Security

Phishing: recognise the request and respond safely

Phishing is a deception that impersonates a trusted person or organisation to make you disclose information, transfer money or take an unsafe action. It can arrive by email, text message, social media, telephone or a fraudulent website.

A suspicious parcel message leads to an imitation login while a genuine account app offers separate verification.

At a glance

  • A familiar name or logo does not establish the sender’s identity.
  • Urgency, secrecy and unexpected requests deserve independent verification.
  • A secure HTTPS connection can still lead to a fraudulent site.
  • A verification code can be stolen just like a password.
  • Your response depends on what you actually shared or opened.

How a phishing attempt works

The attacker presents a plausible reason to act: an unpaid delivery fee, a locked mailbox, a changed supplier account or a document shared by a colleague. The desired action may be small enough to seem harmless. Entering a password, approving an unexpected login or granting access to an account can be the real objective.

The visible sender name is only a label. Messages may come from lookalike addresses or an account that has already been compromised. An existing conversation is therefore useful context, but it is not proof that a new payment instruction or attachment is genuine. Verify the specific request through a separate, established channel.

Check the request before judging the design

Focus first on what the message asks you to do. Did you expect it? Does the request match a real order or conversation? Is someone asking for a password, recovery code, payment change or remote access? A polished layout and natural grammar are compatible with fraud; spelling mistakes are only one possible clue.

On a computer, inspect a link’s destination without opening it where the interface supports this. On a phone, avoid tapping merely to investigate. Shortened links, unfamiliar domains and confusing subdomains require care. Instead of trying to decode every suspicious URL, open the organisation’s known app or type its known address yourself.

Example: the delivery fee that becomes an account theft

You receive a text claiming a parcel needs a small extra payment. You are expecting a delivery, so the story feels timely. The linked page asks for card details and then a bank verification code. The small advertised fee does not limit what the attacker can do with the information supplied.

Open the carrier’s genuine app or use the tracking reference from the original order confirmation. Check whether the same action is required there. If the message claims to be from a supplier, use a contact number already in your records rather than the number in the message. This verifies the transaction without engaging with the suspicious link.

Choose the response that matches the exposure

Simply receiving a message differs from typing credentials or running an attachment. Record what happened: the time, device, account, information entered and files opened. Keep a screenshot or the original message if it can be saved safely. Do not forward a live malicious link to family or colleagues as an informal warning.

Use the genuine service’s reporting or recovery route. If money or card details are involved, contact the bank through its trusted app or an established telephone number promptly. Do not accept a follow-up caller’s claim that a transfer to a “safe account” is required. Such a call can continue the same deception.

  • If you only received the message, report it using the platform’s reporting control and remove it.
  • If you entered credentials, change the affected password through the genuine service and review sessions and recovery settings.
  • If you ran a file or allowed remote control, stop the interaction and seek device assessment before using that device for sensitive recovery.

A new password is only part of account recovery

An attacker may have added a recovery address, created an email forwarding rule or registered another device. Inspect security activity, signed-in sessions, connected applications and available recovery settings after regaining access. Remove unfamiliar items only when you understand their purpose; a household or work account may have legitimate shared access.

Change reused passwords on other affected accounts, giving particular attention to the email account used to reset them. Set up a supported stronger authentication method and securely retain its recovery material. Phishing-resistant methods can reduce specific credential relay risks, but they cannot make an unlocked device or an already approved fraudulent payment harmless.

When a device or business process may be involved

A download that you did not open does not establish that malware ran. An attachment that executed, an unexpected installed extension or granted remote access warrants closer assessment. Avoid repeatedly opening the item to see what it does. Keep business support staff informed about the actual action taken, rather than describing every suspicious message as a confirmed infection.

For a business payment change, pause the transaction and confirm the beneficiary with the supplier through a previously established contact. If a mailbox was accessed, consider what conversations or information it exposed and who needs to be informed through the organisation’s incident process. Technical recovery and any notification obligations require the actual facts; this overview does not determine legal duties.

Build a repeatable verification habit

Use unique passwords and protect both sign-in and account recovery. Keep software current, review unnecessary permissions and decide in advance how payment changes will be confirmed. A password manager that refuses to fill on an unfamiliar domain can provide a useful warning; deliberately copying the password around that warning removes the benefit.

Make it easy for household members or colleagues to report a mistake quickly. Blame and embarrassment delay useful information. A short rule works across many scams: stop when the request is unexpected, verify it independently and disclose only what is necessary through the genuine service. No filter or visual checklist catches every convincing attack.

Questions about this term

Does clicking a phishing link mean my account is already stolen?

Not necessarily. A click alone doesn’t prove an account takeover, and the risk depends on the page, your device and what you did next. Close the page and think about whether you entered information, approved a request, downloaded anything or granted permissions. Check the genuine account’s security activity if relevant. If a file ran or access was granted, assess the device before doing any sensitive recovery from it.

Can a phishing website use HTTPS?

Yes, it can. HTTPS protects the connection to the domain you reached, but it doesn’t show that the domain is the business you meant or that its owner is honest. A lookalike site can get a valid certificate for its own name. Check the destination, and verify unexpected requests through an app or address you already know rather than relying on a browser security symbol.

What if I gave away a one-time verification code?

Treat the account or transaction as possibly exposed, though please don’t be hard on yourself. A current code can help an attacker finish a sign-in or action while it is still valid. Use the genuine service straight away to review activity, end unfamiliar sessions and secure your recovery options. If the code approved a payment, contact your bank through a trusted channel, as changing a password alone may not cancel a transaction that has already been approved.

Should I reply to ask whether the message is genuine?

It’s better not to. A reply stays inside the channel the attacker may control, can confirm that your address is active and invites more persuasion. Contact the claimed sender through an address or number you already know, or look in the genuine account app. At work, use your organisation’s reporting process so the message and any exposure can be assessed without spreading the link.

How is phishing different from spam or malware?

Spam means unwanted bulk messages, phishing is deception meant to make someone act or give up information, and malware is harmful software. One message can fall into all three, but phishing can also work through a phone call or a false payment instruction without installing anything. The distinction helps you choose a response: secure exposed accounts and transactions, and assess a device when software or access was involved.

Technical sources

← All glossary terms