Phishing is not limited to obvious spelling mistakes. Modern scams can copy a company’s design, use a believable sender name and refer to real services. The goal is usually to steal a password, payment detail or verification code.
Check the sender address, not only the name
A message can say it is from your bank or a delivery company while using an unrelated address. Tap or hover over the sender to see the full address. Look carefully for added words, misspellings or a different domain ending.
Be cautious with urgency
“Your account will be closed today” or “act in the next ten minutes” are designed to bypass your judgment. Real companies may send security notices, but you can safely open a new browser tab and visit their official website instead of using the email link.
Inspect links before you click
On a computer, hover over a link to preview its destination. On a phone, press and hold it. A legitimate-looking label can lead to an unrelated address. Do not enter credentials into a page reached through a suspicious message.
Treat unexpected attachments carefully
Unexpected invoices, shared documents and delivery files can be malicious. Confirm with the sender through a separate channel before opening an attachment, especially if it asks you to enable editing, macros or a download.
If you already clicked
- Do not panic. Close the page without entering information if possible.
- If you entered a password, change it immediately from the official service website.
- Turn on two-factor authentication if it is available.
- Run a security scan if you downloaded or opened a file.
- Tell your workplace IT team if the message involved a work account.