Online Safety · 6 min read

How to Recognise and Avoid Phishing Attacks

Phishing bypasses antivirus entirely, because nothing malicious is installed — you simply hand over your credentials to a convincing copy of a site you trust.

Published 2026-08-09 · Last updated 2026-08-09

The three cues that catch most attempts

Urgency: your account will be closed, a payment failed, a package is held. Mismatch: the display name says your bank but the actual address does not. Destination: the link text says one thing and the real URL says another — hover, or long-press on mobile, to see it.

Check the domain, not the page

Attackers replicate branding perfectly; they cannot replicate the domain. Read the address from right to left: the part immediately before the first single slash is the real domain. secure-bank.example-login.com is not your bank.

Make stolen passwords worthless

Use a password manager so every site has a unique credential, and turn on multi-factor authentication — ideally an authenticator app or a hardware key rather than SMS. With those two controls, a successful phish costs you one account rather than all of them.

Never act from the message

If a message claims something needs attention, close it and navigate to the service yourself through a bookmark or by typing the address. Real notifications are always visible when you log in normally.

Frequently asked questions

Does antivirus block phishing sites?
Most suites block known phishing URLs and Chrome and Edge maintain their own lists, but new pages appear faster than they can be catalogued.
What should I do if I entered my password on a phishing site?
Change that password immediately from a different device, sign out of all sessions, enable multi-factor authentication, and check for new forwarding rules or recovery addresses on your email account.