How to Identify Common Phishing Attacks

A fishing hook reaching toward an email envelope, representing a phishing attack

Phishing is the most common way accounts get stolen. An attacker sends a convincing-looking email, message or website that tricks you into handing over your password, payment details or other sensitive information — or into installing malware. The best defense is knowing what phishing looks like before you click.

What Is Phishing?

Phishing relies on social engineering: manipulating trust and emotion rather than breaking technical defenses. Attackers impersonate banks, delivery companies, government offices, coworkers or tech support. The message usually contains a hook — a problem, a prize, a deadline or a threat — designed to make you act before you think.

The Common Warning Signs

  • Unexpected contact. A message you were not expecting, out of the blue.
  • Urgency. "Your account will be closed in 24 hours if you do not act now."
  • Threats or fear. Claims of suspicious activity, legal action or missed payments.
  • Requests for credentials or money. Legitimate organisations rarely ask for login details or gift cards in a message.
  • Poor language or layout. Odd grammar, typos or mismatched branding.
  • An unknown link or attachment. The payload of most phishing messages.

Check the Sender, Not the Name

The display name is easy to fake. Always click (or hover) to reveal the actual email address.

  • Does the domain match the real organisation? "support@paypa1-security.com" is not PayPal.
  • Is it a public email like @gmail.com pretending to be your bank?
  • Does it contain slight misspellings or extra characters of a known brand?

If you have the slightest doubt, contact the organisation using a phone number or website you already know — not one from the message.

Hover over any link without clicking. Your browser or email client will show where it really points. Ask yourself: does this address match the site it claims to be? Attackers disguise links with clever text and shortened URLs.

Practical Tip

When in doubt, don't click. Type the known website address into your browser yourself, or use the official app.

Beware of Urgency and Fear

Scammers manufacture pressure so you skip your normal caution. Real organisations rarely demand that you act immediately and never over a random email. A legitimate "account problem" can be verified by calling the official number.

Beyond Email: Smishing and Phone Scams

Phishing also arrives by SMS (smishing) and phone calls (vishing). Text messages claiming missed deliveries, "fraud alerts" or one-time codes can be just as dangerous as email. The same rules apply: check the number, ignore the urgency, and verify through official channels. Never hand over a confirmation code to someone who called you.

What to Do If You Are Unsure

  • Do not reply, click or download.
  • Report it to your email provider using the "Report phishing" option if available.
  • If you clicked or entered details, act quickly: change your passwords, enable multi-factor authentication, and contact the real organisation and your bank. Review how strong passwords protect you.
  • When in doubt at work, tell your IT support or manager before doing anything.
Note: This article is educational guidance and cannot guarantee you will recognise every attempt. Attackers evolve constantly. When in doubt, slow down — the pause is the defense. See our Disclaimer.

Related Articles

Never Get Hooked Again

Practical awareness resources from We IT Services to keep you one step ahead.