You get a text: "Your parcel is held - confirm your details here." Or an email that looks exactly like your bank, warning your account will be locked. That's phishing - and it's the most common way ordinary people get their accounts and money stolen in 2026. It doesn't break encryption or guess passwords; it tricks you into handing them over. This guide explains what phishing is, the types to recognise, how to spot it, and the defences that actually work.
Phishing is the best-known branch of social engineering.
Phishing isn't the only silent threat - a keylogger records what you type.
What phishing is
Phishing is a social-engineering attack: a scammer impersonates someone you trust to trick you into revealing credentials or data, or installing malware. It usually arrives as a message that manufactures urgency ("act now or lose access") and pushes you toward a fake login page or a reply with personal details.
The attack targets human judgement, not technology. That's why it works against even strong passwords - you're persuaded to type them into the attacker's page yourself.
The main types
- Email phishing - the classic mass campaign.
- Spear phishing - personalised to a specific target, far more convincing.
- Whaling - aimed at executives.
- Smishing - by SMS/text; vishing - by voice call (fake "support" or "bank").
- Clone phishing - copies a real message but swaps in a malicious link.
All share one goal: get you to act before you verify.
How to spot it
- Urgency or threats - "your account will be closed."
- A sender address that's subtly wrong - look closely at the domain.
- Mismatched links - hover to see the real destination; it won't match the claimed site.
- Requests for passwords or codes - legitimate services never ask.
- Generic greetings and unexpected attachments.
On mobile, links are harder to inspect - be extra careful. When unsure, don't click: type the address yourself or use the official app.
A phishing message, dissected
Picture a text: "NETFLIX: Your payment failed. Update your card within 24h or your account will be suspended: netflix-billing-secure.com/verify". Four red flags are stacked in one line:
- Manufactured urgency - "within 24h… suspended" pushes you to act before thinking.
- A look-alike domain -
netflix-billing-secure.comis not netflix.com; the real brand is only a prefix. Attackers love subdomains and hyphens (paypal.account-verify.io) because the trusted word still appears. - An unexpected channel - a real billing issue shows up in the app, not a random SMS link.
- A request to "update" payment via the link - legitimate services tell you to log in normally, never through a texted URL.
Train yourself to read the domain right-to-left: the true site is the part just before the first single slash (here, netflix-billing-secure.com), not whatever brand name appears earlier in the URL.
How to stop it
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
A password manager won't autofill on a fake site → NordPassAutofills only on the genuine domain · Zero-knowledge vault · Built-in breach scanner→- Never click links in unexpected messages. Navigate to sites directly.
- Turn on two-factor authentication so a stolen password alone isn't enough - and prefer phishing-resistant factors.
- Use a password manager. It only autofills on the genuine domain; if it refuses to fill, the site is probably fake - a built-in warning. (See why password managers are safe.)
- Verify "urgent" requests through a separate, trusted channel.
What to do if you already clicked
Falling for a phish isn't the end - speed limits the damage. If you entered credentials on a fake page:
- Change that password immediately, on the real site, and anywhere you reused it. Reuse is what turns one phish into many compromised accounts.
- Check 2FA on the affected account: confirm no unknown second factor or recovery email was added, and sign out all active sessions.
- Watch for the follow-up. Attackers often chain a phish with a fake "support" call (vishing) to extract your 2FA code - never read a code aloud to anyone.
- If it was a work account, tell IT now. Early reporting limits a breach far more than hiding the mistake.
- If you entered card details, contact your bank to freeze or reissue the card and watch statements.
The faster you rotate the password and revoke sessions, the smaller the window an attacker has - see what to do if an account is hacked for the full checklist.
Why passkeys and managers are phishing-resistant
Both bind to the real domain. A password manager autofills only on the exact legitimate site, so a look-alike page gets nothing. Passkeys and hardware keys (FIDO2/WebAuthn) go further: the login is cryptographically tied to the real site's origin, so even if you land on a fake page, it won't authenticate. That origin-binding is the real defence - see our best authenticator app guide, and if you think you've already been caught, what to do if an account is hacked.
The bottom line
Phishing tricks you into giving up credentials through fake messages and login pages - it beats strong passwords because it targets you, not your encryption. Spot it by its urgency, wrong sender and mismatched links; stop it by never clicking unexpected links, enabling phishing-resistant 2FA, and letting a password manager refuse to autofill on fakes. The habit of verifying before you act is the whole defence.
Editorial guide based on documented phishing techniques (email/spear/smishing/vishing) and standard defences (2FA, passkeys, password-manager domain-binding). Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
Lock down your accounts → NordPassStrong unique passwords · breach scanner · free tier→Frequently asked questions
What is phishing?
Phishing is a type of social-engineering attack where a scammer impersonates a trusted person or organisation - your bank, an employer, a popular service - to trick you into revealing sensitive information or credentials, or into installing malware. It usually arrives as a message (email, text, or chat) that creates urgency and pushes you to click a link to a fake login page or to reply with personal data. The name plays on 'fishing': the attacker baits many targets and waits for someone to bite.
What are the main types of phishing?
Several. Email phishing is the classic mass version. Spear phishing targets a specific person with personalised detail, making it far more convincing. Whaling targets executives. Smishing is phishing by SMS/text, and vishing is by voice call (often a fake 'support' or 'bank' agent). Clone phishing copies a real message you've seen before but swaps in a malicious link. They share one goal: get you to act - click, log in, pay, or share - before you stop to verify.
How do I spot a phishing attempt?
Watch for: a sense of urgency or threat ('your account will be closed'), a sender address that's subtly wrong, links whose real destination (hover to check) doesn't match the claimed site, requests for passwords or codes that legitimate services never ask for, generic greetings, and unexpected attachments. On mobile, links are harder to inspect - be extra cautious. When in doubt, don't click; go to the site directly by typing the address yourself, and contact the organisation through a number or app you already trust.
How do I protect myself from phishing?
Layer defences. Never click links in unexpected messages - navigate to sites directly. Turn on two-factor authentication so a stolen password alone isn't enough; phishing-resistant factors like passkeys or hardware keys are best because they won't authenticate on a fake domain. Use a password manager: it only autofills on the genuine domain, so if it refuses to fill, that's a red flag the site is fake. Keep software updated, and verify any 'urgent' request through a separate, trusted channel.
Why do passkeys and password managers help against phishing?
Because they bind to the real website's domain. A password manager autofills credentials only on the exact legitimate domain it saved them for - so on a look-alike phishing page it simply won't fill, which warns you. Passkeys (and hardware security keys using FIDO2/WebAuthn) go further: the cryptographic login is tied to the real site's origin, so even if you're fooled into visiting a fake page, the passkey won't authenticate there. That origin-binding is what makes them genuinely phishing-resistant, unlike a password you can be tricked into typing anywhere.


