Accounts · Reference
Phishing That Gets Past the Filters
The obvious attempts are filtered out. What reaches you is well written and correctly branded, and the real tells are structural.
Advice about spelling mistakes and strange greetings is a decade out of date. Modern phishing is competently written, uses correct branding, and arrives at a moment when the message is plausible. The reliable signals are not about how the message looks.
The structural tells
It creates urgency. Your account will be suspended, a payment failed, unusual activity was detected, respond within 24 hours. Urgency exists to stop you checking. Legitimate services rarely impose deadlines measured in hours.
It asks you to follow a link to sign in. This is the core mechanism. Almost every credential phish requires you to authenticate somewhere the attacker controls.
It arrives at a plausible moment. After you ordered something, during tax season, following a real news event, right after you actually did sign in somewhere. Targeted versions reference real details about you drawn from public sources or a previous breach.
It requests an unusual channel. Move to a text message, call this number, install this app to resolve it.
It asks for something a real organisation would not. Your password, a two-factor code, remote access to your computer, payment in gift cards or a peer-to-peer transfer.
The one habit that defeats nearly all of it
Never authenticate from a link in a message.
If a message says something needs attention, go to the service the way you normally do — your bookmark, the app, typing the address. If the message was real, the notice will be there when you arrive.
This single rule handles almost every credential phish, regardless of how convincing the message is, because it removes the attacker's page from the process. It costs ten seconds.
Checking a link when you must
Look at the domain immediately before the first single slash. Everything else is decoration. secure-login.example-bank.attacker.com is on attacker.com. Subdomains are free and can say anything.
Watch for near-miss domains. A hyphen inserted, a letter doubled, a different top-level domain, a character from another alphabet that looks identical.
A padlock means encrypted, not legitimate. Certificates are free. Nearly all phishing sites have one.
Shortened links hide the destination. Treat them as unknown.
Phone calls and texts
Caller ID is trivially forged. A call appearing to come from your bank proves nothing.
Hang up and call back on a number you obtained yourself — the back of your card, the official site typed in. Do not use a number from the message, and do not press a button to be transferred.
No legitimate institution will ask you to move money to keep it safe. This is the core of a widespread and effective fraud. There is no scenario in which your bank asks you to transfer your balance to a different account for protection.
No legitimate institution will ask for a code they just sent you. That code exists to prove it is you. Anyone asking for it is trying to become you.
The variants that catch careful people
The reply-chain message. A compromised account replies inside a genuine existing thread. Context is real, history is real, and the attachment is not.
The fake invoice for a service you use. Plausible amount, correct branding, an attachment or a payment link.
The delivery notice. Everyone is expecting a parcel.
The internal-looking request. A message appearing to come from a colleague or a family member, asking for something small and time-sensitive.
The support search result. Searching for a support number and reaching a paid advert placed by a fraudster. Get contact details from the service's own site, not from a search result.
If you entered credentials
Change that password immediately, from a different device, and change it anywhere else you used it.
Check the account's active sessions and sign out everywhere.
Review the recovery settings. Attackers add their own recovery email or phone so they can return after you change the password. This step is skipped constantly and it is why people get compromised twice.
Check for forwarding rules on email accounts, which are added silently and quietly copy everything.
Register a second factor if you had none, and check the existing ones were not changed.
If it was a financial account, contact the institution directly, on a number you looked up.
Reducing exposure generally
Passkeys or hardware keys on the accounts that matter. They do not authenticate to the wrong domain, which makes the attack fail rather than requiring you to notice it.
A password manager that fills only on the correct domain. If it does not offer to fill, that is a warning worth heeding.
Assume messages you did not initiate are unverified, regardless of how they look. Verification means contacting the organisation through a route you chose.