How it works Blog About Contact
Guide

What Is Phishing? A Complete Guide

The word gets used constantly, often without much explanation — "watch out, that's phishing." It's one of those terms everyone's heard but few people could define precisely, which is a little ironic, since understanding what it actually means is most of what you need to defend against it.

Quick answer Phishing is when someone impersonates a trusted person or organization — a bank, delivery service, or company — through a message, call, or fake website, in order to trick you into sharing sensitive information, clicking a malicious link, or sending money. It relies on borrowed trust and urgency rather than technical hacking.

What phishing actually is

At its core, phishing is impersonation. Someone pretends to be an organization or person you already trust, then uses that borrowed credibility to get you to do something you wouldn't do for a stranger — click a link, share a password, or send money.

The three main delivery methods

Phishing isn't tied to one format. It shows up through whichever channel is most convenient for the scammer, which is why the same underlying trick keeps reappearing in new places.

What phishing is actually trying to get from you

The end goal varies. Some phishing attempts want your login credentials or OTP, some want a direct payment, and others want you to install something harmful. The method — impersonation plus urgency — stays consistent even when the target changes.

Newer phishing formats worth knowing

Phishing has adapted to newer habits too, including QR code scams and fake shopping websites designed to look like a real storefront.

Quick rule of thumb: phishing always needs you to act — click, reply, call, or pay. If a message just informs you of something without asking you to do anything urgent, it's far less likely to be phishing.

How to protect yourself from phishing generally

Conclusion

Phishing isn't really a technical attack — it's a trust attack, borrowing the credibility of an organization you already believe. Once you can see through the impersonation, regardless of whether it arrives by email, text, call, or QR code, the same defense works every time: verify independently before you act.

Want to see how phishing shows up in a specific situation? Browse the full blog for guides on individual scam types, or check a message directly.

Got a message you're unsure about? Paste it into our free checker for a quick first read.

Frequently asked questions

What's the difference between phishing, smishing, and vishing?

They're the same underlying trick delivered through different channels: phishing usually refers to email, smishing is phishing done by text message, and vishing is phishing done by phone call. All three impersonate someone trustworthy to get you to act.

Can phishing happen through apps other than email or SMS?

Yes. Phishing shows up through WhatsApp, social media messages, QR codes, and even fake websites — anywhere a message or link can impersonate someone you trust.

Is it phishing if the message doesn't ask for money directly?

Yes. Phishing can aim to steal login credentials, personal details, or install malware, not just extract a direct payment. The end goal varies, but the impersonation-plus-urgency method stays the same.

What's the fastest way to check if a message is phishing?

Look at whether it creates urgency, impersonates an organization, and asks you to click a link or share sensitive details — and verify independently through a channel you already trust rather than the message itself.

Further reading

Got a message you think might be phishing?

Run it through the checker