Skip to content

Phishing

Phishing: Fake Emails and Login Pages

Phishing is when someone pretends to be a trusted organisation to trick you into entering passwords, payment details, or other sensitive information.

High riskSafeGlobalCurrent
Last verified 9 February 2025
phishingemailsocial-engineeringaccount-security

Overview

What is it

Phishing is a deception in which an attacker impersonates a person or organisation you trust, such as a bank, a delivery firm, a government agency, or a colleague. The aim is to persuade you to sign in on a look-alike page, open a harmful attachment, or approve a payment. Legitimate organisations rarely demand instant action, and they never need your full password or your one-time security codes.

Entry point

How does it usually begin

Phishing usually arrives by email, but the same pattern appears in direct messages, calendar invitations, comment replies, and paid adverts. A typical message warns of a locked account, an unpaid invoice, a missed parcel, or a shared document, and it carries a link or attachment that leads to a fake page.

Psychology

The psychological play

Phishing leans on authority, urgency, and fear. A familiar logo and tone lower your guard, while a deadline or the threat of losing access stops you from pausing to check. Attackers also rely on routine and curiosity, because we open email and click links many times a day without thinking.

Warning signs

What to watch for

  • The sender address is close to, but not exactly, the real domain.
  • The message creates urgency or threatens account closure.
  • A link points to a web address that does not match the organisation.
  • You are asked for a password, a full card number, or a one-time code.
  • The greeting is generic, or the spelling and layout feel slightly off.
  • An unexpected attachment invites you to enable content or sign in.

Victim perspective

What the victim usually sees

You see a message that looks like it comes from a brand you use, with a button to sign in. The page looks familiar, but the web address is slightly wrong. After you enter your details you may be sent to the genuine site, so nothing appears to have gone wrong.

Anatomy

The anatomy of the deception

  1. 01

    Contact

    An email arrives that looks like it is from a service you use.

    Defender move

    Check the real sender address and where links actually lead before clicking.

  2. 02

    Trust

    The message copies familiar branding, tone, and layout.

    Defender move

    Treat branding as decoration and verify through an independent channel.

  3. 03

    Pressure

    A warning says your account will be closed or a payment will fail.

    Defender move

    Notice the deadline; urgency is a signal to slow down.

  4. 04

    Request

    You are asked to sign in, confirm details, or open an attachment.

    Defender move

    Never sign in from a link; navigate to the site yourself.

  5. 05

    Payment or Information

    You enter your password or payment details on the page.

    Defender move

    Use a password manager so it will not autofill on a look-alike domain.

  6. 06

    Consequence

    Your details are used to access your account or take payments.

    Defender move

    Change the password, turn on two-factor authentication, and report it.

Verification

What to verify

  1. 1Open the organisation's app or type its address yourself instead of using the link.
  2. 2Call the number printed on your card or statement, never the number in the message.
  3. 3Check the full web address, including the part after the first single slash.
  4. 4Ask yourself whether you were expecting this message at all.

Protection

How to protect yourself

  • Turn on two-factor authentication using an app rather than text messages.
  • Use a password manager, which will not autofill on a look-alike address.
  • Keep devices and browsers updated so known bad pages are blocked.
  • Treat any unexpected request for a password or code as hostile until verified.

If it happened

If you already responded

Act quickly, and don't blame yourself.

  1. 1Do not click anything else in the message.
  2. 2Change the password for the affected account and any account that reused it.
  3. 3Enable two-factor authentication and review recent account activity.
  4. 4Report the message to the impersonated organisation and to your national fraud service.

Examples

Real-world examples

Common examples include a fake parcel-redelivery notice, a fake bank security alert, a shared-document notification from a file service, and a fake payroll message asking you to confirm your details.

Sources

Where this comes from

Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.

  • Verified factINSTITUTIONAL

    Guidance on phishing and account protection

    Microsoft Security · 01 Oct 2024

    View source
  • Verified factINSTITUTIONAL

    Phishing Activity Trends reporting

    Anti-Phishing Working Group (APWG) · 05 Aug 2024

    View source
  • Verified factGOVERNMENT

    Guidance on phishing and social engineering

    UK National Cyber Security Centre (NCSC) · 10 Jun 2024

    View source

Spotted this pattern? Help others by reporting it.