VPN Guide
What Is Phishing?
Phishing is a social-engineering attack where someone impersonates a trusted entity to trick you into revealing credentials, installing malware, or sending money. According to the FBI's 2024 Internet Crime Report, phishing was again the most-reported cybercrime category. The good news: a small number of habits prevent the vast majority of attacks.
Editorial shortlist
Need a VPN recommendation now?
Skip the theory — compare our top-rated VPNs for US users, with pricing, privacy notes, and setup guides.
See all VPN reviewsCompare providersThe Main Types of Phishing
Email phishing — the classic: a fake message from your 'bank,' 'IT department,' or 'shipping carrier' with a link to a lookalike login page.
Spear-phishing — a targeted attack using personal details (your name, your boss's name, your project) to seem more legitimate.
Whaling — spear-phishing aimed at executives, usually for wire-transfer fraud.
Smishing — phishing via SMS. 'Your USPS package can't be delivered, click here to update.' Hugely common in 2025–2026.
Vishing — phishing by phone call. 'This is Microsoft Support, your computer has a virus.'
Quishing — phishing using QR codes (often placed over real codes in restaurants, parking meters, etc.)
Clone phishing — a near-perfect copy of a real email you previously received, but with a swapped link.
Business Email Compromise (BEC) — attacker impersonates a vendor or executive to redirect a real invoice payment.
How to Spot a Phishing Message
Universal red flags:
- Urgency — 'Your account will be closed in 24 hours.'
- Mismatched sender — display name says 'PayPal' but the email is from a random domain.
- Suspicious links — hover (don't click) and check the actual URL. `paypa1.com` is not `paypal.com`.
- Generic greeting — 'Dear Customer' from a service that knows your name.
- Unexpected attachments — invoices, shipping labels, or zip files you weren't expecting.
- Requests for credentials — legitimate services almost never ask for your password by email.
AI-generated phishing in 2026 has eliminated the old 'bad grammar' tell. Don't rely on that signal anymore.
What to Do If You Clicked
- Don't enter credentials if the page looks suspicious — close the tab.
- If you already entered your password, change it immediately at the real site, and anywhere you reused it.
- Enable 2FA on the affected account if it isn't already.
- Run a malware scan in case the page dropped a payload.
- Watch for follow-up attacks — successful phishers often immediately try other angles.
- Report it — forward suspicious emails to `reportphishing@apwg.org` and to the impersonated company.
How to Avoid Getting Caught in the First Place
- Use a password manager — it auto-fills only on the real domain, so a lookalike won't trigger autofill (a huge tell).
- Enable 2FA everywhere — preferably with an authenticator app or hardware key, not SMS.
- Treat unsolicited links and attachments with suspicion, even from people you know.
- Verify payment changes out-of-band — a phone call to a known number, not the one in the email.
- Use a VPN with threat protection (NordVPN, Surfshark) that blocks known phishing domains at DNS level.
- Keep your browser updated — modern Chrome, Edge, Safari, and Firefox flag known phishing sites.
Frequently Asked Questions
Continue comparing
Full reviews
Reviewed Sep 2026 · Public-source research · First-party tests appear on review pages when dated results are published · Verify details on provider sites. Editorial policy & scoring