Phishing is a form of fraud in which attackers impersonate trusted people or organizations in order to steal passwords, payment information or other sensitive data.
1. Check the sender address
The displayed sender name can look legitimate while the actual email address belongs to a different domain. Small spelling changes and lookalike domains are common warning signs.
2. Be cautious with urgent requests
Messages claiming that an account will be closed or demanding immediate payment often attempt to pressure the recipient into acting without verification.
3. Inspect link destinations
The visible text of a link can be different from its actual destination. Always verify the domain before entering login credentials.
4. Avoid unexpected attachments
Files presented as invoices, shipping documents or payment confirmations may contain malicious content.
5. Verify unusual payment changes
Requests to change bank details or payment instructions should be confirmed through a second communication channel.
Other common warning signs
- Unusual language or spelling
- Requests that do not follow normal company procedures
- Requests for passwords or confidential information
- Unexpected QR codes
- Fake login pages designed to imitate real services
If a message looks suspicious, verify the sender before clicking links or opening attachments.