Every time you log in to your bank, someone out there is hoping you will do it on the wrong website. Phishing, the art of tricking people into handing over passwords and card details, has grown from clumsy spam into a polished industry. Learning the main types of phishing is the single best defence a bank customer has, because almost every scam is a variation on a handful of tricks. Once you can name them, they lose most of their power.
Here is a plain guide to the forms phishing takes, and the small habits that keep your accounts out of a stranger's hands.
The oldest trick still works. A message lands claiming to be from your bank, a delivery company or a streaming service, warning that your account is locked or a payment failed. It pushes you to click a link and log in right away. The link leads to a near-perfect copy of the real site, and whatever you type goes straight to the criminal. If you study real phishing email examples, the tells are consistent: a manufactured sense of urgency, a slightly wrong sender address, and a link whose visible text does not match where it actually points. Hover over any link before clicking, and when in doubt, type the bank's address in yourself.
Most phishing is scattered wide and cheap. Spear phishing is the opposite. Here the attacker researches one person, often using details scraped from social media, and writes a message tailored to them. It might mention a real colleague or a recent purchase, which makes it far more convincing. When the target is a chief executive or finance director, the same approach earns its own name, whaling phishing, because the potential payout is so large. The defence holds at any level: verify unusual requests through a second channel, especially anything involving a payment or a password.
Phishing left the inbox years ago. Smishing arrives by text message, often a short note about a missed delivery or a suspicious transaction with a link to tap. Vishing is the voice version, a phone call from someone posing as your bank's fraud team, talking you into moving money to a "safe account" that in fact belongs to them. If you have ever wondered what is smishing and phishing in the same breath, the honest answer is that they are the same con on different devices. No real bank will ever ask you to transfer money to protect it. That single fact stops most phone scams cold.
Some criminals skip the message entirely and publish a fake banking app or buy ads that sit above the real bank in search results. You think you are downloading your bank's tool or clicking through to its homepage, and instead you are handing your login to a clone. Download banking apps only from official app stores, check the developer name, and be wary of sponsored search results when you are hunting for a login page.
Criminals follow the money, and your accounts are where it sits. That is also why it pays to think about where you keep value that is not in a bank at all. Anyone holding cryptocurrency faces the same logic in sharper form, which is why many owners move their coins into a cold wallet that stays disconnected from the internet. The principle carries across every account you own: the harder something is to reach remotely, the safer it tends to be.
You do not need to memorise every scam to stay safe. A few habits cover almost all of them. Turn on two-factor authentication so a stolen password alone is useless. Never log in through a link inside a message. Slow down when something feels urgent, because urgency is the scammer's favourite tool. And treat any unexpected request for a code, a password or a transfer as a red flag until you have confirmed it directly with the institution. Handling sensitive information carefully matters for organisations too, a point the team at PoliLingua explores in their look at whether it is safe to handle confidential documents with AI.
Even careful people get caught on a bad day. If you think you have entered your details on a fake site, contact your bank straight away using the number on the back of your card, change the password, and watch your statements for anything odd. Speed matters more than embarrassment. Banks handle this every hour, and reporting quickly gives you the best chance of getting money back.
For a deeper history of the subject, the overview of phishing is worth a read, and the community at r/Scams posts real, current examples every day that are strangely useful for training your eye.