Phishing is the most common way a business gets breached, and it usually arrives as an ordinary looking email. The goal is simple: get you to click a link, open an attachment, or type your password into a fake page. It works because it copies a brand you already trust, like Microsoft, your bank, or a supplier you deal with every week.
It impersonates something familiar
A convincing phish looks like a real login page, invoice, or delivery notice. The logo and layout can be perfect, so the giveaway is usually in the sender address and the link, not the design.
The link is the trap
The button might say Microsoft or DHL, but the actual web address underneath goes somewhere else. On a computer, hover over a link to see the real destination before you click. On a phone, press and hold to preview it.
Urgency is a tactic, not a coincidence
Your account will be closed in 24 hours. Your payment failed. Verify now. That pressure is deliberate, because a rushed person stops checking. A real provider will not close your account because you took an hour to think.
Attachments can be dangerous too
An unexpected invoice, receipt, or scan attached to an email can carry malware, or open a fake login page when clicked. If you were not expecting the file, do not open it. Confirm with the sender through a channel you already trust.
When in doubt, go direct
Never use the link or phone number in a suspicious message. Open a new browser tab and type the company address yourself, or call the number printed on a statement or the back of your card.
Red flags to watch for
- The sender address is slightly wrong, like micros0ft.com with a zero, or a public gmail.com address for a big company.
- A generic greeting such as Dear User or Dear Customer instead of your name.
- Pressure to act right now or lose access, get fined, or miss a delivery.
- A link whose real destination does not match the company it claims to be from.
- Spelling and grammar that a real company would have caught before sending.
- A request for your password, card details, or a login you would normally never be asked for by email.
Check yourself
0/41.An email from Microsoft says your password expires today and you must verify your account within 24 hours. What is the safest first step?
2.You hover over a link that says www.hsbc.co.uk and the status bar shows the real address is hsbc-secure-verify.co. What does this tell you?
3.Which of these is the strongest single sign that an email is a phish?
4.You receive an unexpected PDF invoice from a supplier you do use. What is the sensible move?
This is general guidance, not a substitute for advice on your specific setup. Want a hand putting it into practice? Talk to us or see our care plans.
