What Phishing Actually Is
Phishing is a form of social engineering in which an attacker impersonates a trusted entity — your bank, a streaming service, a government agency, a shipping company, or even a colleague — to manipulate you into taking a harmful action. That action might be entering your login credentials on a fake website, downloading an infected attachment, approving a fraudulent payment, or providing sensitive personal information. The name comes from “fishing”: attackers cast a wide net of messages, knowing that even a small percentage of recipients will take the bait.The Three Main Types of Phishing
Email Phishing
The classic form. You receive an email that mimics a legitimate organization, complete with logos, formatting, and official-sounding language. The message typically directs you to a fake login page or prompts you to open an attachment.
Smishing (SMS)
Delivered by text message, smishing attacks often impersonate delivery companies, banks, or government agencies. They create urgency — “Your package could not be delivered” or “Your account has been suspended” — and include a link to a malicious site.
Vishing (Voice)
Voice phishing involves a phone call from someone claiming to be tech support, the IRS, your bank’s fraud department, or a similar authority. They may already know some of your personal information, making the call feel disturbingly legitimate.
How to Spot a Phishing Attempt
1
Check the Sender's Real Address
The display name in an email can say anything — “PayPal Security Team” or “Apple Support” — but the actual sending address tells the real story. Click or hover on the sender name to reveal the full email address. Legitimate companies always send from their own domain (e.g.,
support@paypal.com). Watch for lookalike domains like paypa1.com, apple-support.net, or extra subdomains like paypal.account-alert.com.2
Hover Over Links Before Clicking
Never click a link in a suspicious message without first checking where it actually leads. On a desktop, hover your cursor over the link and look at the URL preview in the bottom corner of your browser or email client. On mobile, press and hold the link to see the destination. If the URL doesn’t match the supposed sender’s official domain, do not click.
3
Look for Urgency and Fear Tactics
Phishing messages are engineered to override your critical thinking by creating panic. Phrases like “Your account will be closed in 24 hours,” “Unusual activity detected — verify now,” or “Final notice before legal action” are designed to make you act before you think. Legitimate organizations rarely demand immediate action through unsolicited messages. When you feel pressured, slow down.
4
Examine Branding and Language Carefully
Sophisticated phishing emails look nearly identical to legitimate ones, but inconsistencies often slip through. Look for mismatched fonts, low-resolution logos, awkward sentence structure, generic greetings like “Dear Customer” instead of your actual name, and unusual formatting. Even a single typo in an official-looking email is a red flag.
5
Verify Independently Before Acting
If a message asks you to take any action involving your account, payment information, or personal data, verify it through a channel you control — not through the message itself. Open a new browser tab and navigate directly to the organization’s official website. Call the company using a phone number from their official site, not one provided in the message. This single habit prevents the vast majority of successful phishing attacks.
Webroot’s real-time web filtering automatically blocks known phishing URLs before the page even loads in your browser. This provides a critical safety net for the moments when a convincing message slips past your guard, preventing your credentials from reaching attackers even if you do click a malicious link.
What to Do If You Clicked a Phishing Link
It happens to careful people too. If you think you’ve fallen for a phishing attempt, act quickly — the faster you respond, the better your chances of limiting the damage.Steps to take immediately after clicking a suspicious link
Steps to take immediately after clicking a suspicious link
- Disconnect from the internet if you suspect malware was downloaded. This cuts off any communication between malware and attacker-controlled servers.
- Change your password for any account that was targeted, and do so from a separate, trusted device. Use a strong, unique password you haven’t used elsewhere.
- Enable multi-factor authentication on the affected account if it isn’t already active. This prevents attackers from using stolen credentials even if they have your password.
- Run a full security scan using Webroot or your installed security software to check for malware that may have been silently installed.
- Contact your bank or card provider immediately if you entered any financial information. They can flag the account, block fraudulent charges, and issue new card details.
- Report the phishing message to your email provider (most have a “Report Phishing” option), the impersonated organization, and relevant authorities such as the FTC at reportfraud.ftc.gov.