Phishing is the number one way people get hacked and scammed — a fake message that tricks you into clicking a link or handing over a password. The good news: once you know the signs, they’re surprisingly easy to catch. Here’s how.
Note: Informational guide to help you recognise and avoid scams.
What phishing is
A phishing email pretends to be from a company you trust — your bank, a delivery service, Amazon, Microsoft — to get you to click a link, download a file, or enter your login. The link leads to a fake page that steals whatever you type.
The warning signs
Watch for these red flags:
- Urgency or fear: “Your account will be closed in 24 hours!” Scammers rush you so you don’t think.
- Unexpected requests for your password, payment, or personal details.
- Slightly wrong sender address —
support@amaz0n-security.cominstead of the real domain. - Generic greetings like “Dear Customer” instead of your name.
- Links that don’t match. Hover over a link (don’t click) to see the real destination.
- Spelling and formatting that feels off.
- Attachments you didn’t expect — a classic way to deliver malware.
Any one of these is a reason to slow down.
A quick example
“Your PayPal account has been limited. Click here to verify your information within 24 hours or it will be suspended.”
Red flags: urgency, a request to “verify” details, and a link that (on hover) goes to a random domain, not paypal.com. Real companies don’t threaten you into clicking.
The golden rule
Never click the link in a suspicious message. Instead, go to the company’s website or app directly (type the address yourself or use your bookmark) and check your account there. If there’s a real problem, you’ll see it.
What to do with a phishing email
- Don’t click, reply, or download anything.
- Don’t enter any details.
- Report it (most email apps have a “Report phishing” button) and delete it.
- If you already clicked or entered a password, act fast — change that password, turn on 2FA, and see what to do if you’ve been scammed.
Why phishing is getting sneakier
Scammers now use leaked data and AI to make messages more convincing and personal. That’s why unique passwords, 2FA, and passkeys matter — they limit the damage even if a scam succeeds.
Conclusion
Phishing works by creating urgency and impersonating people you trust — so slow down, check the sender, hover over links, and never enter details from a message you didn’t expect. When in doubt, go to the site directly. Learn these signs once and you’ll dodge the most common way people get hacked, every single time.

Leave a Reply