← Back to scam types
Cyber Fraud·7 min read

What Is a Phishing Scam? The Complete Guide

What Is a Phishing Scam?

A phishing scam is a type of cyber fraud in which criminals impersonate a trusted organization — a bank, a government agency, a tech company, a delivery service, or an employer — to trick victims into revealing sensitive information such as login credentials, credit card numbers, Social Security numbers, or one-time authentication codes. The most common delivery method is email, but phishing also occurs via text message (smishing), phone calls (vishing), and social media direct messages.

Phishing is the most prevalent form of cybercrime in the world. According to the FBI's Internet Crime Complaint Center, phishing complaints consistently rank as the top reported cybercrime year after year, with millions of victims and billions of dollars in losses. The term comes from "fishing" — the scammer casts a wide net of fraudulent messages, hoping someone will "bite" by clicking a link or entering their information.

What makes phishing so dangerous is its exploitation of trust. A phishing email doesn't try to hack your computer — it tries to hack you. The email looks like it's from your bank, your email provider, or Amazon, using familiar logos, professional formatting, and urgent language. The goal is to make you act before you think — click the link, enter your password, approve the transaction — because you believe you're dealing with a legitimate organization.

How a Phishing Scam Works

A phishing attack has four components: the lure, the hook, the catch, and the harvest. The lure is the fraudulent message — an email, text, or call designed to look like it's from a trusted source. The scammer uses a real organization's branding, spoofed sender address, and a compelling reason for you to act: "Your account has been suspended," "Suspicious activity detected," "Package delivery failed," or "Invoice attached — payment overdue."

The hook is the link or attachment in the message. When you click the link, you're taken to a fake website that mimics the real one — a cloned login page for your bank, a fake Amazon sign-in, or a fraudulent Microsoft 365 portal. The fake site captures whatever you type: your username, password, credit card number, or authentication code. Alternatively, the attachment may contain malware that installs keylogging software or ransomware on your device.

The catch is the moment you enter your information or download the attachment. Your credentials are transmitted to the scammer in real time. The harvest is what the scammer does with the stolen data: logging into your bank account, making fraudulent purchases, selling your credentials on the dark web, or using your email account to launch phishing attacks against your contacts.

A more targeted variant is spear phishing, where the scammer researches a specific individual — using LinkedIn, social media, or company websites — and crafts a personalized message. A spear phishing email might reference a specific project, name a colleague, or mention a real upcoming meeting, making it far more convincing than a mass phishing blast. Business email compromise (BEC) attacks, where scammers impersonate a CEO or vendor to authorize fraudulent wire transfers, are a high-value form of spear phishing that costs businesses billions annually.

Red Flags: How to Spot a Phishing Scam

Several warning signs can help you identify phishing attempts. Check the sender's email address — not just the display name. A phishing email may show "Bank of America" in the name field but have an address like [email protected]. Look for subtle misspellings, extra words, or unfamiliar domains. Legitimate organizations send from their own registered domains, not from Gmail, Yahoo, or lookalike addresses.

Urgency and fear are the scammer's primary tools. Phishing emails almost always create a false sense of emergency: "Your account will be closed in 24 hours," "Unauthorized charge of $499 — confirm or dispute," "Package returned — address verification required immediately." This urgency is designed to make you click before you have time to verify. Real organizations rarely communicate this way and typically give you days, not hours, to respond.

Other red flags include: generic greetings ("Dear Customer" instead of your name); links that don't match the supposed sender (hover over a link to see the real URL before clicking); requests for sensitive information that legitimate organizations never ask for via email (passwords, full Social Security numbers, PINs); attachments you weren't expecting (especially .zip, .exe, or .html files); and poor grammar, odd spacing, or formatting inconsistencies that a real corporate communication department would never produce.

How to Protect Yourself from Phishing

The most effective protection is to never click links in emails or texts that ask you to log in, verify your identity, or resolve an account problem. Instead, go directly to the organization's website by typing the URL into your browser or using a saved bookmark. If the email says your Amazon account has a problem, go to amazon.com directly — don't click the link in the email. If the message is legitimate, you'll see the same alert when you log in.

Enable multi-factor authentication (MFA) on every account that offers it — email, banking, social media, shopping. MFA means that even if a phisher steals your password, they can't log in without the second factor (a code from your phone, a fingerprint, or a hardware key). Use an authenticator app (Google Authenticator, Authy) or a hardware key (YubiKey) rather than SMS-based codes, which can be intercepted via SIM swapping.

If you receive a suspicious email, do not click any links or open attachments. If it claims to be from a company you do business with, forward it to that company's fraud or abuse address (many companies have one — e.g., [email protected]). Delete the email. If you already clicked a link or entered information, change your password immediately, enable MFA, and contact the organization's fraud department. You can also check any suspicious URL with our $1 scam risk report to see exactly what red flags the site has before you interact with it.

Frequently asked questions

Phishing Scam — your questions answered

A phishing scam is a type of cyber fraud where criminals send fake emails, texts, or messages that impersonate trusted organizations to trick victims into revealing passwords, credit card numbers, or other sensitive information. The messages typically contain links to fake websites that capture whatever the victim enters.

Got a Suspicious Link from an Email or Text? Check It Now

Before you click any link in a suspicious email, text, or message, paste the URL into Scam Detective. For $1, you'll get a 0–100 scam risk score, a plain-English verdict, all five red flags, and a 3-step action checklist — so you know exactly what you're dealing with before you enter a single password.

Check a URL — $1 →

Other scam types