What is phishing?

Phishing is a message — an email, a text, a call or a QR code — that impersonates someone you trust so that you hand over a password, a one-time code, card details or money. By text it is called smishing, by phone vishing, but the trick is the same: get you to act before you check.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

Phishing is impersonation used to steal access or money. The sender poses as a bank, a delivery company, an employer or a government agency, creates a reason to hurry, and sends you to a fake login page, a phone number or a file. Clicking the link is usually not the damage — typing a password, a code or card details is. The messages work because they are built on real data about you, most of it from past data breaches and people-search sites, which is why they can quote your name and the bank you actually use.

How a breach turns into phishing — September 2026

On 12 September Revolut confirmed that staff had handed customer data — names, addresses, ID documents — to criminals posing as a government agency. Two days later, Malwarebytes reported, a customer got a text that landed in the same thread as genuine Revolut messages. The link opened a page asking for camera access, mimicked the bank’s “turn your head” video check, and then asked for a password. By 18 September the Financial Times was reporting a $3 million ransom demand over data on about 680 customers.

That is the pattern in miniature. The leak itself did not empty anyone’s account. It gave the next message a real name, a real bank and a real reason to be worried, and the phishing did the rest. What Revolut confirmed →

Email phishing

The original form and still the most common. A message styled like your bank, Microsoft, PayPal or your own IT department says an account is locked, a payment failed or a document is waiting, and links to a login page on a lookalike domain. Spear phishing is the targeted version: it uses your name, your employer or a real colleague’s name, which is where leaked data comes in. Business email compromise goes one step further and asks accounts payable to “update the bank details” on an invoice.

Smishing: phishing by text

Texts get opened far more often than email, and a phone screen hides most of the link. The usual stories are a parcel that cannot be delivered, an unpaid toll, a bank alert and, around elections, political fundraising. We have separate walkthroughs for fake delivery texts and political text scams. Forward any of them to 7726 and delete — do not reply STOP.

Vishing: phishing by phone

A caller from “the fraud department” already knows your name and the last digits of your card, which makes the rest of the script believable. The ask is always the one-time code the bank just texted you, or a transfer “to a safe account.” Seniors get the Medicare and Social Security versions most, especially during Medicare open enrollment. No real bank asks you to read out a code it sent.

Quishing and fake CAPTCHAs

A QR code on a parking meter sticker, a letter or an email attachment hides the link completely, so there is nothing to inspect before the page opens. A newer variant shows a fake “verify you are human” box and tells you to paste a command into your computer — that one installs malware directly. It is covered in our guide to the ClickFix fake-CAPTCHA scam.

Why phishing works: leaked data

A generic “Dear customer” email is easy to ignore. A text that uses your first name, names the bank you actually use and mentions the town you live in is not. That detail comes from data breaches — emails, phone numbers and account names copied from companies you did business with — combined with address and family details published by data brokers. After a well-known breach, expect phishing that mentions it: “your account was affected, verify your identity here.” Knowing which breaches your address is in tells you which stories to be suspicious of.

Warning signs

A deadline measured in hours. A threat — the account will be closed, a fine, an arrest. A request for something the real company never asks for by message: a password, a one-time code, a gift card, remote access, a transfer to a “safe” account. A link whose domain is almost right — a digit 1 in place of an l, the brand name with “-verify” or “-support” tacked on — or a shortened one you cannot read. A caller who gets angry when you say you will hang up and call back. Spelling mistakes are no longer a reliable tell; AI writes clean English now. The reliable test is the request, not the grammar.

What to do if you clicked

Opening the page is rarely the damage on an updated device. What matters is what you entered. If it was a password, change it from the real site or app and anywhere you reused it, then sign out other sessions. If it was card or bank details, call the number on the back of your card and have the card reissued. If you gave a one-time code, assume the account was accessed and check the recovery email and phone. If you downloaded and opened a file, disconnect and run a security scan. Then report it: emails to reportphishing@apwg.org, texts to 7726, losses at ReportFraud.ftc.gov. For account-by-account recovery, see hacked account help.

Which breaches is your email in?

The phishing you get is built from the breaches you are in. Check your email against 890 known breaches in seconds — free, no signup — and see which details are already out there.

Run my free breach check →
Common questions

Phishing, explained

What is phishing in simple terms?

Phishing is a message that pretends to come from someone you trust — your bank, a delivery company, your employer, a government agency — so that you hand over a password, a code, card details or money, or install something. The message is the bait; the fake login page, the phone number to call back or the attachment is the hook.

What is the difference between phishing, smishing and vishing?

Only the channel. Phishing is the general term and usually means email. Smishing is the same trick by text message (SMS), vishing is by voice call, and quishing hides the link in a QR code. The goal is the same in all of them: get you to act before you check.

What happens if I click a phishing link?

Usually nothing yet. Opening the page on its own rarely does damage on an updated phone or computer; the harm comes from what you do next — typing a password, a one-time code or card details, allowing camera or notification access, or downloading a file. If you entered anything, change that password from the real site or app, call your bank if card details were involved, and sign out other sessions.

How do scammers get my email address or phone number?

Mostly from data breaches and from people-search sites. A breach supplies your email, phone and sometimes the name of a service you really use; data brokers fill in your address, age and relatives. That is why a phishing text can know your name and the bank you use — it is working from real leaked data, not guessing.

Should I reply STOP to a phishing text?

No. Replying confirms the number is live and read by a person, which makes it more valuable to whoever is sending. Forward the text to 7726 (SPAM) so your carrier can block the sender, then delete it.

How do I report phishing?

Forward phishing emails to reportphishing@apwg.org and texts to 7726. If you lost money or gave out account details, report it at ReportFraud.ftc.gov, and tell the company that was impersonated — most banks have a dedicated address for this on their security page. If your identity was used, IdentityTheft.gov builds a recovery plan.

Can phishing be prevented?

You cannot stop the messages from being sent, but you can make them useless. Go to accounts by typing the address or opening the app yourself rather than following links, use a password manager (it will not autofill on a fake domain), turn on two-factor authentication with an app or passkey rather than SMS where you can, and reduce how much of your personal data is publicly available to build a convincing lure from.