Phishing
Phishing is an attempt to trick you into revealing credentials or payment details, usually through a fake website that imitates a real organization.
How it works
A message — typically email, though the same tactic appears over SMS (smishing) and voice calls (vishing) — links to a page cloned to look like a bank, delivery company, or other trusted service. The page captures whatever you type instead of logging you in anywhere real.
Common warning signs
- A domain that's close to, but not exactly, the real organization's.
- Urgency ('verify now or your account will be closed').
- A login form shown before any other content loads.
- A request to confirm a password or one-time code by clicking a link.
How to protect yourself
Never enter credentials on a page you reached by clicking a link in an unsolicited message — navigate to the real site yourself instead, and check the domain letter by letter before typing anything.
If it already happened
Change the affected password immediately on the real site, and check for reused passwords elsewhere.
