Online Safety · 6 min read
How to Recognise and Avoid Phishing Attacks
Phishing bypasses antivirus entirely, because nothing malicious is installed — you simply hand over your credentials to a convincing copy of a site you trust.
Published 2026-08-09 · Last updated 2026-08-09
The three cues that catch most attempts
Urgency: your account will be closed, a payment failed, a package is held. Mismatch: the display name says your bank but the actual address does not. Destination: the link text says one thing and the real URL says another — hover, or long-press on mobile, to see it.
Check the domain, not the page
Attackers replicate branding perfectly; they cannot replicate the domain. Read the address from right to left: the part immediately before the first single slash is the real domain. secure-bank.example-login.com is not your bank.
Make stolen passwords worthless
Use a password manager so every site has a unique credential, and turn on multi-factor authentication — ideally an authenticator app or a hardware key rather than SMS. With those two controls, a successful phish costs you one account rather than all of them.
Never act from the message
If a message claims something needs attention, close it and navigate to the service yourself through a bookmark or by typing the address. Real notifications are always visible when you log in normally.
Frequently asked questions
- Does antivirus block phishing sites?
- Most suites block known phishing URLs and Chrome and Edge maintain their own lists, but new pages appear faster than they can be catalogued.
- What should I do if I entered my password on a phishing site?
- Change that password immediately from a different device, sign out of all sessions, enable multi-factor authentication, and check for new forwarding rules or recovery addresses on your email account.