The most successful cyberattacks rarely involve breaking any technology. They involve tricking a person — and the favourite tool for that is the phishing email, a message crafted to make you click a link, hand over a password, or approve a payment while your guard is down.
Understanding phishing is less about technical knowledge and more about recognising the emotional pattern it exploits: urgency, fear and authority, pushing you to act fast before you think.
The recurring tells
Watch for manufactured urgency: "your account will be suspended tonight", "unusual activity, verify immediately". Real institutions rarely demand instant action through a link. Watch for a mismatch between the friendly display name and the actual sending address, and for links whose visible text differs from where they truly lead — hover before you click and read the real destination.
Watch for requests that a legitimate organisation would never make: a bank asking for your full password, a service asking you to "confirm" card details over email, or a colleague suddenly needing gift cards. Generic greetings, odd grammar, and attachments you did not expect are all further flags — though modern phishing can be polished, so no single tell is proof.
The one habit that defeats most of it
The single most protective habit is this: never act on a message's own links or numbers. If an email claims to be from your bank, do not click its link — open your browser and go to the bank's site yourself, or call the number on the back of your card. If a "colleague" asks for an unusual payment, confirm through a separate channel you already trust.
This one rule — verify through a channel the message did not give you — neutralises the entire category, because it removes the attacker's control over where you land. The scam depends on you following their link; refuse to, and the trick collapses.
What to do if you slipped
Everyone can be caught on a tired day, so know the recovery steps. If you entered a password on a suspicious page, change that password immediately everywhere you used it, and enable 2FA. If you approved a payment, contact your bank at once — speed matters for recovery. Report the message to your email provider and, where relevant, your employer, so others are warned.
Falling for a phish is not stupidity; it is being human on a bad day against professionals. The shame that keeps people silent is the scammer's best friend — reporting quickly is what limits the damage.