What is behind the message?
Phishing is an attempt to trick you into sharing information, opening harmful content or sending money by impersonating someone you trust. An attacker may pose as your bank, a delivery service or someone you know.
The example above combines a threat to block your account, a short deadline and a request for card details. Your task is to check the request before acting on it.
A familiar logo, signature or well-written message is not enough to confirm who is contacting you.
Why might the message feel personal?
Some messages reach many people. Others target you or your organisation, using a colleague’s name, a familiar supplier or details about your work. This targeted approach is called spear phishing.
Knowing your name does not make a request authentic. Check what you are being asked to do and whether you expected the request.
Where might you encounter phishing?
- Email: an unexpected invoice, attachment or invitation to sign in again.
- Texts and messaging apps: a notice about an account restriction, delivery or refund (smishing).
- Phone calls: someone posing as a bank or support service asks for confidential information (vishing).
- QR codes: a code leads to a page whose origin you have not checked (quishing).
Three questions before you act
Am I being rushed?
A short deadline and a threat to remove access are intended to make you skip checks. Urgency is a reason to pause, not evidence that you should trust the message.
What exactly am I being asked to do?
Look for requests for passwords, card details, one-time codes, payments or app installations. Do not share sign-in or transaction approval codes with someone requesting them in a message or call.
Can I check this independently?
An address can resemble a familiar one and a sender’s name can be copied. If you are unsure, do not rely on a link or number in the same message to complete your check.
How to verify the request
- Pause the action. Do not open an unexpected attachment or enter information through a suspicious link.
- Open the service yourself. Use the official app or a website address you already know. If needed, call the number on your card or the bank’s official website.
- Check the actual request. For a work message, contact your colleague through another known channel and follow your internal reporting procedure.
Two-factor authentication reduces the risk from a stolen password, but some methods can still be targeted by phishing. Read our 2FA guide.
If you have already clicked or shared information
If card details, your banking account or money are at risk, contact your bank immediately on its official number. Do not wait to finish the quiz or receive a response to an incident report.
| What happened | Next step |
|---|---|
| You only opened the page | Close it without entering information or downloading anything. Opening a page alone does not mean your account was taken over; if something downloaded or you notice changes, seek a device assessment. |
| You entered a password | From a device you have no reason to suspect is compromised, change the password through the official service, end other sessions and replace the same password on other accounts. |
| You entered card details or approved a payment | Tell your bank immediately what you entered or approved and follow its protective guidance. |
| You installed software or allowed device access | Disconnect the device from the network and seek technical help. For a work device, notify your IT or security team immediately. |
Keep the message, page address and time of the event without reopening suspicious content. In a report, describe what happened and the steps you have taken. Do not send passwords, PINs or one-time codes.