Phishing
Phishing is a message — email, text, or chat — designed to impersonate someone trustworthy so the recipient hands over credentials, payment details, or access to a device. It doesn't rely on exploiting software; it relies on exploiting trust, urgency, and habit.
Common phishing formats
- Fake login pages that mimic Microsoft, banks, or shipping carriers
- Invoice or payment scams targeting businesses (often called business email compromise)
- Text-message phishing, or smishing, claiming a package delivery issue
- Spear phishing aimed at one specific person using researched personal details
What makes a message look convincing
Modern phishing kits copy real company branding almost exactly, use lookalike domains (a zero in place of an 'o', an extra hyphen), and often route through compromised legitimate sites so the link itself doesn't look immediately suspicious. Some phishing pages are only live for a few hours before being taken down, specifically to dodge blocklists.
Urgency is the tell that survives every redesign: 'your account will be suspended,' 'unusual sign-in detected,' 'payment failed.' Legitimate companies rarely demand action within minutes.
If you already clicked
- Don't enter anything further on the page — close the tab immediately
- Change the password for that account from a separate, trusted device
- Enable two-factor authentication if it isn't already on
- Run a malware scan in case the link also triggered a download
- Watch the affected account and linked payment methods for a few days
A phishing click that leads to a downloaded file is a different problem than one that just harvests a password — the former can leave malware running on the PC even after you close the browser tab.
Where phishing overlaps with other scams
Phishing is often the delivery method for social engineering attacks more broadly, and increasingly for AI-generated scam messages that are harder to spot because the grammar and tone no longer give the scam away.
Frequently asked questions
Can antivirus software stop phishing?
Web-protection features in tools like Malwarebytes Premium can block known phishing domains before the page loads, but no tool replaces checking the sender and URL yourself before entering credentials.
Why do phishing emails still work despite awareness campaigns?
They exploit split-second decisions during a busy moment rather than a lack of general knowledge — even security-aware people can click when a message looks urgent and familiar.
How do I report a phishing email?
Most email providers have a built-in 'report phishing' option, and forwarding the message to the impersonated company's abuse address helps get the fake page taken down faster.
Malware-Bytes.net is an independent information resource about malware protection for Windows. We are not Malwarebytes, and this site is not the official Malwarebytes website or support channel. Malwarebytes is a trademark of Malwarebytes Inc.