How to Spot and Avoid Phishing Scams
Nearly everyone with an email address or a mobile phone has received a phishing attempt at some point, whether it looked like a message from their bank, a note about a missed parcel, or an urgent plea from someone pretending to be their boss. Phishing is the term for these scams: someone impersonates a trusted organisation or person, usually by message or call, to trick you into handing over passwords, personal details or money.
What makes phishing so persistent is that it doesn’t rely on breaking into anything technically. It relies on human psychology, on people being busy, distracted, or momentarily worried enough to click before they think. The scams themselves have also spread far beyond email, turning up in text messages, phone calls and even printed QR codes on parking machines.
This guide walks through the warning signs worth knowing, the different channels phishing now uses, what’s changed in recent years, what to do if you think you’ve already fallen for one, and where to report it in the UK. Scams evolve constantly, so treat this as general awareness rather than a promise that you’ll catch every single attempt.
- Urgency and pressure, being told you must act right now or face a consequence, is one of the most reliable signs of a phishing attempt.
- Phishing arrives by email, text message (smishing), phone call (vishing) and increasingly by QR code (quishing).
- Checking the real sender address and hovering over links before clicking still catches a large proportion of fake messages.
- AI writing tools have made phishing messages noticeably more polished and harder to spot on tone and grammar alone.
- If you’ve entered details on a fake site, change that password immediately, turn on two-factor authentication, and check for any other accounts using the same password.
- In the UK, suspicious emails can be reported to the National Cyber Security Centre’s Suspicious Email Reporting Service at report@phishing.gov.uk.
What exactly is phishing?
Phishing is a scam where someone poses as a bank, delivery firm, employer, government department or other trusted party to get you to click a link, open an attachment, or hand over information directly. The name is a deliberate play on “fishing”: the scammer casts out a wide net of messages and waits for someone to bite.
The end goal varies. Sometimes it’s to steal login details for your email, bank or shopping accounts. Sometimes it’s to capture payment card information. Sometimes the message wants you to install something, a fake delivery-tracking app, a document with hidden macros, or a piece of software disguised as an update, so that malicious code ends up running on your device. Occasionally the aim is simpler still: to get you to transfer money directly, often dressed up as an unpaid fee, a tax refund, or a favour for someone you know.
What ties all of this together is impersonation. Phishing messages often copy the branding, colour scheme, tone and layout of a genuine organisation closely enough to look convincing at a glance, especially on a small phone screen where logos are tiny and formatting differences are easy to miss.
Because phishing relies on you acting quickly without thinking too hard, slowing down before you click, tap, or reply is often the single most effective defence available to anyone, regardless of how tech-savvy they are.
What are the warning signs of a phishing message?
The clearest and most consistent warning sign is pressure. A message that insists you must act immediately, or that something bad will happen if you don’t, is behaving exactly the way a scam is designed to behave. Genuine organisations rarely demand instant action through a single unsolicited message.
- An urgent or threatening tone, such as a warning that your account will be suspended, a payment has failed, or a package will be returned to sender within hours.
- A sender address that looks almost right but isn’t quite the organisation’s genuine domain, perhaps with an extra word, a different ending, or a subtle misspelling.
- Generic greetings like “Dear Customer” instead of your actual name, when the organisation in question would normally know exactly who you are.
- Links that, when you hover over them on a computer or long-press on a phone, point to a web address that has nothing to do with the organisation being impersonated.
- Requests for information a legitimate organisation wouldn’t normally ask for by email or text, such as your full password, PIN, or a one-time passcode that was just sent to you.
- Unexpected attachments, particularly ones that ask you to “enable content” or run macros before you can view them.
- Small but odd details: a logo that’s slightly the wrong shade, unusual phrasing, or a signature that doesn’t match how that company normally signs off.
No single sign guarantees a message is fake, and no single sign guarantees it’s genuine either. It’s the combination, and particularly the presence of urgency alongside anything else on that list, that should make you pause.
It’s not just email: smishing, vishing and quishing
Phishing now spreads across several different channels, and it’s worth being alert on all of them rather than assuming a threat only arrives in your inbox. Scammers use whichever channel is cheapest and most likely to catch someone off guard, and that has shifted heavily towards text messages and phone calls in recent years, partly because spam filters on email have improved.
| Type | Channel | Typical disguise |
|---|---|---|
| Phishing | Bank, delivery courier, streaming service, employer IT team | |
| Smishing | SMS/text message | Delivery notification, missed parcel fee, bank fraud alert |
| Vishing | Phone call | Bank fraud team, tech support, government department |
| Quishing | QR code | Parking payment sticker, restaurant menu, delivery label |
Smishing texts tend to be short and blunt by necessity, often just a line or two claiming a delivery fee is owed or that suspicious activity has been spotted on an account, followed by a link. Because text messages feel more personal and immediate than email, and because most people trust their phone number as something private, smishing often gets a faster, less guarded reaction than an equivalent email would.
Vishing, the phone call version, relies on a confident, professional-sounding voice and often on caller ID that has been spoofed to display a number that looks genuine. A common tactic is to claim there’s suspicious activity on your bank account and ask you to “verify” yourself by reading out a code, transfer money to a “safe account”, or install remote access software so the caller can “help”. No genuine bank will ever ask you to move money to a new account to keep it safe, and that specific request is one of the most reliable giveaways of a vishing scam.
Quishing is the newest of the four and uses QR codes rather than clickable links, precisely because QR codes hide the destination address until you scan them. Fake codes have turned up stuck over genuine ones on parking meters and posters, sent by email as an “attachment” to bypass link-scanning security software, or printed on fake parking fine notices left on windscreens.
Why phishing is getting harder to spot
Many people find phishing messages harder to identify now than they did a few years ago, and the reasons are largely technical. Scammers increasingly use AI writing tools to produce messages that read fluently and naturally in English, without the clumsy grammar and odd phrasing that used to be a fairly dependable red flag. If you want to understand how these tools generate convincing text so easily, our plain-English guide to large language models explains the basics of how they work.
Design has also improved. Scam emails and fake websites now frequently use logos, colour schemes and layouts lifted directly from the genuine organisation, sometimes copied pixel for pixel from the real site’s source code. Fake login pages in particular can be visually identical to the real thing, which means the address bar, rather than the page itself, is often the only reliable clue that something is wrong.
Targeting has also become sharper. Rather than sending an identical message to millions of random addresses, some phishing attempts, sometimes called spear phishing, are built around information the scammer already has, such as your name, employer, or a recent purchase, making the message feel far more plausible and personal.
None of this means detection is hopeless. It means the checks that matter most have shifted slightly, away from spotting spelling mistakes and clumsy design, and towards verifying the sender, the link destination, and whether the request itself makes sense.
What to do if you’ve clicked a link or entered your details
If you’ve clicked a phishing link but haven’t entered anything or downloaded a file, close the page and don’t interact with it further. Simply visiting a link is usually low risk on its own, although it’s still worth staying alert for anything unusual on that device afterwards.
If you’ve entered a password or personal details on a fake site, the priority is to limit the damage quickly.
- Change the password for that account immediately, using the genuine website or app rather than any link from the suspicious message.
- If you’ve reused that password anywhere else, change it there too, since scammers routinely try stolen passwords against other popular sites. A password manager makes this far less painful, since it can generate and store a unique password for every account so one leak doesn’t put everything else at risk.
- Turn on two-factor authentication for the affected account if it isn’t already switched on. This means a stolen password alone usually isn’t enough for someone to get in.
- If you entered card details, contact your bank or card provider straight away so they can monitor for fraudulent transactions or issue a replacement card.
- If you downloaded and opened a file, run a full scan with reputable security software, and disconnect the device from the internet first if you suspect something is actively running.
If a device starts behaving strangely after clicking something suspicious, running unusually slowly, showing pop-ups it never used to, or draining its battery faster than normal, that’s worth investigating rather than ignoring. Our guide on how to speed up a slow laptop covers some of the checks worth running, including how to spot unwanted software that might be quietly using up resources in the background.
How to protect yourself day to day
The most reliable habit is a simple one: pause before clicking, and check the sender address rather than just the display name. Display names can be set to anything the sender likes, so a message that appears to be from “Royal Mail” or “Your Bank” can still come from a completely unrelated email address once you look closely at what’s actually behind it.
Hovering over a link before clicking, or long-pressing it on a phone, will usually reveal the actual destination address. If that address doesn’t match the organisation the message claims to be from, don’t click it. When in doubt about whether a message is genuine, it’s safer to go directly to the organisation’s website by typing the address yourself, or to call them using a number from a genuine source such as a bank card or a previous statement, rather than any number or link provided in the message itself.
Un
Sam Allcock is the founder and editor of Morrow Tech. He has spent over a decade in digital publishing and writes about the technology worth your attention, from AI to everyday gadgets.
