What Is Phishing? The Complete Guide to Phishing Scams, Attacks, and How to Stay Safe

Phishing is the single most common entry point for cybercrime in the world. More data breaches, more ransomware attacks, more identity thefts, and more financial frauds begin with a phishing email, text, or call than with any other method. The FBI’s Internet Crime Complaint Center received more than 298,000 phishing complaints in 2023 — more than any other category of cybercrime — with losses exceeding $18 million.

Despite its dominance, phishing remains widely misunderstood. Most people think of it as obviously fake emails full of typos asking for your bank password. The reality in 2025 is far more sophisticated: AI-generated messages indistinguishable from real communications, voice calls that clone the voice of someone you know, fake websites with valid SSL certificates, and targeted attacks built from months of social media research about your specific life.

This guide covers everything — what phishing is and how it works, the six types of phishing you need to know, how to spot every common red flag, what to do if you clicked a phishing link, how to report phishing, and the specific brand-impersonation scams that generate the most searches and the most victims every year.

What Is Phishing?

Phishing is a type of social engineering attack in which a criminal impersonates a trusted entity — a bank, a government agency, a technology company, an employer, or even a personal contact — to trick a victim into surrendering sensitive information, clicking a malicious link, downloading malware, or sending money.

The name comes from “fishing” — casting a wide net (or a carefully baited hook) and waiting for someone to bite.

Unlike technical hacking, phishing doesn’t exploit software vulnerabilities. It exploits human psychology — specifically, trust, urgency, fear, and the tendency to act quickly when something appears to come from a legitimate authority. This is why it works. Even technically sophisticated people click phishing links when the message is convincing enough and arrives at the wrong moment.

The defining characteristics of a phishing attack:

– Impersonation of a trusted entity

– A call to action (click this link, verify your account, confirm your payment, call this number)

– A mechanism for capturing the victim’s response (a fake login page, a fraudulent phone number, a malware payload)

– A sense of urgency or threat designed to suppress critical thinking

How Phishing Works — The Mechanics of an Attack

Understanding the mechanics of a phishing attack demystifies why they’re so effective.

Step 1: The attacker selects a target and builds a lure.

In mass phishing campaigns, the “target” is anyone who receives the email. In spear phishing (targeted attacks), the attacker researches the specific victim — their employer, their bank, their recent purchases, their social connections — to build a highly personalized message.

Step 2: The message is delivered.

Delivery can happen via email (classic phishing), text message (smishing), phone call (vishing), social media direct message, or even in-person via a USB drive or QR code. The message impersonates a trusted entity and contains a call to action.

Step 3: The victim is directed to a capture mechanism.

Clicking the link in a phishing email takes the victim to a fraudulent website that looks identical to the real one. The victim enters their username, password, credit card number, or other sensitive information — which is immediately captured by the attacker.

Step 4: The attacker uses the captured information.

Login credentials are used to access the victim’s real accounts. Financial information is used to commit fraud. Personal information is used for identity theft. In some cases, the “capture” is malware downloaded when the link is clicked — no information entry required.

Step 5: The victim may not know for days, weeks, or months.

Sophisticated phishing sites often redirect the victim to the real website after capturing their credentials, so the login appears to succeed normally. The victim has no idea their credentials have been stolen.

The 6 Types of Phishing You Need to Know

Not all phishing uses email. The six types below represent the full spectrum of phishing attacks in use today.

  1. Email Phishing (Classic Phishing)

The original and still most common form. Mass emails impersonating banks, retailers, streaming services, government agencies, and technology companies, sent to millions of addresses simultaneously. The goal is to trick recipients into clicking a malicious link, downloading an attachment, or entering credentials on a fake login page.

→ Full guide: https://www.scammed.org/phishing/email-phishing/

  1. Spear Phishing

Targeted phishing directed at a specific individual or organization. Unlike mass phishing, spear phishing uses personalized information — your name, your employer, your role, your recent activity — to make the attack highly convincing. Spear phishing is responsible for the majority of corporate data breaches and is the technique used in most sophisticated attacks against executives, government officials, and high-value targets.

→ Full guide: https://www.scammed.org/phishing/spear-phishing/

  1. Smishing (SMS Phishing)

Phishing delivered via text message. The explosion of package delivery notifications, two-factor authentication texts, and mobile banking alerts has given smishing attackers a broad template of believable messages to impersonate. Common smishing lures include fake USPS/UPS/FedEx delivery notifications, fake bank fraud alerts, fake DMV notices, and toll road payment scams.

→ Full guide: https://www.scammed.org/phishing/smishing/

  1. Vishing (Voice Phishing)

Phishing conducted over the phone. A caller impersonates the IRS, Social Security Administration, your bank’s fraud department, a tech support company, or even a family member in distress. Modern vishing attacks increasingly use AI voice cloning to sound exactly like someone the victim knows and trusts.

→ Full guide: https://www.scammed.org/phishing/vishing/

  1. Whaling

Spear phishing specifically targeted at high-level executives — CEOs, CFOs, and other senior leaders. Also called “CEO fraud” or “Business Email Compromise” (BEC). The goal is typically to trick an executive or their assistant into authorizing large wire transfers or providing access to sensitive systems. Whaling attacks caused $2.9 billion in losses in 2023 according to the FBI.

→ Full guide: https://www.scammed.org/phishing/whaling/

  1. Pharming

A more technical form of phishing where the attacker corrupts the DNS (Domain Name System) or the victim’s computer settings to redirect legitimate website requests to a fraudulent server — even if the victim types the correct web address. The victim ends up on a fake site without clicking any suspicious link. Pharming is less common but particularly insidious because it bypasses the “don’t click suspicious links” advice.

→ Full guide: https://www.scammed.org/phishing/pharming/

How to Spot a Phishing Email — 10 Warning Signs

Training yourself to recognize phishing is one of the most practical security skills you can develop. Here are the ten warning signs that an email may be a phishing attempt:

Warning Sign 1: The sender’s email address doesn’t match the supposed sender’s domain.

The display name may say “PayPal Security” but the actual sending address — visible when you hover over or click the sender name — is something like paypal-security@notification-center-mail.com. Legitimate companies send email from their own domains.

Warning Sign 2: There is a sense of urgency or threat.

“Your account will be suspended in 24 hours.” “Unusual sign-in activity detected — verify immediately.” “Your payment has failed — update now or lose access.” Urgency is the most common manipulation tactic in phishing because it suppresses the critical thinking that would otherwise catch the scam.

Warning Sign 3: The link doesn’t go where it says it goes.

Hover over any link (without clicking) and look at where the URL actually points. A link that says “paypal.com” but points to “paypa1.com” or “paypal.secure-verify.net” is fraudulent. Look for misspellings, extra words, or completely unrelated domains.

Warning Sign 4: The email asks you to enter personal information.

Legitimate companies do not ask you to submit passwords, Social Security numbers, credit card numbers, or bank account information via email. Ever.

Warning Sign 5: The greeting is generic.

“Dear Customer,” “Dear User,” “Dear Account Holder.” Legitimate companies know your name. Generic greetings are a tell that the message was sent to millions of people.

Warning Sign 6: There are attachments you weren’t expecting.

Phishing emails frequently contain malicious attachments — PDFs, Word documents, ZIP files — that install malware when opened. Never open an unexpected attachment, even from someone you know, without verifying they actually sent it.

Warning Sign 7: The email promises something too good to be true.

A refund you didn’t request. A prize you didn’t enter. A package you weren’t expecting. These are designed to create excitement that overrides suspicion.

Warning Sign 8: The branding looks slightly off.

Logos that are slightly distorted or blurry, colors that don’t quite match, fonts that are wrong, and layouts that look slightly different from the real company’s emails. Attackers copy and paste real brand elements but rarely get them perfectly right.

Warning Sign 9: There are grammatical errors or awkward phrasing.

While AI-generated phishing is increasingly polished, many attacks — particularly those originating overseas — contain grammatical errors, unusual word choices, or phrasing that doesn’t read naturally in English.

Warning Sign 10: The email is from a company you don’t use.

A PayPal security alert when you don’t have a PayPal account. A Netflix billing notification when you’re not a subscriber. A bank fraud alert from a bank you’ve never banked with. These are obvious tells that the email is mass-blast phishing.

What to Do If You Clicked a Phishing Link

Clicking a phishing link is not the end of the world — but it does require immediate action to minimize potential damage.

Step 1: Don’t enter any information.

If you clicked a link and were taken to a page asking for your username, password, or financial information — do not enter it. Close the browser tab immediately.

Step 2: Disconnect from the internet if you downloaded anything.

If clicking the link triggered a download, disconnect your device from Wi-Fi and mobile data immediately. This limits the ability of any malware to communicate with the attacker’s server.

Step 3: Run a full security scan.

Use your antivirus software to run a full scan of your device. If you don’t have antivirus software, this is the moment to install a reputable product (Malwarebytes, Bitdefender, Norton, or Windows Defender for Windows users).

Step 4: Change your passwords.

Change the password for any account that the phishing message was impersonating, and for any account where you use the same password. Do this from a different device if possible.

Step 5: Enable two-factor authentication.

If you haven’t already, enable 2FA on every account that supports it — especially email, banking, and social accounts.

Step 6: Contact your bank if financial information was entered.

If you entered credit card numbers, bank account information, or other financial details on the fake site, call your bank’s fraud line immediately. Request new card numbers and review recent transactions.

Step 7: Monitor your accounts and credit.

Watch for unauthorized transactions over the coming days and weeks. Pull your credit reports to check for new accounts you didn’t open.

Step 8: Report the phishing attempt.

→ See: How to Report Phishing

The Most Impersonated Brands in Phishing Scams

Phishing attackers overwhelmingly impersonate a small set of high-trust, high-recognition brands. These are the most commonly impersonated companies in phishing attacks in the U.S., with dedicated alert pages covering each:

PayPal — paypal scam email 18K/mo. The most frequently impersonated financial service. Common lures include fake invoice notifications, account limitation warnings, and “unusual activity” alerts.

https://www.scammed.org/phishing/paypal-scam-email/

Geek Squad / Best Buy — geek squad scam email 12K/mo. Fake renewal invoices — often for $299 to $499 — impersonating Geek Squad’s Total Tech Support subscription. Designed to trick recipients into calling a fraudulent phone number.

https://www.scammed.org/phishing/geek-squad-scam-email/

McAfee — mcafee scam email 12K/mo. Fake antivirus renewal notices and virus detection alerts designed to get victims to call a tech support scam number or enter payment information.

https://www.scammed.org/phishing/mcafee-scam-email/

Norton / LifeLock — norton lifelock scam email 8.9K/mo. Virtually identical to McAfee scams — fake renewal invoices for security software subscriptions.

https://www.scammed.org/phishing/norton-scam-email/

Apple — apple phishing email 1K/mo. Fake Apple ID suspension warnings, iCloud storage alerts, and purchase receipts for apps the victim never bought.

https://www.scammed.org/phishing/apple-phishing-email/

Amazon — amazon phishing email 1K/mo. Fake order confirmations, shipping notifications, account suspension warnings, and Prime renewal scams.

https://www.scammed.org/phishing/amazon-phishing-email/

Microsoft — microsoft phishing email 500/mo. Account security alerts, Office 365 credential harvesting, and fake Teams notifications — particularly common in corporate environments.

https://www.scammed.org/phishing/microsoft-phishing-email/

How to Report Phishing

Reporting phishing is important — it helps protect others who may receive the same message, and it contributes to law enforcement databases that help identify and prosecute phishing operations.

Report to the FTC: reportfraud.ftc.gov

Forward phishing emails to: spam@uce.gov (FTC’s dedicated phishing inbox)

Report to the Anti-Phishing Working Group: reportphishing@apwg.org

Report to your email provider: Gmail, Outlook, Yahoo, and Apple Mail all have built-in “Report Phishing” functions

Report to the impersonated company: Most major companies have dedicated abuse or phishing reporting addresses

→ Full reporting guide: https://www.scammed.org/phishing/how-to-report-phishing/

Frequently Asked Questions About Phishing

Q: What is the most common type of phishing attack?

A: Email phishing remains the most common delivery method by volume. Within email phishing, impersonation of major technology and financial brands — particularly PayPal, McAfee, Geek Squad, and Norton — generates the highest complaint volumes.

Q: Can you get hacked just by opening a phishing email?

A: In most modern email clients, simply opening an email (without clicking any links or downloading attachments) is generally safe. The risk comes from clicking links, downloading attachments, or entering information on fake sites.

Q: What is the difference between phishing and spam?

A: Spam is unsolicited bulk email — advertising, newsletters, junk. It’s annoying but not necessarily malicious. Phishing is a specific type of fraud that impersonates a trusted entity to steal information or money. All phishing arrives unsolicited, but not all spam is phishing.

Q: How do phishers get my email address?

A: Email addresses are obtained through data breaches, purchased from data brokers, harvested from websites and social media, and guessed using common username patterns. If your email address has ever been in a company’s database that was breached, it’s almost certainly in criminal hands.

Q: What is the best protection against phishing?

A: The combination of education (knowing what to look for), technical controls (spam filters, anti-phishing browser extensions, two-factor authentication), and good habits (never clicking unexpected links, verifying by going directly to a company’s site) provides the strongest protection. No single tool eliminates phishing risk completely.

Q: What should I do if I gave a phisher my password?

A: Change that password immediately on the account that was targeted, on any other account where you use the same password, and on your email account (which can be used to reset other passwords). Enable two-factor authentication on all affected accounts. Monitor for unauthorized activity.