Phishing and Online Scams

Phishing and online scams are cyberattacks in which criminals pretend to be trusted people or organisations. Their goal is to make victims reveal passwords, share bank details, install malware or send money.

Scammers may impersonate:

  • Banks
  • Government departments
  • Delivery companies
  • Employers
  • Police officers
  • Online stores
  • Friends or family members
  • Technical-support teams
  • Social media platforms
  • Investment companies

Modern scam messages can contain correct spelling, professional logos and personalised information. Therefore, a professional-looking message is not necessarily genuine.

What Is Phishing?

Phishing is a cyberattack in which criminals use fake messages, calls or websites to steal information, money or account access.

According to the UK National Cyber Security Centre, phishing commonly uses emails, text messages and phone calls to trick victims into visiting dangerous websites or sharing sensitive information.

The information targeted may include:

  • Usernames
  • Passwords
  • Banking PINs
  • Card numbers
  • One-time passwords
  • Recovery codes
  • Personal information
  • National Insurance or identity details
  • Business login credentials
  • Cryptocurrency wallet information

Why Is It Called Phishing?

The word “phishing” sounds like “fishing.”

A criminal sends a message as bait. The victim who trusts the message takes the bait by clicking a link, opening an attachment or sharing information.

flowchart LR
    A["Scammer sends bait"] --> B["Victim trusts message"]
    B --> C["Victim clicks or replies"]
    C --> D["Fake site or conversation"]
    D --> E["Information or money stolen"]

Real-Life Phishing Example

A person receives this text message:

Your parcel could not be delivered. Pay a £1.99 redelivery fee today.

The message contains a link to a website that looks like a real delivery company.

The victim enters:

  • Name
  • Address
  • Phone number
  • Card number
  • Expiry date
  • Security code

The parcel does not exist. The small £1.99 charge was only an excuse to collect banking and personal information.

Phishing vs Spam vs Online Scam

TermMeaningExample
PhishingA message or website designed to steal information or account accessFake bank login page
SpamUnwanted messages sent to many peopleRepeated advertising emails
Online scamAny internet-based scheme designed to steal money or informationFake investment platform
Malware attackMalicious software is installed on a deviceInfected email attachment
Identity theftStolen personal information is used to impersonate someoneCriminal opens an account using stolen details

Spam is not always malicious. Phishing is deliberately deceptive, while an online scam is a broader category that includes phishing, fake shopping, investment fraud and many other schemes.

How Does a Phishing Attack Work?

Most phishing attacks follow a similar process.

Step 1: Selecting a Target

The attacker may target:

  • Thousands of random email addresses
  • Customers of a specific bank
  • Employees of a company
  • A company administrator
  • Students at a university
  • A particular business owner
  • Older or vulnerable people
  • Previous scam victims

Step 2: Creating a False Identity

The scammer copies the name, logo and design of a trusted organisation.

For example, the message may look like it came from:

  • HMRC
  • DVLA
  • Microsoft
  • Amazon
  • Netflix
  • A bank
  • A university
  • A delivery service

Step 3: Creating Pressure

The message gives the victim a reason to act quickly.

Examples include:

  • “Your account will be closed.”
  • “Your payment has failed.”
  • “Your parcel is waiting.”
  • “Unusual activity was detected.”
  • “Pay the fine within 24 hours.”
  • “Your refund expires today.”
  • “Your manager needs this payment urgently.”

Step 4: Requesting an Action

The victim is asked to:

  • Click a link
  • Open an attachment
  • Scan a QR code
  • Call a number
  • Reply to the message
  • Enter login details
  • Share an OTP
  • Install an application
  • Approve an MFA notification
  • Transfer money

Step 5: Stealing Information or Money

The attacker may then:

  • Take over an account
  • Make card transactions
  • Steal business documents
  • Reset other passwords
  • Install malware
  • Commit identity fraud
  • Send scams from the victim’s account
  • Sell the stolen information
  • Demand further payments
flowchart TD
    A["Trusted identity copied"] --> B["Urgent message sent"]
    B --> C["Victim is pressured"]
    C --> D["Link, payment or code requested"]
    D --> E["Account, information or money stolen"]

Types of Phishing Attacks

1. Email Phishing

Email phishing uses fake emails sent to many potential victims.

Example

An email claims:

Your Microsoft account will be closed because of inactivity. Click here to keep it active.

The link opens a fake Microsoft login page. Any username and password entered on the page are sent to the attacker.

Common Signs

  • Unexpected password-reset request
  • Suspicious sender address
  • Link different from the claimed company
  • Urgent account warning
  • Request for personal information
  • Unexpected attachment

2. Spear Phishing

Spear phishing targets a specific person or organisation. The message contains personalised information to make it convincing.

Example

An attacker studies a school’s website and learns:

  • The principal’s name
  • The accountant’s name
  • The school’s email format
  • The name of a supplier

The attacker sends the accountant an email that appears to come from the principal:

Please pay the attached supplier invoice today. I am in a meeting, so do not call me.

Because the message contains real names and business information, it may appear genuine.

3. Whaling

Whaling is spear phishing aimed at senior or important people.

Common targets include:

  • Chief executive officers
  • Directors
  • School principals
  • Finance managers
  • Website administrators
  • Government officials

Example

A criminal impersonates a solicitor and tells a company director that a confidential acquisition payment must be completed immediately.

4. Smishing

Smishing means phishing through SMS or mobile messages.

Smishing messages often impersonate:

  • Delivery companies
  • Banks
  • DVLA
  • Mobile networks
  • Tax authorities
  • Parking companies
  • Streaming services

Example

Your parking charge remains unpaid. Pay before midnight to avoid additional penalties.

The included link opens a fake payment website.

5. Vishing

Vishing means voice phishing through telephone or internet calls.

The caller may pretend to be:

  • Bank security
  • Police
  • HMRC
  • Technical support
  • A mobile provider
  • An internet company
  • A relative in an emergency

Practical Example

A caller says they are from the bank’s fraud department.

They claim:

Someone is stealing money from your account. Transfer your money to this safe account immediately.

There is no “safe account.” The destination account belongs to the scammer.

A genuine bank will not ask a customer to transfer money to keep it safe.

6. Quishing or QR-Code Phishing

Quishing uses a malicious QR code.

The QR code may appear:

  • In an email
  • On a fake parking notice
  • Over a genuine restaurant QR code
  • On a poster
  • Inside a document
  • On a parcel
  • At a payment point

Real-Life Example

A criminal places a fake QR-code sticker over a genuine parking-payment code. Drivers scan it and enter card details into the attacker’s website.

The NCSC warns that criminals increasingly place QR codes in phishing emails to direct users to scam websites.

7. Social Media Phishing

Scammers use social media messages, advertisements or fake profiles.

Examples

  • “Your account has violated copyright rules.”
  • “Click here to receive a verification badge.”
  • “You have won a giveaway.”
  • “Vote for me in this competition.”
  • “Your business page will be deleted.”
  • “Contact support through this link.”

A compromised friend’s account may also send phishing links to their contacts.

8. Clone Phishing

Clone phishing copies a genuine message previously received by the victim. The attacker changes its link or attachment.

Example

A company regularly receives invoices from a known supplier. The attacker copies a previous invoice email but replaces the bank details with the attacker’s account.

9. Business Email Compromise

Business Email Compromise, or BEC, involves impersonating or compromising a business email account to request money or sensitive information.

The attacker may pretend to be:

  • A company director
  • Finance manager
  • Supplier
  • Solicitor
  • Employee
  • Customer

Example

A supplier’s genuine email account is hacked. The attacker replies inside an existing conversation and says:

We have changed our bank. Please send all future payments to this new account.

Because the message comes from a real compromised account, checking spelling and logos may not reveal the fraud.

The FBI’s Business Email Compromise guidance describes BEC as one of the most financially damaging forms of online crime.

10. Search-Engine Phishing

Criminals create fake websites or advertisements that appear in search results.

Example

A victim searches for their bank’s customer-support number. A fake advertisement appears above the genuine result. The displayed number connects to a scammer.

Important websites should be opened through:

  • The official mobile application
  • A saved bookmark
  • An address typed directly into the browser
  • Contact information printed on a bank card or statement

11. OAuth and Device-Code Phishing

This is a more advanced attack that may use a genuine login page.

The attacker asks the victim to enter a device code or approve access to an application. The victim may unknowingly authorize the attacker’s device.

This can give the attacker an access token without directly stealing the password.

Practical Example

An employee receives what appears to be a shared-document email. The message instructs them to:

  1. Open the real Microsoft verification page.
  2. Enter a code shown in the email.
  3. Approve the login.

The code actually belongs to the attacker’s device. By entering it, the employee authorizes that device to access the account.

This shows why a genuine website alone does not make an unexpected request safe.

12. Pharming

Pharming redirects users from a genuine website address to a fake website.

This may happen through:

  • Compromised DNS settings
  • Malware
  • Modified router settings
  • A manipulated hosts file

The victim may type the correct address but still reach a fraudulent page.

Psychological Tricks Used by Scammers

Scammers attack human emotions, not only computers.

The NCSC identifies several common warning signals, including authority, urgency, emotion, scarcity and current events. See its scam-recognition guidance.

Authority

The scammer pretends to be a powerful or trusted person.

Examples:

  • Police officer
  • Bank manager
  • Government department
  • Employer
  • Doctor
  • Solicitor

Urgency

The victim is told to act immediately.

Examples:

  • “Pay within two hours.”
  • “Your account will be suspended.”
  • “This is your final warning.”
  • “Do not disconnect the call.”

Fear

The scammer threatens:

  • Arrest
  • Account closure
  • Financial loss
  • Legal action
  • Public embarrassment
  • Loss of employment

Greed or Opportunity

The scammer promises:

  • Guaranteed investment profit
  • Free gift cards
  • Lottery winnings
  • Cheap products
  • High-paying jobs
  • Easy cryptocurrency returns

Sympathy and Love

Romance and family-emergency scams exploit trust and concern.

Secrecy

The victim may be told:

  • “Do not tell your bank.”
  • “Do not speak to your family.”
  • “This investigation is confidential.”
  • “Your manager does not want anyone else to know.”

A demand for secrecy is a major warning sign.

How to Recognise a Phishing Message

Look for several warning signs together. One sign alone does not always prove that a message is fraudulent.

Warning signExample
Unexpected contactA bank you do not use sends an alert
Urgent deadline“Respond within 30 minutes”
Threat“You will be arrested”
Unexpected reward“You won a competition you never entered”
Suspicious linkThe address does not match the organisation
Unusual paymentCryptocurrency, gift cards or bank transfer requested
Secret request“Do not tell anyone”
Sensitive informationPassword, PIN or OTP requested
Remote-access requestCaller asks to control your device
Unusual senderDisplay name looks correct but email address does not
Changed bank detailsSupplier unexpectedly provides a new account
Unexpected QR codeEmail asks you to scan a code to sign in
MFA requestApproval notification arrives when you are not logging in
Emotional pressureFear, excitement or sympathy is created

Poor spelling can be a warning sign, but modern scams may be grammatically perfect. Criminals can use templates and artificial intelligence to create convincing messages.

How to Check a Suspicious Email

Check the Complete Sender Address

A display name can say “Microsoft Support” while the actual email comes from an unrelated address.

Check:

  • The domain after the @ symbol
  • Missing or additional letters
  • Unusual numbers
  • Free email services used for business communication
  • Reply-to address different from the sender

Do Not Trust the Logo

Anyone can copy a company logo from its website.

Check the Link Without Opening It

On a computer, place the pointer over the link without clicking. The browser may display the destination.

On mobile, be cautious with long-pressing because an accidental touch may open the link. It is safer to open the company’s official application independently.

Do Not Open Unexpected Attachments

Dangerous attachments may include:

  • Executable files
  • ZIP archives
  • Office documents
  • PDFs containing malicious links
  • HTML files
  • Password-protected archives

Contact the Sender Separately

If a colleague sends an unusual payment request, call them using a number you already know.

Do not use a phone number or email address supplied in the suspicious message.

How to Check a Website Address

The website’s domain name is more important than its logo or appearance.

Look for Misspellings

A scammer may:

  • Add an extra letter
  • Remove a letter
  • Replace a letter with a number
  • Use a different domain ending
  • Add a trusted company name before an unrelated domain

Understand the Real Domain

In an address such as:

bank.example-scam.com/login

The real registered domain is example-scam.com, not bank.

HTTPS Does Not Prove a Website Is Genuine

The padlock and HTTPS mean that the connection is encrypted. Criminals can also obtain HTTPS certificates for fake websites.

Avoid Links from Unexpected Messages

For banking, government, shopping or account security:

  1. Close the message.
  2. Open the official app.
  3. Type the known website address yourself.
  4. Check the notification inside the real account.

Common Online Scams

1. Fake Shopping Scam

A fake store advertises an expensive product at an unusually low price.

Possible results include:

  • No product is delivered.
  • A counterfeit product arrives.
  • Card information is stolen.
  • The victim is charged repeatedly.

Example

A new website advertises a £700 phone for £150 and accepts only bank transfer or cryptocurrency.

The price and payment method are warning signs.

2. Investment and Cryptocurrency Scam

The scammer promises high or guaranteed returns.

The victim may initially see fake profits inside a professional-looking application. Small withdrawals may be allowed to build trust. When the victim invests more money, withdrawals are blocked.

The scammer then demands additional:

  • Tax
  • Withdrawal fees
  • Verification deposits
  • Insurance payments

Legitimate investment returns are never guaranteed.

3. Romance Scam

A criminal creates a fake dating or social media profile and gradually builds an emotional relationship.

After gaining trust, they request money for:

  • Medical treatment
  • Travel
  • Visa fees
  • Business problems
  • Family emergencies
  • Cryptocurrency investment

A romance scam may continue for weeks or months.

4. Job and Recruitment Scam

The scammer advertises a fake job or contacts people through WhatsApp or Telegram.

They may request:

  • Registration fee
  • Training fee
  • Equipment payment
  • Identity documents
  • Bank details
  • Cryptocurrency deposit
  • Money to complete online tasks

Example

A recorded call says:

I am from a recruitment company. Add this number on WhatsApp to discuss a high-paying remote role.

The “job” later asks the victim to deposit money before receiving commission.

Genuine employers do not normally require applicants to pay money to receive a job.

5. Tech-Support Scam

A pop-up or caller claims the computer has a virus.

The scammer asks for:

  • Remote access
  • Security-software payment
  • Banking information
  • Gift cards
  • Access to online banking

A genuine security warning will not normally tell you to call an unknown number displayed in a browser pop-up.

6. Parcel-Delivery Scam

The message claims:

  • A delivery was missed.
  • An address is incomplete.
  • A small redelivery fee is required.
  • Customs payment is outstanding.

Visit the delivery company’s official website and enter the tracking number manually.

7. Bank Impersonation Scam

The scammer claims that suspicious transactions were found.

The victim may be asked to:

  • Share an OTP
  • Approve a login
  • Install remote-access software
  • Move money to a “safe account”
  • Hand a bank card to a courier

Banks do not provide special accounts for customers to move money into for safety.

8. Government Impersonation Scam

The message may pretend to be from:

  • HMRC
  • DVLA
  • Police
  • Court
  • NHS
  • Visa or immigration department
  • Tax authority

It may offer a refund or threaten a fine.

9. Lottery and Prize Scam

The victim is told they won a prize but must first pay:

  • Processing fee
  • Delivery charge
  • Tax
  • Insurance
  • Legal fee

You cannot win a competition you never entered.

10. Rental Scam

A fake landlord advertises a property they do not own.

The victim is pressured to pay a deposit before viewing the property.

Warning signs include:

  • Rent far below the local market
  • Landlord refuses a viewing
  • Landlord claims to be abroad
  • Immediate bank transfer requested
  • Stolen photographs
  • No proper tenancy documents

11. Ticket Scam

Criminals sell fake tickets for:

  • Concerts
  • Sports events
  • Festivals
  • Flights
  • Theme parks

Use the official seller or an authorized resale service. Avoid bank transfers to unknown individuals.

12. Charity Scam

Criminals exploit disasters, wars or medical emergencies by creating fake donation pages.

Check the charity through the official charity regulator and type its website address directly.

13. Family-Emergency Scam

A message from an unknown number says:

Hi Mum, I lost my phone. This is my new number. I urgently need money.

The scammer may use information from social media or an AI-generated voice.

Call the family member on their existing number or ask a private question before sending anything.

14. Recovery Scam

A recovery scam targets someone who has already lost money.

The scammer promises to recover the original loss but requests an upfront fee or more personal information.

Police, regulators and banks do not require cryptocurrency payments to recover stolen money.

15. Sextortion Scam

The victim receives an email claiming their webcam was hacked and an embarrassing recording was created.

The message may include an old password obtained from a previous data breach to appear convincing.

Do not pay. Preserve the message, secure your accounts and report the threat.

Recent Phishing and Online Scam Cases

The following cases were reported by official authorities and were current when this article was prepared in August 2026.

Case 1: Fake DVLA Vehicle-Tax Emails — August 2026

On 20 August 2026, Norfolk County Council warned about emails impersonating DVLA.

The messages claimed that:

  • Vehicle-tax renewal had not been completed.
  • The recipient could face a fine of up to £1,000.
  • Payment had to be completed through a link.

The link opened a fake DVLA website designed to collect personal and financial information. Read the official consumer scam alert.

Lesson: Open GOV.UK directly and check vehicle-tax information there. Do not use an unexpected payment link.

Case 2: Scammers Impersonating the FBI’s IC3 — July 2026

On 20 July 2026, the FBI warned that criminals were impersonating Internet Crime Complaint Center personnel.

The attackers targeted previous scam victims and falsely claimed they could recover lost money. Methods included:

  • Fake social media profiles
  • Fraudulent websites
  • Emails and phone calls
  • AI-generated videos
  • Malicious complaint-update links

The scheme attempted to scam the same victims again. See the FBI’s IC3 impersonation warning.

Lesson: Recovery offers should be verified independently. A person who has already lost money may be deliberately targeted again.

Case 3: Fake FIFA and World Cup Websites — May 2026

On 27 May 2026, the FBI warned that criminals were creating websites impersonating FIFA before the 2026 World Cup.

The fake websites were used to:

  • Collect personal information
  • Steal banking details
  • Sell fake tickets
  • Advertise fake hospitality packages
  • Offer fake jobs

Some domains used minor spelling changes or unusual endings to resemble the genuine website. Read the FBI warning about spoofed FIFA websites.

Lesson: Major events attract fake ticket, employment and merchandise websites. Use official websites and authorized sellers.

Case 4: Kali365 Microsoft 365 Device-Code Phishing — May 2026

On 21 May 2026, the FBI published an alert about a phishing-as-a-service platform called Kali365.

Attackers sent messages impersonating trusted cloud and document-sharing services. Victims were instructed to enter a device code on a genuine Microsoft page.

Entering the code could authorize the attacker’s device and give it access to services such as:

  • Outlook
  • Teams
  • OneDrive

The attack could bypass normal password and MFA expectations by stealing authorization tokens. See the FBI Kali365 alert.

Lesson: Never enter an authentication code supplied by an unexpected person or message, even if the code is entered on a genuine website.

Recent Scale of Online Scams

As of July 2026, the UK NCSC stated that its reporting service had received more than 58 million scam reports. Those reports contributed to the removal of hundreds of thousands of scams across more than 454,000 URLs. See the NCSC phishing-reporting figures.

The FBI’s 2025 Internet Crime Report, released in April 2026, recorded more than one million complaints and nearly $21 billion in reported losses from cyber-enabled crime in the United States. Phishing, spoofing, extortion and investment schemes were among the most frequently reported categories. Read the FBI’s 2025 Internet Crime Report summary.

These figures cover reported cases only. Many scams are never reported.

Stop, Check and Report

flowchart TD
    A["Unexpected message or call"] --> B["STOP: do not click or pay"]
    B --> C["CHECK: contact organisation independently"]
    C --> D{"Confirmed genuine?"}
    D -->|Yes| E["Continue carefully"]
    D -->|No or unsure| F["Block and report"]

Stop

Do not:

  • Click the link
  • Reply to the message
  • Share information
  • Approve an MFA request
  • Scan the QR code
  • Transfer money
  • Install software
  • Call the supplied number

Check

Contact the organisation through:

  • Its official application
  • The number printed on your bank card
  • A saved contact
  • A genuine paper statement
  • A website address you typed yourself

Report

Reporting can help authorities block scam accounts, websites and phone numbers.

What to Do If You Clicked a Phishing Link

If you clicked but did not enter information:

  1. Close the page.
  2. Do not download anything.
  3. Update the browser and operating system.
  4. Run a full antivirus scan.
  5. Remove unexpected downloads.
  6. Check for unfamiliar browser extensions.
  7. Monitor accounts for suspicious activity.

Clicking a link does not always mean the device was infected, but it should be treated seriously.

What to Do If You Entered a Password

  1. Open the genuine website directly.
  2. Change the password immediately.
  3. Change it anywhere else it was reused.
  4. Sign out of all active sessions.
  5. Remove unknown devices.
  6. Enable MFA or create a passkey.
  7. Check recovery email addresses and phone numbers.
  8. Review email forwarding rules.
  9. Check connected applications.
  10. Secure the associated email account.

Make these changes from a clean and trusted device.

What to Do If You Shared Bank Details or Sent Money

  1. Contact the bank immediately using its official app or the number printed on the card.
  2. Explain exactly what information was shared.
  3. Ask the bank to stop or recall the payment if possible.
  4. Freeze or replace affected cards.
  5. Check recent transactions.
  6. Preserve messages, receipts and account details.
  7. Report the crime quickly.
  8. Do not pay anyone promising guaranteed recovery.

Fast reporting may improve the chance of stopping a payment, but recovery is not guaranteed.

What to Do If You Installed Remote-Access Software

  1. Disconnect the device from the internet.
  2. Stop communicating with the caller.
  3. Do not access online banking from that device.
  4. Contact the bank from a different device.
  5. Remove the remote-access application.
  6. Run a full or offline malware scan.
  7. Change important passwords from a clean device.
  8. Review active account sessions.
  9. Consider professional technical assistance.
  10. Inform company IT immediately if it is a work device.

How to Report Phishing and Online Scams

United Kingdom

IncidentReporting method
Suspicious emailForward it to report@phishing.gov.uk using the NCSC reporting guidance
Suspicious SMSForward it free to 7726; see Ofcom’s reporting guidance
Suspicious websiteUse the NCSC scam-website reporting service
Money lost or account hackedUse Report Fraud guidance on GOV.UK
ScotlandContact Police Scotland on 101 for non-emergencies
Immediate dangerCall 999

For WhatsApp, Telegram, Signal and social media messages, use the platform’s block-and-report function as well.

India

Victims can report cybercrime through the Government of India’s National Cyber Crime Reporting Portal.

For financial cyber fraud, call the national helpline at 1930 immediately. Keep the following information ready:

  • Transaction ID
  • Bank or wallet name
  • Date and time
  • Amount
  • Phone number
  • Screenshots
  • Messages and account details

United States

Report internet-enabled scams to the FBI’s Internet Crime Complaint Center.

Readers in other countries should contact their bank, local police and national cybercrime-reporting service.

How to Protect Yourself from Phishing and Scams

  • Use a unique password for every account.
  • Use a password manager.
  • Enable MFA.
  • Prefer passkeys or security keys when available.
  • Never share OTPs or recovery codes.
  • Keep devices and applications updated.
  • Use antivirus protection.
  • Check account login notifications.
  • Review social media privacy settings.
  • Avoid posting excessive personal information.
  • Verify payment requests through another channel.
  • Never move money to a “safe account.”
  • Do not allow remote access to unexpected callers.
  • Use official applications and saved bookmarks.
  • Avoid making payments under pressure.
  • Be careful with QR codes in emails and public places.
  • Use secure payment methods.
  • Keep important accounts protected with separate passwords.
  • Report suspicious messages.

Protection for Businesses and Website Owners

Businesses should not depend only on employees recognizing every phishing message.

Use several security controls together:

  • MFA or passkeys for administrator accounts
  • Separate administrator and normal user accounts
  • Email filtering
  • SPF, DKIM and DMARC email authentication
  • Regular staff training
  • Payment-verification procedures
  • Limited account permissions
  • Login alerts
  • Endpoint protection
  • Secure backups
  • Software updates
  • Incident-response procedures

Payment Verification Example

A Studies Blueprint employee receives an email apparently from the website owner:

Pay this new hosting invoice to the updated bank account today.

Before paying, the employee should confirm the request through a known phone number or another trusted communication method.

Email alone should not be sufficient to change supplier bank details or approve a large payment.

Protecting a WordPress Website

A phishing attack may target the website’s administrator account.

Use:

  • A strong, unique WordPress password
  • 2FA or a passkey
  • A protected administrator email account
  • Minimum required user permissions
  • Login monitoring
  • Updated themes and plugins
  • Secure backups
  • HTTPS
  • Malware scanning
  • A web application firewall where appropriate

If criminals copy the Studies Blueprint website, report the fake domain to its hosting provider, search engine, browser-safety provider and relevant cybercrime authority.

Common Phishing Myths

Myth 1: Phishing Emails Always Contain Spelling Mistakes

Modern phishing messages may use perfect spelling, genuine logos and artificial intelligence.

Myth 2: HTTPS Means a Website Is Genuine

HTTPS encrypts the connection. It does not prove that the website owner is trustworthy.

Myth 3: Only Older People Become Scam Victims

Anyone can be targeted. Scams are designed around different interests, jobs, ages and financial situations.

Myth 4: MFA Stops Every Phishing Attack

MFA provides important protection, but attackers may steal one-time codes, pressure users to approve requests or steal authenticated sessions. Passkeys and security keys provide stronger phishing resistance.

Myth 5: A Message from a Friend’s Account Must Be Safe

The friend’s account may have been compromised.

Myth 6: A Small Payment Is Harmless

A small delivery or verification charge may be used to steal card information or confirm that the victim is willing to pay.

Myth 7: The Caller ID Proves Who Is Calling

Phone numbers and sender names can be spoofed.

Frequently Asked Questions

What Is the Most Common Sign of Phishing?

An unexpected request combined with urgency is a major warning sign. Stop and verify the request independently.

Can Opening an Email Infect a Computer?

Simply viewing a normal email is usually less dangerous than opening its attachment or link. However, keep the email application and operating system updated.

Can a QR Code Be Phishing?

Yes. A QR code can direct the phone to a fake login or payment website.

Should I Reply to a Scam Message?

No. Replying confirms that the account or phone number is active and may lead to more scams.

Will a Bank Ask for an OTP?

An OTP may be required inside the bank’s genuine app or website. Bank employees should not ask you to read an OTP to them over a call or message.

Can a Scammer Use My Name and Address?

Yes. Some personal information may come from social media, public records or previous data breaches. Correct personal details do not prove that the sender is genuine.

What Is a Safe Account?

Banks do not ask customers to transfer money into a special “safe account.” This phrase is commonly used in impersonation scams.

Can Antivirus Stop Phishing?

Antivirus and browser protection can block some known malicious websites and files. They cannot detect every new scam or prevent a victim from voluntarily sending money.

What If I Am Unsure Whether a Message Is Genuine?

Do not use the link or contact details in the message. Open the organisation’s official app or contact it using independently verified information.

Conclusion

Phishing and online scams succeed by creating trust, fear, excitement or urgency.

The safest response to an unexpected message is:

  1. Stop before clicking, paying or sharing information.
  2. Check the request through an independent and trusted method.
  3. Report suspicious messages, accounts and websites.
  4. Protect affected passwords, devices and financial accounts immediately.

A logo, familiar name, correct personal detail, HTTPS padlock or professional design does not prove that a message or website is genuine. Verify the request, not just its appearance.

Continue Learning