What Is Phishing?
Phishing is a type of social engineering attack in which someone attempts to trick you into revealing information, clicking a malicious link, opening a harmful attachment, or taking another unsafe action.
Phishing can arrive through email, text messages, social media, messaging applications, phone calls, or fake websites.
Common Warning Signs
1. Unexpected Messages
Be cautious when you receive an unexpected message asking you to log in, make a payment, open a file, or provide personal information.
2. Urgent or Threatening Language
Attackers may try to create panic by claiming that your account will be closed, your payment failed, or you must act immediately.
3. Suspicious Links
A link may look familiar while actually leading to a different website. Check the destination carefully before entering credentials or other sensitive information.
4. Unexpected Attachments
Treat unexpected attachments carefully, especially when you were not expecting a document, archive, executable file, or other download.
5. Requests for Sensitive Information
Be suspicious of unexpected requests for passwords, verification codes, financial information, or other sensitive details.
6. Unusual Sender Information
Check the sender's address or account carefully. Attackers may use addresses that resemble legitimate organizations while containing small differences.
How to Verify a Suspicious Message
- Stop before clicking the link or opening the attachment.
- Check who sent the message.
- Read the message carefully for unusual requests or inconsistencies.
- Inspect links without opening them when possible.
- Contact the organization using a trusted website or phone number.
- Use the organization's official app or website instead of the message link.
Why HTTPS Is Not Enough
A common mistake is assuming that a website is safe simply because its address begins with HTTPS.
HTTPS helps protect data traveling between your browser and a website, but it does not prove that the website itself is legitimate. Phishing websites can also use HTTPS.
Always consider the website address, the reason you were directed there, and whether the request makes sense.
What to Do If You Clicked a Phishing Link
Accidentally clicking a suspicious link does not automatically mean that your account has been compromised. What you should do next depends on what happened.
- Close the suspicious page.
- Do not enter passwords or sensitive information.
- Do not download or run unexpected files.
- If you entered a password, change it from the legitimate service.
- Enable two-factor authentication if available.
- Review recent account activity for unusual access.
- Run appropriate security checks on your device if a file was downloaded.
Phishing Safety Checklist
- Was I expecting this message?
- Do I recognize the sender?
- Is the request unusual or urgent?
- Does the link lead where I expect?
- Am I being asked for sensitive information?
- Can I verify the request through an official channel?
Remember
The safest response to a suspicious message is to slow down and verify before taking action. When something creates unnecessary urgency, take a moment to check the request through a trusted channel.
Practice What You Learned
Test your understanding of phishing and social engineering with our cybersecurity practice quizzes.
Take the Phishing Practice Quiz