Skip to Main Content

Phishing

How phishing works across email, text, phone and QR codes — how to recognise it, and what to do in the first hour if you have already replied.

10 guides

Phishing

What is phishing? How it works, and how to recognise it

Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.

  • #phishing
  • #email
  • #fundamentals
5 min read
Phishing

I gave a scammer my password. What should I do?

Change the password on that account first, then sign out every device. That second step is the one people miss, and it is the one that actually removes the attacker. Here is the full order, and what changes if you also gave a code.

  • #phishing
  • #incident-response
  • #passwords
7 min read
Phishing

What is vishing? Voice phishing and cloned-voice calls

Vishing is phishing by phone call. It is the most psychologically effective form, because a live conversation removes the one thing that protects you in every other channel — time to think.

  • #phishing
  • #vishing
  • #phone-scams
4 min read
Phishing

What is smishing? Text message scams explained

Smishing is phishing by text message, and it is growing because phones are where the defences are weakest — links cannot be hovered, domains are truncated, and a text feels more personal than an email.

  • #phishing
  • #smishing
  • #sms
4 min read
Phishing

Phishing vs spear phishing: what's the difference?

Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.

  • #phishing
  • #spear-phishing
  • #comparison
4 min read
Phishing

I clicked a phishing link. What should I do?

Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.

  • #phishing
  • #incident-response
  • #how-to
5 min read
Phishing

Phishing email examples, annotated

Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.

  • #phishing
  • #email
  • #examples
4 min read
Phishing

How to identify a phishing email in under ten seconds

Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.

  • #phishing
  • #email
  • #how-to
4 min read
Phishing

How phishing works: the anatomy of an attack

A phishing attack has five stages, and only one of them is the message you see. Understanding the other four explains why the messages look the way they do, and where the chain is easiest to break.

  • #phishing
  • #email
  • #how-it-works
4 min read

Other topics