What is phishing?
Phishing is a cyberattack aimed at people. A criminal sends a carefully prepared message and tries to persuade the recipient to take a specific action—usually clicking a link, sharing data, opening a file or making a payment.
Email is the most common channel, but phishing also uses SMS messages (smishing), phone calls (vishing), social media and other direct communication. Attackers impersonate people and institutions we trust, such as a manager, colleague, police officer or bank employee.
Phishing remains effective because campaigns can be sent to thousands of recipients at once. Fake websites and messages often copy a real brand’s logo, layout and tone. A tired, stressed or distracted recipient may therefore miss the warning signs. The attacker’s goal is to trigger an emotional response before the victim has time to assess the situation rationally.
How to recognize a phishing attack
Attackers constantly adapt their scenarios to current events, trends, holidays and information they have collected about you or your company. No list can cover every possible variation, but the following signals should make you stop and verify the message:
A request for sensitive information
Be suspicious if someone asks for a password, a scan of an identity document or other confidential data. No legitimate contact should require you to disclose your password or give an unknown person access to sensitive information.
Pressure and urgency
Messages that demand an immediate decision, a link click or a file download are designed to make you act on impulse. Slow down and verify the request through a trusted channel.
If it sounds too good to be true
Unexpected inheritances, prizes, salary increases and special benefits are common pretexts. Treat them cautiously, check the source and confirm the offer independently.
A message from a public institution
Criminals may impersonate the police, a tax office or another public institution. They can claim that you have an unpaid fine, that your device is blocked or that your tax return contains an error. Do not follow the instructions until you have confirmed the matter using the institution’s official contact details.
How to defend against phishing
Stay alert
Most attacks begin with a fake email containing a link or attachment. Check the sender’s address and contact the organization through an independently verified phone number or website if anything seems unusual. Never rely only on a phone number supplied in the suspicious message.
Read messages carefully
Look for spelling and punctuation errors, unusual sender domains and shortened links. Hover over a link without clicking it to see its real destination. Be especially cautious about phrases such as “send these details within 24 hours” or “click immediately to check whether you have been defrauded”.
Be careful what you share
Information posted on social media can help criminals prepare a targeted attack, including spear phishing. Limit what strangers can see, do not accept every connection request and avoid publishing travel plans, your home address or unnecessary details about your employer.
Use a password manager and MFA
A password manager can generate and store unique passwords and may warn you about a phishing site. Do not reuse one password across multiple services. Where possible, enable multi-factor authentication, preferably using an authenticator app or security key.
Use separate email addresses
Consider using separate addresses for work, online payments and private matters. This limits the impact of a compromise and makes targeted attacks harder to organize.
Keep software up to date
Delaying updates leaves known vulnerabilities open. Install security updates as soon as they become available for your operating system, browser and applications.
Act if you suspect an incident
If a device behaves unexpectedly or you clicked a suspicious link, stay calm and act quickly. Disconnect the device from the network, contact your IT team at work and ask a trusted specialist for help at home. Early reporting can limit the damage.
Choose education
Security awareness is the strongest long-term defense. Everyone should know how to recognize phishing, respond safely and practice these skills in controlled conditions. Regular, realistic phishing simulations help build habits that protect employees both at work and at home.

