How It Works
The perpetrators copy the design, layout and logos of an official e-mail, be it from a bank, Paypal or some other institution (virtually every bank in the U.K. and U.S. has been a victim). It won't have your name in the greeting, but there will be a sense of urgency in the message. The idea is for you to believe that the security of your account has been breached, so you'll click on the link in the mail and type in all the requested personal information. The only problem is that the link doesn't lead to an official site. Instead it takes you to a bogus site set up by the criminals, where they harvest that information.
The first attempts at phishing, just a few years ago, were quite crude. The English was poor, and the design was frequently amateurish. These days, however, they're very sophisticated, to the point where it's often hard to tell the fake from the real thing.

Got a text, call, email or offer that feels off? Paste it in below and we will tell you how scammy it looks, the warning signs to spot, and exactly what to do next.
Try our Scam Detector free, here on this site →How to Identify a Phishing Scam
It can be difficult to figure out whether an e-mail is real or fake. However, the following offer very good indicators as to the legitimacy of the mail:
- Check the header (the part at the top of the mail, including address and subject line). If there are many addresses in the cc part, it's phishing
- Who is the letter addressed to? If it simply says "Dear customer," then beware. Proper e-mails will address you by name.
- Does the letter make sense? Are the grammar and spelling correct? If not, chances are it's a scam.
- Run your mouse over the link in the mail. If it's legitimate, the address that you see at the bottom of your screen (in the grey area) should be identical. A phishing mail will show a different address.
- There's an urgency in the message - if you don't respond within 48 hours, your account will be closed, for example. They want you to acct immediately.
Your situation may be slightly different. ask a question below ↓ and our editorial team will reply with our advice.
How to Prevent Phishing
Even with the best e-mail spam filters, it's impossible to stop every phishing message reaching your inbox. But there are steps you can take to make sure you're not hurt by them.
- Install a filter such as Mailwasher, which allows you to preview (and delete) e-mails before they're on your computer.
- Make sure you have both anti-virus software and a firewall installed on your computer, and update them very regularly.
- Sometimes phishing mails can install viruses; these will help prevent that happening.
- Be dubious about opening any attachment to an e-mail. These can contain viruses and spyware. Only open attachments that you were expecting, sent by people you know and trust.
- Never click on a link in an e-mail. Instead, open your browser, and type in the proper link. Don't copy and paste from the e-mail!
- Don't e-mail sensitive information. No legitimate organisation will ask for this in an e-mail. If in doubt, search online for a phone number and ring them.
- You should only perform online transactions with legitimate companies you trust. Never type in sensitive information unless you see a closed padlock in the bottom right-hand corner of your screen - that means the transaction is secure and encrypted. Even then, be careful; some phishers have forged security icons.
- Check your credit card and bank statements every month and report any suspicious activity.
- Report all suspected phishing mails to the institution being hoaxed.
What To Do If You Think You've Been Phished
If you feel you've been scammed, your actions depend a great deal on the information you've given out. If it's just a password log on to the site immediately and change it. If you can't get into your account, inform the company so they can take action.
If you've given more information, then you should contact your banks and credit card companies, informing them and changing account numbers. Request a copy of your credit file from one of the credit reporting agencies and have a fraud alert put on your account.
Act quickly, and you can minimise any damage. The one thing you quite literally can't afford to do is fret and wait.
Phishing is widespread, and becoming even more so. The criminals behind it are becoming slicker and more sophisticated. But if you think carefully, you can avoid the traps.
Ask Safe from Scams a question
Ask our editorial team a question and we will reply with our advice. Tell us as much about your situation as you can: the more detail you give, the more useful our answer can be.
You do not need to use your real name. Please do not include your full address, phone number, email address, or the names of other people. We may edit or remove identifying details for privacy and legal reasons.
Comments are moderated before publication.