Line
Skip to main content
< All Topics
Print

Phishing Explained: How to Spot and Avoid Online Scams

What is Phishing?

Phishing is a type of online scam where attackers pretend to be someone you trust — such as a bank, delivery company, or even your workplace — to trick you into sharing personal or financial information.

These scams often arrive as emails, text messages, or fake websites that look real. Once you click a link or enter your details, cyber-criminals can steal your passwords, install malware, or gain access to your accounts.

Common goals of phishing include:

  • Stealing credit card or banking details

  • Gaining access to email or corporate systems

  • Spreading malware or ransomware

 Global Phishing Trends

Phishing continues to grow worldwide, becoming more sophisticated each year. Here are some key trends:

  • AI-generated phishing: Scammers use AI tools to create convincing, error-free messages.

  • Brand impersonation: Attackers mimic popular companies like Microsoft, Google, or PayPal.

  • SMS and WhatsApp scams (Smishing): Fraudulent links are sent through text or chat apps.

  • Targeted phishing (Spear Phishing): Personalized attacks aimed at specific people, such as company executives.

  • Fake login portals: Fraudulent Microsoft 365 or Google Workspace sign-in pages designed to steal passwords.

 How to Spot a Phishing Attempt

Watch out for these common red flags:

Warning Sign What It Means
Strange sender email The address looks off — maybe one letter is changed or added.
Urgent or threatening tone “Your account will be locked!” or “Act now to avoid suspension.”
Unexpected attachments or links Files or links you weren’t expecting.
Poor spelling or grammar Slight language mistakes are often a giveaway.
Mismatched web addresses Hover over a link before clicking — does it lead where it should?
Unusual requests Asking for payments, gift cards, or confidential data.

How to Protect Yourself

You can avoid most phishing scams by following these simple steps:

For Everyone

  • Think before you click: Check links and sender details carefully.

  • Use strong, unique passwords: Avoid using the same one for multiple accounts.

  • Turn on multi-factor authentication (MFA): Adds a second layer of security.

  • Keep devices updated: Install security patches and updates regularly.

  • Report suspicious messages: Don’t delete them — report them to your IT or security team.

For Businesses

  • Train employees with regular phishing awareness sessions.

  • Use email filtering and anti-phishing tools.

  • Enable DMARC, SPF, and DKIM to block fake company emails.

  • Have a clear reporting and response plan for suspected phishing attacks.

If You’ve Been Phished

If you think you’ve clicked a phishing link or shared your details:

  1. Change your passwords immediately.

  2. Notify your bank or IT/security team right away.

  3. Run an antivirus or malware scan on your device.

  4. Monitor your accounts for any suspicious activity.

Act quickly — the sooner you respond, the less damage scammers can do.

Stay Smart, Stay Safe

Phishing scams are becoming harder to spot, but awareness is your best defense.
Always pause before clicking links or sharing information. When in doubt — don’t click, report it!

Messenger