
Guides Threats
How to spot phishing
Bad spelling stopped being the giveaway years ago. These are the checks that still work.
Check where the link goes, not what it says
Link text can say anything. On a computer, hover and read the address in the status bar; on a phone, press and hold to preview. Read the domain from the right: the part immediately before the first single slash is the real one.
So "yourbank.example.com" is a page on example.com, not on yourbank. This one habit defeats a large share of attempts.
Treat urgency as the signal
Account suspended, payment failed, parcel held, unusual sign-in, respond within 24 hours. Urgency exists to stop you checking. Real organisations rarely need an answer in the next few minutes, and none of them lose your business because you logged in through their app instead of their link.
Notice what is being asked of you
Legitimate messages rarely ask for a password, a card number, or a code sent by SMS. A code request is worth particular alarm: those codes exist to stop someone who already has your password, so a person asking for one usually has it.
Be sceptical of attachments you did not expect
Especially documents asking you to enable content or macros, archives containing a single file, and anything with a double extension. An invoice from a company you have never dealt with is not an invoice.
A convincing message can come from a real address
If a colleague's or supplier's account has been compromised, the message genuinely comes from them, in a real thread, in their writing style. This is why sender address alone is not a sufficient check, and why unexpected requests to change bank details should always be confirmed by other means.
The reliable move
Do not use the link. Open the app, or type the address you already know. If the message was genuine, whatever it wanted will be waiting for you inside your account. If it was not, you have lost ten seconds.