Phishing is a scam where attackers send fake emails, texts, or messages that impersonate a trusted company or person to trick you into revealing passwords, financial details, or clicking malicious links. Good grammar does not establish authenticity. Spelling errors may be a clue, but sensitive requests need independent verification. If you've already clicked something or shared details, skip ahead to our scam recovery guide.
A polished message can still be phishing
Phishing can be generic or carefully tailored. A message may copy a familiar brand, refer to real events or come from a compromised account. The requested action and independent confirmation matter more than how professional it looks.
The FBI counted 191,561 phishing/spoofing complaints and about $216 million in associated reported losses in 2025. Those are complaint statistics, not a count of every attack or a measure of AI use. If you need help identifying which checks fit a message, use our scam checker.
A plausible message can reach someone while they are distracted or busy. That is an analytical explanation of why a familiar-looking request may escape scrutiny, not a claim of documented personal casework. The practical response is to verify sensitive requests through an independently chosen channel.
The 8 types of phishing you'll actually encounter
"Phishing" is an umbrella term. The attack that hits you depends on the channel and the target. Here are the eight variants worth knowing, each with the tell that identifies which one you are looking at. Those tells name the attack. They do not settle it. Independent verification steps follow the list; no single clue settles every case.
The classic: a mass email impersonating a bank, delivery service, or login page, hoping a small percentage click. Volume is the strategy.
The tell: The sender's real address (not the display name) doesn't match the company's true domain.
A targeted email crafted for one person, referencing your real name, employer, or a recent event to feel legitimate.
The tell: It knows just enough about you to feel personal — but still pushes you toward a link or payment.
Spear phishing aimed at executives and finance staff, usually impersonating a CEO or a key vendor to authorize a transfer.
The tell: Urgency plus authority: a 'CEO' asking for a wire or gift cards, often while 'travelling' and unreachable by phone.
Phishing by text message — fake delivery notices, bank alerts, or toll/road-fee notices with a short link.
The tell: A link in an unexpected text. Check an unexpected request through the official app or a site you locate independently.
A phone call impersonating your bank's fraud department, a government agency, or tech support, pressuring you to act 'to protect your account.'
The tell: They called you, create panic, and ask you to move money, share a code, or install software.
A QR code — on a flyer, parking meter, email, or fake invoice — that opens a credential-stealing page when scanned.
The tell: A QR code is asking you to log in or pay. Many phone cameras preview the destination before opening it. Read the address, and use the organization’s official app or site instead if the code is unexpected.
A compromised or spoofed business account sends a real-looking invoice or payment-detail change to redirect funds.
The tell: A last-minute change to bank details, or a new invoice that breaks the normal process.
A copy of a genuine email you already received, resent with the links or attachments swapped for malicious ones.
The tell: A 'resend' or 'updated version' of a message you recognise — but the links now point somewhere new.
The hardest version to judge is the one where the service being impersonated is real: bank fraud alerts arrive unprompted, at odd hours, about money, which is exactly the shape of a scam. If yours came from a name you did not recognise, see whether an EnFact notification is real or a scam — verify it with your card issuer; formats can vary, so a single message-format rule is not enough. The channel changes, but the goal never does: get you to act quickly, on their link, before you think. Voice and QR variants use channels outside ordinary email filtering. Several of these — especially vishing and deepfake calls — now overlap with AI-powered scams. The same unsolicited-message playbook also kicks off task scams — the fake "easy online job" that arrives by text, WhatsApp, or Telegram out of nowhere. And the whole pattern inverts if you are the one selling: instead of a fake login page aimed at a buyer, the seller gets a forged payment confirmation and a reason to ship before the money lands, which is how the Wompi scam in Colombia works.
For a text claiming to be from a US bank, our bank-text verification guide compares published sender details and explains how to check the alert independently. The number on the screen alone cannot authenticate it.
An unexpected code is a different question from a fake bank alert. Our guide to why Link sends verification codes explains Stripe’s checkout connection and why even a genuine code should not be handed to an unsolicited caller.
Why grammar is not authentication
Spelling and formatting mistakes can raise suspicion. Their absence does not make a message safe: templates, copied legitimate text and AI-assisted writing can all produce convincing copy. We do not have a reliable measure showing that most phishing messages use AI.
Here's what AI actually changed about the attacker's playbook:
- ▸
Flawless language — correct grammar is not proof of a genuine sender.
- ▸
Personalisation at scale — an operator can use public details to tailor the message, with or without AI.
- ▸
Polymorphic variants — variations in wording can complicate filtering; they do not make all filters ineffective.
- ▸
Conversational follow-up — AI chatbots can hold a convincing back-and-forth, so a reply doesn't prove a human — or a legitimate one — is on the other end.
Stop judging the writing. Judge the request and the route: Does it create urgency? Does it ask you to log in, pay, or share a code via a link? Would the real organisation ever contact you this way? When unsure, ignore every link and go directly to the official site or app yourself.
FTC: recognizing, responding to and reporting phishing
Verify the request outside the message
Look back at the eight tells above and notice what they have in common. Every one of them is a property of the message: the address behind the display name, the link in the text, the QR code, the changed bank details. The sender controls all of it. With AI writing the copy, cloning the branding and spoofing the number, they now control it well enough that a careful reader can be wrong.
There is one thing the sender does not control: the channel you use next.
Leave the message. Do not use its link, its number, its attachment or its reply button. Find the organisation yourself: the number printed on your card, the app you already have installed, the address you type in. Ask your question there.
Independently contact the organization through its verified app, site or phone number and check the request. This reduces dependence on details supplied by the sender. A calm reaction from the sender is not proof of legitimacy; the independent confirmation is what matters.
A request to avoid independent checking is a warning. But a cooperative sender can still be fraudulent, so assess what the real organization confirms rather than relying on the sender’s reaction. Our guide to official-sounding claims explains why presentation deserves a separate check.
None of this means stop reading the message. The eight tells above still earn their place: they tell you what you are dealing with, and plenty of phishing is still careless enough to be caught on sight. The claim is narrower and it matters. Inspecting the message is no longer sufficient on its own to decide whether to act. Use the tells to recognise the attack, and use the route test to decide.
Source: FTC, How To Avoid a Scam.
You clicked a phishing link: what to do right now
Clicking happens — to careful people on bad days. What matters is the next few minutes. Work through these in order:
- 1.
Don't enter anything else — if a login or payment page opened, close it. Do not type credentials, codes, or card details into it.
- 2.
Do not open unexpected downloads — if you ran suspicious software or granted remote access, disconnect the affected device from the network and seek technical help.
- 3.
Secure exposed accounts — if you entered a password or code, use a trusted device to change it, review sessions and change reused passwords. A click alone does not prove every account is compromised.
- 4.
Turn on two-factor authentication — add 2FA to email and financial accounts so a stolen password alone isn't enough.
- 5.
Run a malware scan — if you suspect harmful software, update your security tools and scan; seek qualified help if the device may be compromised.
- 6.
Alert your bank — if you entered card or account details, tell your bank immediately and ask them to watch for or block fraudulent activity.
If money already moved, or you shared sensitive personal details, speed matters even more — follow the full playbook in our scam recovery guide, and if your personal data may be exposed, see identity theft.
How to report a phishing email
Reporting takes a minute and helps providers and investigators shut down the campaign for everyone else. Send it to as many of these as apply:
- ▸
Anti-Phishing Working Group — forward the email to reportphishing@apwg.org, which feeds an industry-wide database of active campaigns.
- ▸
Your email provider — use the built-in "Report phishing" or "Report spam" button — it trains the filter and forwards to abuse teams.
- ▸
Your country's authority — FTC (reportfraud.ftc.gov) in the US, Report Fraud in the UK, Scamwatch in Australia, and equivalents elsewhere.
- ▸
The impersonated company — use the reporting route published on the company’s independently located official website; do not guess an email address.
For a full country-by-country directory of where to report different kinds of fraud, see our reporting guide.
Research and educational guidance by Peter. Sources and material corrections are linked on this page.
Frequently Asked Questions
Reviewed 23 September 2026. We corrected overbroad verification and recovery claims during our launch-content review. See the corrections log for the material changes.
Sources & References
Every statistic in this guide is sourced from verified organizations. Click to verify any claim.
Think you've been phished?
Don't guess. Get expert guidance on your specific situation.
Book a Consultation →