Phishing is a social-engineering attack in which a criminal impersonates a trusted person or organization to obtain information, money, software installation, or account access. Email is common, but phishing also appears in text messages, calls, QR codes, ads, search results, and collaboration tools. For warning signs, attack types, and complete recovery steps, see What is phishing?.
How phishing works
The message supplies a believable reason to act: an account warning, invoice, delivery, refund, shared document, job, or security request. The target is sent to a fake login, asked to open a file, told to call a number, or pressured to approve a payment or sign-in.
Accurate personal information does not authenticate the sender. It may come from public sources or a previous data breach.
Common forms
- Smishing uses text messages.
- Vishing uses calls or voice messages.
- Spear phishing targets a specific person or organization.
- Business email compromise impersonates an employee or vendor to redirect money or data.
How to respond
Do not use the messageâs link or phone number. Open the official app, type a known address, or contact the person through a channel you already trust. Report phishing through the platform and at ReportFraud.ftc.gov when appropriate.
If you entered a password, change it through the real service, end unfamiliar sessions, and enable two-factor authentication. Contact financial institutions immediately after a payment or exposure of bank information.
Phishing and malware are different
Phishing describes the deception. Malware describes harmful software. A phishing page can steal a password without installing anything, and malware can arrive through a route that is not phishing.