A message arrives claiming to be your bank. It says there’s a problem with your account. Click here to fix it, right now, or lose access. That urgency is the entire attack — not the logo, not the spelling, not even the link itself.
Phishing works by borrowing trust. The attacker copies the look of a real organisation and manufactures a reason to act fast, before you’ve had time to check anything.
The Pattern Behind Almost Every Phishing Attempt
Strip away the specific story — delivery fee, frozen account, unpaid invoice — and four steps remain.
- Attention. Money, danger, or a missed opportunity gets your eyes on the message.
- Pressure. Act now, or something bad happens.
- Action. Click a link, call a number, send a code.
- Capture. A fake page or a patient voice on the phone takes what it needs.
Warning Signs Worth Slowing Down For
None of these alone proves a scam. Together, they’re a pattern worth trusting.
- The sender’s address or number doesn’t quite match the organisation
- Unusual urgency, or a threat of immediate loss
- A link that opens a login page on an unfamiliar domain
- A request for a password, PIN, or one-time code
- An attachment you weren’t expecting
- A prize, job, or refund that requires payment first
- Pressure to move the conversation off the official app or line
A Convincing Message Is Not the Same as a Legitimate One
Correct spelling, a real logo, and knowledge of your name prove nothing on their own. Attackers copy designs, pull details from public profiles, and generate polished text. Even a compromised real account can send a fraudulent message — the account is genuine, the request isn’t.
How to Check Without Falling for It
- Skip the link or number in the message entirely.
- Open the organisation’s official app, or type the website address yourself.
- Check whether the alert also shows up inside the official account.
- Call a number you already had saved — not one from the message.
- Read the domain name character by character. Not the logo. The domain.
If You Clicked, But Didn’t Enter Anything
Close the page. Don’t download whatever it offered. Run a security check on the device, and clear any browser notification permission that popped up uninvited. Then just watch the relevant account for a few days.
If You Entered a Password or Code
Move fast here — speed matters more than anything else in this section.
- Change the affected password immediately, from a device you trust.
- Change any other account using that same password.
- Sign out other sessions and check which devices are connected.
- Turn on multifactor authentication or a passkey wherever it’s offered.
- If money or payment details were involved, call your bank now — not tomorrow.
- Save the message, the sender’s details, and any transaction reference. You’ll want them for the report.
Embarrassment Is Part of the Design
Phishing works partly because people delay reporting it out of embarrassment. That delay is exactly what benefits the attacker. A fast report gives your bank, employer, or platform a real chance to limit the damage — and to warn the next person before the same message reaches them.
Urgency belongs to the attacker. Verification belongs to you. Open the official service yourself, on your own terms, before you enter anything, approve anything, or send anything.

