How to Recognize Phishing: Signs of a Fake Message and What to Do
Scammers rarely break into systems directly anymore — it's much easier to get you to hand over your password yourself. Phishing fakes emails and websites of services you trust, and you can spot the fake in seconds if you know where to look.
How phishing works and why it succeeds
Phishing is a message disguised as a familiar company: a bank, a marketplace, an email provider or a payment system. The scammer's goal is to get you to hand over a password, card number or SMS code yourself. The US Federal Trade Commission (FTC) describes the typical scenario like this: you're told there's "suspicious activity on your account," a "problem with a payment," or you receive "an invoice you don't recognize," and then you're rushed to click a link and confirm your details (FTC, How To Recognize and Avoid Phishing Scams). The trick isn't technical — it targets emotion: fear of losing money and no time to check.
Signs of a fake message
CISA, the US cybersecurity agency, highlights several reliable markers that should make you suspicious of a message (CISA, Recognize and Report Phishing):
- Pressure and urgency. "Your account will be closed in 24 hours," "confirm your details immediately" — an artificial deadline is meant to stop you from thinking it through.
- Impersonal greeting. "Dear customer" instead of your actual name. A real bank usually addresses you by name and doesn't ask for your password by email.
- Sender mismatch. The "From" name looks respectable, but the actual address is on an unrelated or lookalike domain (for example, [email protected] instead of the official one).
- A link that leads somewhere else. The visible link text and the real address underneath it don't match.
- A request to enter data or open an attachment. A login-and-password form, a request for an SMS code, an unexpected "invoice," "receipt" or "photo" file — all of these are reasons to stop and check.
How to check a link before you click
Google recommends a simple rule: on a computer, hover over the link and look at its real address — if it doesn't match the text, that's a warning sign (Gmail Help, Avoid and report phishing emails). What to look for:
- The real domain sits to the left of the first single slash. An address like yourbank.com.login-verify.top/… takes you to login-verify.top, not to yourbank.com. Read the address from the start up to the first slash.
- Lookalike domains. Swapped letters (paypa1.com, gooogle.com), extra words and hyphens, or unfamiliar zones like .top or .xyz instead of the usual one.
- Shortened links. Services like bit.ly hide the final destination — don't click them blindly.
- The padlock and https aren't a guarantee. Fraudulent sites can have valid certificates too; a certificate only means the connection channel is encrypted, not that the owner is honest.
If you're unsure, don't click the link in the message at all. Open the site manually using an address you already know, or go through the official app and find the contacts there.
What to do if you already clicked or entered data
Act fast — every minute matters here:
- Change your password on the service where your data may have leaked, and on every other site where you used the same password.
- Turn on or check two-factor authentication — even with a stolen password, an attacker can't get in without the second factor.
- If you entered card details — call your bank using the number on the back of your card, block the card, and watch for unauthorized transactions.
- Scan your device with antivirus software if you opened an attachment or downloaded something.
- Warn anyone who might be affected: if your work email was compromised, tell your IT team — phishing could spread further from your address.
How to lower your risk in advance
Fake messages aren't going away, but the cost to you drops sharply if you're prepared:
- Two-factor authentication everywhere it's available. This is the key safety net if a password leaks — more in our article on two-factor authentication.
- A password manager. It not only stores unique passwords, but also won't autofill them on a fake domain: if autofill stays empty, the address is probably wrong. How to choose one — in our password manager comparison.
- Encrypting your traffic on untrusted networks. On open Wi-Fi in a café or airport, your connection can be intercepted; HamikVPN encrypts your traffic so intercepted data stays unreadable. It's important to understand the boundary: a VPN protects the channel, but it won't save you if you type your password into a fake site yourself — which is why you should choose the tool itself carefully (see signs of an unreliable VPN).
The best filter is a habit of not rushing. Any message that demands you act immediately and enter something deserves thirty seconds of pause and a check through an independent channel.
