Home » Latest Articles » A simple guide to phishing scams and how to avoid getting caught

A simple guide to phishing scams and how to avoid getting caught

Laptop screen phishing
Laptop screen phishing. Photo by Aerps.com on Unsplash.

Phishing used to mean clumsy scam messages full of spelling mistakes. Today it often looks like a convincing message from your bank, delivery service or even a colleague. One rushed click is enough to share passwords, card details or personal data with criminals.

The good news is that you do not need to be a security expert to protect yourself. With a few simple checks and habits, you can spot most phishing attempts and avoid the worst consequences if something slips through.

What phishing is and why it works so well

Phishing is when someone pretends to be a trusted organisation or person to trick you into giving information, money or access. It can arrive as a message, website, text, voice call or social media DM.

These scams work because they play on emotions. They create urgency, fear or excitement so you react first and think later. The message usually pushes you toward a quick action: click a link, open an attachment or confirm details.

Common types of phishing you see in everyday life

While details vary, many scams follow similar patterns. Recognising these patterns makes them much easier to ignore.

Fake delivery or invoice messages

You might see a message saying a package could not be delivered or a small fee is due. The link leads to a site that copies a real delivery service, then asks for card details or a login.

These often arrive during busy shopping seasons, when a surprise delivery feels believable. The amounts are kept small so you might not notice suspicious payments right away.

Account “problem” alerts

These claim that there is an urgent problem with an account: bank, streaming service, cloud storage, social network or something similar. You are told to “verify” or “reset” your account using a link or attachment.

The real goal is to collect your username, password or one-time code. Once they have it, criminals may try to log in to your real account or reuse that password elsewhere.

Impersonation of colleagues, friends or family

Sometimes scammers pretend to be someone you know, especially at work. You might get a short message from a “manager” asking you to buy gift cards, process a payment or share documents urgently.

On social media or messaging apps, fraudsters may take over real accounts and then contact friends or family with money requests or strange links.

Red flags that should make you pause

Most phishing attempts share a few warning signs. You do not need to see all of them at once, even one or two should make you slow down and double-check.

  • Unexpected contact:You did not start the conversation and the message appears out of nowhere.
  • Strong urgency:Phrases like “immediately”, “last chance”, “within 24 hours” are used to rush you.
  • Requests for sensitive data:Passwords, one-time codes, card numbers, full ID details or PINs.
  • Unusual payment methods:Gift cards, cryptocurrency or money transfer services for normal bills.
  • Suspicious links or addresses:Slight spelling changes, extra words, or domains that do not match the real site.

Simple checks before you click, pay or reply

A few seconds of checking can block most scams. You can turn these into quick routines that do not slow you down much.

Verify the sender, not just the display name

In messages, tap or hover over the sender to see the real address or number. Scammers often use names that look right but with strange domains, extra numbers or odd spelling.

If something looks off, ignore the message and contact the organisation through their official website, app or known phone number instead.

Inspect links without opening them

Person checking suspicious
Person checking suspicious. Photo by Centre for Ageing Better on Unsplash.

On a computer, hover your mouse over a link to see the real address. On a touchscreen, you can usually press and hold to preview the link without visiting the page.

Look for small changes: extra dashes, letters swapped around, unfamiliar domain endings or long strings of random characters. When in doubt, type the official address yourself into your browser rather than using the link.

Use separate paths to confirm urgent requests

If someone claims to be a colleague or family member who needs help, use a different channel to check. Call them, start a new chat, or send a message to a number or contact you already trust.

At work, follow your employer’s normal process for payments or data requests, even if the message sounds urgent or emotional.

What to do if you clicked or replied

Even careful people slip up sometimes. What matters most is how quickly you respond afterwards. Fast action can limit the damage significantly.

If you entered a password

Go directly to the real site by typing its address and change your password immediately. If you reuse that password on other services, change it there as well.

Turn on two-factor authentication if the service offers it. This adds an extra step when logging in, which makes it harder for criminals to use stolen passwords alone.

If you shared card or banking details

Contact your bank or card provider as soon as possible using the number from its official website or your card. Explain what happened and follow their guidance on blocking cards, reversing payments or monitoring activity.

Keep an eye on your statements for unexpected charges and report anything suspicious quickly. Many banks have dedicated fraud teams to help with these situations.

If malware might be involved

If you opened a strange attachment or file, run a full scan with trusted security software. If the scan finds problems, follow its steps to remove them.

Consider changing your passwords from a different, clean device, especially for important accounts like banking, primary email and social networks.

Tools and settings that give you extra protection

Technology cannot block every phishing attempt, but it can filter out many of the worst ones so you deal with fewer risky messages overall.

  • Spam and junk filters:Use built-in filters and do not disable them just to catch every message.
  • Security updates:Install updates for your operating system and apps, they often fix serious security holes.
  • Security keys or apps:Where possible, use stronger login methods for important accounts, not just SMS codes.
  • Password managers:These can auto-fill only on genuine sites, which helps you spot fake pages.

Teaching family and friends to stay safe

Many phishing victims are people who are less confident with technology. A short, patient conversation can make a big difference for parents, grandparents or younger relatives.

Show them what a fake message might look like, explain the biggest red flags and agree on simple rules. For example, you might agree that no one in the family will ever ask for passwords or one-time codes via message.

Encourage them to pause and ask before responding to anything urgent or strange. It is always better to double-check a real message than to rush and answer a fake one.

0 comments