Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.
Change the password on that account first, then sign out every device. That second step is the one people miss, and it is the one that actually removes the attacker. Here is the full order, and what changes if you also gave a code.
A QR code is a link you cannot read. That single property removes every habit built around checking where a link goes, which is why attackers are sending millions of them every day.
Vishing is phishing by phone call. It is the most psychologically effective form, because a live conversation removes the one thing that protects you in every other channel — time to think.
Smishing is phishing by text message, and it is growing because phones are where the defences are weakest — links cannot be hovered, domains are truncated, and a text feels more personal than an email.
Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
A phishing attack has five stages, and only one of them is the message you see. Understanding the other four explains why the messages look the way they do, and where the chain is easiest to break.