HackMyIP
← back to sheets

How to Spot a Phishing Attack Before It Spots You

~/sheets/phishing-attacks.md
1

The Attack That Starts With a Click

2

Phishing is the most common cyberattack on the planet. It does not require exploits, zero-days, or hacking skills. It just needs you to click a link, open an attachment, or enter credentials on a fake page. Over 90% of data breaches start with a phishing email. Here is how to spot them before they spot you.

3

The Anatomy of a Phishing Email

4

Urgency: "Your account will be suspended in 24 hours." Authority: Pretending to be your bank, boss, or a government agency. Fear: "Unauthorized login detected." Curiosity: "You have a package waiting." Every phishing email uses at least one of these psychological triggers to make you act before you think.

5

Red Flags in Emails

6

Check the sender address carefully. security@paypa1.com is not PayPal (that is a number 1, not the letter l). Hover over links before clicking and check the URL. Look for misspellings and grammar errors. Legitimate companies do not ask for passwords via email. Be suspicious of unexpected attachments, especially .zip, .exe, or Office files with macros.

7

Fake Websites

8

Modern phishing sites are pixel-perfect copies of real login pages. The only difference is the URL. Always check the domain carefully. login.google.com is real. login-google.com is not. google.com.evil-site.net is not. When in doubt, type the URL manually instead of clicking links.

9

Spear Phishing

10

While regular phishing casts a wide net, spear phishing targets you specifically. The attacker researches your name, job, colleagues, and recent activity to craft a convincing personalized message. "Hey, here is the report from yesterday meeting" from someone who looks like your coworker is much harder to spot than a generic Nigerian prince email.

11

What Happens After You Click

12

You enter your credentials on a fake page. The attacker now has your username and password. They log into your real account immediately (often within minutes). They change your password, add their own 2FA, and lock you out. Then they use your account to phish your contacts. The chain continues.

13

Protecting Yourself

14

Enable two-factor authentication on everything (it stops most phishing attacks even if you give up your password). Use a password manager (it will not auto-fill on fake domains). Verify your DNS settings to make sure you are not being redirected by a compromised network. Check your IP exposure regularly.

15

When In Doubt

16

Do not click the link. Go directly to the website by typing the URL. Call the company using a number from their official website, not from the suspicious email. Report phishing emails to your IT department or email provider. One moment of caution can prevent months of damage.

17

Frequently Asked Questions

18

What is a phishing attack?

19

Phishing is the most common cyberattack on the planet. It does not require exploits or hacking skills — it just needs you to click a link, open an attachment, or enter your credentials on a fake page. Over 90% of data breaches start with a phishing email.

20

How do phishing attacks work?

21

A phishing email uses a psychological trigger such as urgency, authority, fear, or curiosity to make you act before you think. You click a link to a pixel-perfect fake login page and enter your credentials, then the attacker logs into your real account within minutes, changes the password, and locks you out.

22

How do I avoid phishing scams?

23

Check the sender address carefully (security@paypa1.com is not PayPal), hover over links before clicking, watch for misspellings, and never enter a password from an email link. Enable two-factor authentication and use a password manager, which will not auto-fill your credentials on a fake domain.

24

What should I do if I clicked on a phishing link?

25

If you entered your credentials on the fake page, treat them as compromised: change that password immediately, change it anywhere you reused it, enable two-factor authentication, and report the email to your IT department or email provider. Do not click further links — go to the real site by typing its URL directly.

26

What are the most common types of phishing?

27

Regular phishing casts a wide net with generic emails, while spear phishing targets you specifically using your name, job, colleagues, and recent activity to craft a convincing personalized message. Both rely on fake login pages and psychological triggers like urgency and fear.

28
Published: April 2026