Phishing
Phishing: Fake Emails and Login Pages
Phishing is when someone pretends to be a trusted organisation to trick you into entering passwords, payment details, or other sensitive information.
Overview
What is it
Phishing is a deception in which an attacker impersonates a person or organisation you trust, such as a bank, a delivery firm, a government agency, or a colleague. The aim is to persuade you to sign in on a look-alike page, open a harmful attachment, or approve a payment. Legitimate organisations rarely demand instant action, and they never need your full password or your one-time security codes.
Entry point
How does it usually begin
Phishing usually arrives by email, but the same pattern appears in direct messages, calendar invitations, comment replies, and paid adverts. A typical message warns of a locked account, an unpaid invoice, a missed parcel, or a shared document, and it carries a link or attachment that leads to a fake page.
Psychology
The psychological play
Phishing leans on authority, urgency, and fear. A familiar logo and tone lower your guard, while a deadline or the threat of losing access stops you from pausing to check. Attackers also rely on routine and curiosity, because we open email and click links many times a day without thinking.
Warning signs
What to watch for
- The sender address is close to, but not exactly, the real domain.
- The message creates urgency or threatens account closure.
- A link points to a web address that does not match the organisation.
- You are asked for a password, a full card number, or a one-time code.
- The greeting is generic, or the spelling and layout feel slightly off.
- An unexpected attachment invites you to enable content or sign in.
Victim perspective
What the victim usually sees
You see a message that looks like it comes from a brand you use, with a button to sign in. The page looks familiar, but the web address is slightly wrong. After you enter your details you may be sent to the genuine site, so nothing appears to have gone wrong.
Anatomy
The anatomy of the deception
- 01
Contact
An email arrives that looks like it is from a service you use.
Defender move
Check the real sender address and where links actually lead before clicking.
- 02
Trust
The message copies familiar branding, tone, and layout.
Defender move
Treat branding as decoration and verify through an independent channel.
- 03
Pressure
A warning says your account will be closed or a payment will fail.
Defender move
Notice the deadline; urgency is a signal to slow down.
- 04
Request
You are asked to sign in, confirm details, or open an attachment.
Defender move
Never sign in from a link; navigate to the site yourself.
- 05
Payment or Information
You enter your password or payment details on the page.
Defender move
Use a password manager so it will not autofill on a look-alike domain.
- 06
Consequence
Your details are used to access your account or take payments.
Defender move
Change the password, turn on two-factor authentication, and report it.
Verification
What to verify
- 1Open the organisation's app or type its address yourself instead of using the link.
- 2Call the number printed on your card or statement, never the number in the message.
- 3Check the full web address, including the part after the first single slash.
- 4Ask yourself whether you were expecting this message at all.
Protection
How to protect yourself
- Turn on two-factor authentication using an app rather than text messages.
- Use a password manager, which will not autofill on a look-alike address.
- Keep devices and browsers updated so known bad pages are blocked.
- Treat any unexpected request for a password or code as hostile until verified.
If it happened
If you already responded
Act quickly, and don't blame yourself.
- 1Do not click anything else in the message.
- 2Change the password for the affected account and any account that reused it.
- 3Enable two-factor authentication and review recent account activity.
- 4Report the message to the impersonated organisation and to your national fraud service.
Examples
Real-world examples
Common examples include a fake parcel-redelivery notice, a fake bank security alert, a shared-document notification from a file service, and a fake payroll message asking you to confirm your details.
Sources
Where this comes from
Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.
- Verified factINSTITUTIONAL
Guidance on phishing and account protection
Microsoft Security · 01 Oct 2024
View source - Verified factINSTITUTIONAL
Phishing Activity Trends reporting
Anti-Phishing Working Group (APWG) · 05 Aug 2024
View source - Verified factGOVERNMENT
Guidance on phishing and social engineering
UK National Cyber Security Centre (NCSC) · 10 Jun 2024
View source
Spotted this pattern? Help others by reporting it.