How Phishing Actually Works
Phishing is the con that starts most break-ins: a message that impersonates someone you trust to steal your password or money. Learn the playbook so you can spot it every time.
Phishing is the single most common way real accounts get compromised, and it has nothing to do with technical wizardry. It's a confidence trick: a message pretending to be someone you trust — your bank, a delivery company, a coworker, Apple or Microsoft — designed to make you hand over a password or click something you shouldn't. Once you understand the playbook, the same tricks start jumping out at you.
The basic move
Almost every phishing attempt follows the same three beats: impersonate a trusted sender, manufacture a reason to act right now, and steer you to a fake page that harvests what you type. The message might warn that your account is locked, a payment failed, a package is stuck, or someone logged in from a strange place. The details change; the shape does not.
The pressure is the point
Notice how these messages make you feel. Real phishing leans on emotion because a rushed, worried person doesn't stop to check. The most common levers are:
- Urgency — "Act within 24 hours or your account will be closed."
- Fear — "Unauthorized login detected. Was this you?"
- Greed or curiosity — "You've received a refund," or a package you didn't order.
- Authority — a message that looks like it's from your boss, the IRS, or tech support.
The single most useful habit in your whole security life is this: when a message makes you feel urgent, slow down. That feeling is the attack working.
The tells that give it away
- The link doesn't match the sender. Hover over it (or press and hold on a phone) to preview the real address. "Your bank" linking to a random domain is the whole scam. When unsure, run it through the suspicious link checker.
- The greeting is generic. "Dear Customer" from a company that knows your name is a red flag.
- It asks for something no real company asks for — your password, a 2FA code, or a payment in gift cards.
- Small errors. Odd grammar, a slightly-wrong logo, or an address like support@paypa1.com.
Adopt one rule: never log in or pay from a link in a message. If your bank "emails" you, open the app or type the website address yourself. That single habit defeats the vast majority of phishing, because the fake page never gets a chance to load.
What to do when you're not sure
Don't reply, don't click, and don't call any number the message gives you. Instead, reach the company through a channel you already trust — the app, the number on the back of your card, or the website you type in yourself. If a message seems to come from a person you know but feels off, verify through a different channel; a quick text to their real number settles it.
Want to sharpen your eye? Run through the interactive phishing quiz, and if you think you already clicked something, go straight to the clicked a phishing link steps. The companion lesson, spotting scam emails, texts, and calls, covers the fast-moving variants.
Phishing isn't just email anymore
The word "phishing" makes people picture a dodgy email, but the same con now arrives through whatever channel is most likely to catch you off guard.
- Text messages ("smishing") — fake delivery notices, toll charges, and bank alerts with a tappable link.
- Phone calls ("vishing") — a "fraud department" or "tech support" agent walking you toward a password or payment.
- Social media and chat — hijacked accounts of people you know, or fake support replies to your public complaints.
- Fake login pages reached through search ads that sit above the real result.
The channel changes; the playbook — impersonate, pressure, harvest — does not, which is why one set of habits covers all of them.
When it's aimed at you personally
Most phishing is a mass net, but "spear phishing" targets a specific person using real details — your name, employer, or a recent purchase — often scraped from a data breach or your public posts. These feel far more convincing precisely because they're accurate. The defense doesn't change: no matter how personalized a message is, don't log in or pay through it. Reach the company or person independently, and the fake page never gets its moment. It's also why sharing less pays off — the fewer details floating around, the harder you are to target convincingly.
One last reassurance: you don't need to catch every trick or grow suspicious of everyone. Keeping the single habit of never logging in or paying from a message does the heavy lifting, and the rest just sharpens an instinct you'll build naturally the more you practice it.
Key takeaways
- Phishing impersonates someone you trust and manufactures urgency to rush you.
- The feeling of urgency is the signal to slow down and verify.
- Check where links really go, and never enter a password or code from a link.
- Reach companies through the app or a number you already trust — never the one in the message.
Quick quiz
A couple of quick questions to lock in what you just read. Nothing is saved — pick an answer to see if you got it.
-
At its core, phishing is best described as:
Phishing does not break your security; it persuades you to give it up.
-
Which feeling is the biggest warning sign of a phishing attempt?
Urgency and fear are used to short-circuit your caution. The feeling itself is the red flag.
-
What is the reliable defense against phishing?
Verify through a channel you already trust, not the one that contacted you.
Keep going
Subscribe for new lessons and a printable security checklist.