Letter in the form of an icon on a laptop screen with a lock, emphasizing email protection against phishing.
Protecting personal data from phishing attacks

Phishing is a form of social engineering. An attacker pretends to be a bank, shop, email provider, colleague, or another trusted contact and tries to make the user hand over a password, card details, a verification code, or other sensitive information.

Most attacks follow a simple pattern. The message creates a reason to act: an account is about to be blocked, a payment looks suspicious, a parcel is waiting, or a manager needs something urgently. The link leads to a fake page, or the message contains an attachment. If the user enters data on that page, the attackers receive it.

A phishing message does not always look clumsy. It may be well written and carefully designed. Check the sender, the domain, the request itself, and the pressure behind it. The logo proves very little.

What Phishing Tries to Steal

Login details are a common target, especially for email, social networks, cloud services, hosting accounts, and online dashboards. Access to email is particularly useful to attackers: it may let them reset passwords elsewhere, read private conversations, search for documents, or send messages in the owner’s name.

Card details can be used for payments. One-time codes may confirm a login or transaction the user never started. Corporate data can help attackers prepare fake invoices, target colleagues, or enter internal systems.

Phishing also comes through more than one channel:

  • Email phishing. A message copies the style of a bank, delivery company, hosting provider, online store, or familiar platform and leads to a fake page.
  • Targeted phishing. The message is written for a specific person or company and may mention a real role, project, colleague, or recent event.
  • SMS phishing. The text refers to a parcel, fine, payment, or account restriction and includes a link.
  • Voice phishing. The caller claims to represent a bank, support team, or manager and asks for a code, an installation, or a payment.
  • Phishing in social networks and messaging apps. It may come from a compromised contact, fake support account, voting request, “gift,” or unexpected file.
  • Fake websites. A copied login page runs on a different domain and collects the credentials entered into it.

How to Spot a Phishing Email or Message

Start with the real sender address, not the display name. A message may show the name of a bank or company while the actual address belongs to an unrelated domain. Extra words, swapped letters, odd hyphens, unfamiliar domain endings, or an address that has nothing to do with the brand are all warning signs.

Pressure matters too. Messages such as “act within 15 minutes,” “your account will be blocked,” “the payment has already gone through,” or “do not tell anyone” are designed to stop you from checking. The same trick appears in messages about prizes, refunds, or gifts that must be claimed immediately.

A legitimate service should not ask you to send a password by email or chat. Do not give anyone a one-time code, approve a transaction you did not start, or read out recovery codes.

Unexpected attachments deserve caution, especially archives, executable files, documents asking you to enable macros, and files that do not fit the conversation. Links can also be disguised: the visible text shows one address, while the actual destination is different.

Spelling mistakes are common in phishing, but they are not required. A convincing message may contain none. One sign is rarely enough, so look at the whole picture.

How to Check a Suspicious Link or Website

On a computer, place the pointer over the link without clicking and read the full address. On a phone, press and hold the link to preview the URL. A shortened or unusually long address is not automatically malicious, but if it hides the destination, do not open it from the message.

The main domain is what matters. In login.example.com, the domain is example.com. In example.com.fake-site.net, the real domain is fake-site.net. Attackers often place a brand name in a subdomain, add hyphens, remove a letter, replace characters with similar ones, or make the URL long enough to hide the important part.

HTTPS and the lock icon only show that the connection is encrypted. They do not prove that the website is genuine. A phishing site can have a valid SSL certificate too.

When a message claims to come from a bank, shop, or online service, avoid its link. Open the official app, use a saved bookmark, or type the address yourself. Check the account directly. Contact support through details shown on the official website, not through a phone number or email address included in the suspicious message.

The Pressure Tactics Behind Phishing

Phishing works best when the user reacts before checking. Fear is created through warnings about a blocked account, unknown login, or payment. Curiosity and greed appear in messages about prizes, refunds, compensation, or gifts.

Workplace attacks often rely on authority: “the manager needs this invoice paid now,” “the supplier has changed its bank details,” or “approve this document before the end of the day.” Another common version looks harmless at first – a delivery notice, subscription reminder, or payment confirmation with a button to cancel.

Attackers follow current events, sales, and popular brands because familiar context lowers suspicion. A recognisable name or logo is not proof. Pause and verify the request through another channel.

How to Protect Yourself From Phishing

Use a separate, long password for every important service. If one password is stolen, it should not open your email, hosting account, social networks, and online bank at the same time. There is little value in changing all passwords on a fixed schedule. Uniqueness matters more, along with a fast change after suspected compromise.

A password manager helps create and store unique passwords. It usually links each login to a specific domain and may refuse to fill it on a different one. That is a useful warning, though not an absolute guarantee.

Enable two-factor authentication for email, banking, hosting, social networks, and cloud services. One-time codes can still be stolen, so do not enter them on a page opened from a suspicious message and never share them by phone. Where available, use a passkey or hardware security key. These options are harder to use on a fake login page.

Keep the browser, operating system, and applications updated. Review active sessions, recovery methods, and third-party access from time to time. Remove permissions you no longer need.

What to Do After Opening a Phishing Link

Opening a page does not always mean the device has been compromised. The next action matters.

You only opened the page. Close it. Do not download anything and do not allow notifications. Check that the browser and system are current. If the page offered an extension, profile, or application, make sure nothing was installed.

You entered a username and password. Open the real service from a trusted device and change the password at once. End other sessions, review recovery options, and enable 2FA. Replace the same password anywhere else it was reused.

You shared a verification code. Assume the attacker may have completed a login or transaction. Check active sessions, payments, and security settings immediately. For banking, call the bank using its official number.

You downloaded or opened a file. Avoid entering passwords on that device. Run a full security scan and inspect new applications, browser extensions, and startup items. On a work device, report the incident to the administrator or security team.

You entered card details. Contact the bank, explain what happened, and follow its advice on blocking or replacing the card. Review transactions and do not approve unknown payments.

After any suspected compromise, check the recovery email, phone number, forwarding rules, connected apps, and linked accounts. If messages may have been sent in your name, warn your contacts through another channel.

How Phishing Affects Businesses

One phishing email can lead to the loss of corporate email, a website, a server, or payment access. A compromised mailbox may be used to replace invoices and bank details, impersonate a manager, send more phishing messages, or search for internal files. The result may be financial loss, downtime, leaked data, and damage to the company’s reputation.

A single annual training session is not enough. Staff need short, regular reminders, a simple way to report suspicious messages, and a rule that financial requests must be confirmed through a second channel. A new bank account, urgent payment, or request for confidential data should be checked using a known phone number or another internal system.

Critical services should use 2FA. Access rights should also be limited to what each person needs. Mail filtering, attachment checks, logs, and an incident response plan help contain an attack. The plan should say who blocks the account, revokes sessions, checks logs, contacts the bank, and informs customers.

For corporate email on a custom domain, configure SPF, DKIM, and DMARC. They help verify message sources and reduce direct spoofing of the company domain, but they do not stop every phishing attempt. An attacker may use a similar domain or a real compromised mailbox. A domain for a website or company email can be registered on the RX-NAME domain registration page.

How to Report a Phishing Email or Website

Do not reply to the sender and do not forward a dangerous attachment to colleagues. Use the “Report phishing” option or send the message to the company’s security team.

If the message copies a bank, shop, or other service, report it to that service through official support. Contact the bank if payment details were exposed. In cases involving money or stolen data, keep the original messages, addresses, headers, screenshots, event times, and transaction details.

Frequently Asked Questions About Phishing

Can I Get a Virus Just by Opening an Email?

Opening the text of an email does not always infect a device. The risk rises after opening a malicious attachment, installing software, or using outdated software with known vulnerabilities.

Is a Website Safe If It Uses HTTPS?

No. HTTPS encrypts the connection but does not verify the owner’s intentions. Check the domain and open important services through an official app, bookmark, or manually entered address.

Can a Bank Ask for a Password or SMS Code?

Do not give a password, PIN, CVV, recovery code, or one-time code to a person who calls or messages you. A code may confirm a real action, but it should only be entered in a known official app or on a verified website.

How Can I Tell Whether a Login Page Is Fake?

Check the main domain, not the logo. Warning signs include misspellings, extra words, unusual subdomains, missing password-manager autofill, and a link that arrived in an unexpected message.

What Should I Do If I Entered My Password on a Phishing Site?

Change it immediately on the genuine website from a trusted device. End unauthorised sessions and review recovery settings. Replace the password in every other service where it was reused.

Does Antivirus Stop Every Phishing Attack?

No. It may block some dangerous pages and files, but it cannot always recognise a convincing fake or stop a user from entering data voluntarily.

Should I Block My Bank Card After Phishing?

If card details were entered or an unknown payment was approved, contact the bank immediately. Whether the card needs to be blocked or replaced depends on what was exposed and whether suspicious transactions occurred.

Quick Phishing Protection Checklist

  1. Check the sender’s address and the website’s main domain.
  2. Avoid unexpected links and suspicious attachments.
  3. Never share passwords, 2FA codes, PINs, CVVs, or recovery codes.
  4. Open banking, email, and other important services through an app, bookmark, or manually entered address.
  5. Use unique passwords, a password manager, and two-factor authentication.
  6. Keep the system, browser, and applications updated.
  7. Confirm urgent and financial requests through another channel.
  8. After a compromise, change the password, end active sessions, and check linked accounts.