What Is Phishing? How to Spot and Avoid It
Phishing is a scam where someone pretends to be a company or person you trust, so you’ll click a malicious link, hand over a password or OTP, or send money. The message is designed to look genuine and to make you act before you think. Once you understand the pattern, phishing becomes much easier to catch.
How phishing works
Almost every phishing attempt follows the same three steps:
- Impersonation. The scammer copies a brand or person you recognize: your bank, a delivery company, a government office, a boss, or a family member.
- A reason to act now. They add pressure. Your account will be blocked, a parcel is held, a payment failed, someone is in trouble. Urgency stops you from checking.
- The trap. A link to a fake login page, a request for an OTP, a file to install, or a number to call. This is where the theft happens.
The message can be polished or clumsy. Modern phishing, often written with AI, is frequently well worded and hard to distinguish from the real thing by tone alone. That is why the checks below focus on structure, not vibes.
Common types of phishing
- Email phishing: a fake message from a bank, retailer, or service, usually with a link to a login page that harvests your credentials.
- Smishing (SMS phishing): the same idea over text messages, like a fake courier fee or a bank KYC alert.
- Vishing (voice phishing): a phone call from a fake official or support agent pressuring you to pay or share codes.
- Spear phishing: a targeted attack that uses your real name, employer, or details to seem personal and credible.
- Clone phishing: a copy of a genuine message you received before, with the link swapped for a malicious one.
- QR phishing (quishing): a QR code that leads you to a fake payment or login page.
The warning signs
No single sign proves a scam, but these are the reliable tells:
- Urgency and threats: “your account will be blocked today,” “act within two hours.”
- A link that is not the exact official domain. Read it from the start, not the end.
sbi.kyc-verify.infois notsbi.bank.in. - Requests for secrets: OTP, PIN, net banking password, card number, Aadhaar, or remote-access apps. No real company needs these through a link or a call.
- A mismatch between the sender and the brand, like a bank message from an ordinary mobile number.
- Attachments or app installs, especially APK files on Android.
How to protect yourself
- Never act from the message itself. Open the official app or type the website address yourself.
- Never share an OTP or PIN. These authorize actions on your account. Anyone asking for one is trying to act as you.
- Check links before clicking. Paste a suspicious URL into a link safety checker so it opens in a sandbox instead of on your phone.
- Turn on two-factor authentication on important accounts, so a stolen password alone is not enough.
- Slow down. The whole scam depends on speed. A genuine institution will let you verify at your own pace.
For a deeper walk-through of link checking, see our guide on how to check if a link is safe.
What to do if you fell for it
If you entered details on a phishing page, act quickly:
- Change the affected password immediately from a device you trust.
- Contact the real company through a number you find yourself, not one from the message.
- If money moved, report it fast so the transfer can potentially be frozen. Our guide on what to do after clicking a phishing link covers the full steps.
- Watch your accounts and statements for the next few weeks.
A faster way to check
When a message feels off, you do not have to judge it alone. Forward it to Kaval on WhatsApp and it checks the link, the domain, and the wording against known scam patterns, then tells you in seconds whether it is safe, a trap, or worth a closer look. It is free, and it works for you and the people you love.
Frequently asked questions
What is phishing in simple terms? Phishing is a scam where someone pretends to be a company or person you trust, like your bank, a courier, or a colleague, to trick you into clicking a link, sharing a password or OTP, or sending money. The message looks real, but the goal is to steal from you.
How can I tell if a message is phishing? Look for urgency and threats, a link whose domain is not the real one, requests for OTPs, passwords, card numbers, or remote access, and small errors in spelling or sender details. When a message pressures you to act fast, slow down and verify through an official channel you found yourself.
What should I do if I clicked a phishing link? Do not enter any details on the page. Close it, and if you already typed a password or OTP, change that password immediately from a trusted device, contact the real company through an official number, and watch your accounts. If money moved, report it right away.
Is phishing only done through email? No. Phishing also happens over SMS (smishing), phone calls (vishing), WhatsApp, social media, and QR codes. The channel changes, but the trick is the same: impersonate someone you trust and create a reason to act quickly.