What is a Phishing Scam?

A phishing scam is a type of social engineering attack where a scammer pretends to be a trusted person or organization to steal sensitive information or persuade you to take a risky action. This information can include passwords, bank account numbers, credit card details, Social Security numbers, one-time passcodes, or business payment instructions.

Phishing can affect individuals, families, small businesses, and large organizations. A single click can lead to account takeover, identity theft, malware infection, ransomware, invoice fraud, or unauthorized wire transfers.

Common Types of Phishing Scams

  • Email phishing: Fake emails that impersonate trusted brands, banks, delivery services, software tools, or employers.
  • Spear phishing: Highly personalized messages that use details about your job, company, contacts, or recent activity.
  • Smishing: Phishing through text messages, often involving package delivery alerts, bank warnings, toll notices, or account verification links.
  • Vishing: Voice phishing by phone, where scammers pretend to be tech support, a bank, law enforcement, or a government agency.
  • Business email compromise: Fraudulent messages that impersonate executives, vendors, or finance teams to redirect payments or request confidential data.
  • Quishing: QR code phishing that sends you to a fake website designed to capture login credentials or payment information.

How to Avoid Phishing

  • Phishing scams often create pressure so you act quickly instead of thinking carefully. How to avoid phishing scams:
    Unexpected requests for passwords, account numbers, payment details, or one-time codes.
  • Urgent language such as “act now,” “final notice,” “account suspended,” or “payment failed.”
    Sender addresses, phone numbers, or web addresses that look slightly wrong.
  • Links that do not match the company’s real website when you hover over them.
  • Attachments you were not expecting, especially invoices, shipping forms, or shared documents.
  • Generic greetings, unusual grammar, odd formatting, or inconsistent branding.
  • Requests to bypass normal procedures, keep a payment secret, or communicate only through the message thread.

Protecting Yourself from Phishing

  • Pause before you click. Scammers depend on urgency. Take a moment to inspect the message.
  • Verify through a trusted channel. Do not reply to a suspicious message or use the phone number inside it. Contact the company, coworker, or vendor using a number or website you already know is legitimate.
  • Use multi-factor authentication. MFA adds protection if a password is stolen, especially when paired with authenticator apps or security keys.
  • Use a password manager. Password managers can help you avoid entering credentials on fake websites because they usually will not autofill on the wrong domain.
  • Keep devices and apps updated. Updates fix security weaknesses that attackers may use after a successful phishing click.
  • Report suspicious messages. Reporting helps email providers, IT teams, and authorities detect scams faster.
  • Train employees regularly. For businesses, short and recurring phishing awareness training is more effective than a one-time annual reminder.