognize a Phishing Attack

A practical beginner's guide to identifying suspicious messages and links.

What Is Phishing?

Phishing is a type of social engineering attack in which someone attempts to trick you into revealing information, clicking a malicious link, opening a harmful attachment, or taking another unsafe action.

Phishing can arrive through email, text messages, social media, messaging applications, phone calls, or fake websites.

Common Warning Signs

1. Unexpected Messages

Be cautious when you receive an unexpected message asking you to log in, make a payment, open a file, or provide personal information.

2. Urgent or Threatening Language

Attackers may try to create panic by claiming that your account will be closed, your payment failed, or you must act immediately.

3. Suspicious Links

A link may look familiar while actually leading to a different website. Check the destination carefully before entering credentials or other sensitive information.

4. Unexpected Attachments

Treat unexpected attachments carefully, especially when you were not expecting a document, archive, executable file, or other download.

5. Requests for Sensitive Information

Be suspicious of unexpected requests for passwords, verification codes, financial information, or other sensitive details.

6. Unusual Sender Information

Check the sender's address or account carefully. Attackers may use addresses that resemble legitimate organizations while containing small differences.

How to Verify a Suspicious Message

  1. Stop before clicking the link or opening the attachment.
  2. Check who sent the message.
  3. Read the message carefully for unusual requests or inconsistencies.
  4. Inspect links without opening them when possible.
  5. Contact the organization using a trusted website or phone number.
  6. Use the organization's official app or website instead of the message link.

Why HTTPS Is Not Enough

A common mistake is assuming that a website is safe simply because its address begins with HTTPS.

HTTPS helps protect data traveling between your browser and a website, but it does not prove that the website itself is legitimate. Phishing websites can also use HTTPS.

Always consider the website address, the reason you were directed there, and whether the request makes sense.

What to Do If You Clicked a Phishing Link

Accidentally clicking a suspicious link does not automatically mean that your account has been compromised. What you should do next depends on what happened.

Phishing Safety Checklist

Remember

The safest response to a suspicious message is to slow down and verify before taking action. When something creates unnecessary urgency, take a moment to check the request through a trusted channel.

Practice What You Learned

Test your understanding of phishing and social engineering with our cybersecurity practice quizzes.

Take the Phishing Practice Quiz