Reviewed by the Foxmole editorial team · 2026-07-29

Key takeaways

  • Phishing is a scam message that impersonates someone you trust to steal passwords, codes, or money.
  • It was the #1 reported cybercrime in 2024 (FBI IC3).
  • The one rule that defeats most of it: never act from the message, go to the source yourself.

Phishing is the most common online scam, and the good news is that it works the same way almost every time. Once you understand the pattern, you can spot it.

What phishing actually is

Phishing is a message, email, text, phone call, or DM, that pretends to be a trusted source (your bank, a delivery company, an employer, a well-known app) to trick you into doing something: entering a password, sharing a one-time code, paying an invoice, or installing something.

193,407
phishing complaints, the #1 reported cybercrime (FBI IC3, 2024)
3.8M
phishing attacks observed across 2025 (APWG)

The common types

  • Email phishing, the classic: a fake email with a link to a lookalike login page.
  • Smishing, phishing by SMS text (“your parcel is held, pay a small fee”).
  • Vishing, phishing by phone call, often “your account has suspicious activity.”
  • Spear phishing, a targeted message using details about you to seem more convincing.

How it works, step by step

  • A message arrives with a hook, usually urgency or fear.
  • It points you to a link or phone number the attacker controls.
  • You land on a lookalike page and enter a password or code, which goes straight to them.

That’s it. The whole scam depends on you acting inside the message rather than checking for yourself.

How to protect yourself

  • Never act from the message. Go to the site yourself or call a number you already trust.
  • Check the sender and the link before you click. (Full checklist: our spot phishing guide.)
  • Turn on two-factor authentication so a stolen password isn’t enough. (2FA guide.)
  • Add a browser safety layer that flags known phishing sites before they load. (Browser extension guide.)

Keep going

Source