Global information guide

Phishing Scams Protection: Recognize and Reduce Risk

Phishing uses deceptive messages to trick people into revealing sensitive information. This guide explains common techniques, how to spot red flags, and practical steps to lower your risk.

Local context: Credit reporting, consumer rights, record-retention periods, score displays, lending decisions, products, taxes, and consumer protections vary by country and provider. This content is general information, not legal, financial, tax, debt, credit, insurance, investment, or personalised advice. Check the process and terms that apply where you live.

How phishing works and why it matters

Phishing is a type of social engineering where attackers try to trick people into revealing credentials, personal details, or payment information by posing as a trusted contact. Messages may arrive by email, SMS, instant message, or voice call and are designed to create a sense of legitimacy. The attacker’s goal is to gain access to accounts, enable fraudulent transactions, or gather data that can be sold or reused. Understanding the basic purpose of phishing helps you approach unexpected requests with healthy scepticism and prioritise verification before sharing anything sensitive.

Phishing campaigns vary in sophistication. Some use mass emails with generic greetings, while others, known as spear‑phishing, target specific individuals with personal details gathered from public profiles or previous breaches. Impersonation can include cloned websites, forged documents, and messages that appear to come from colleagues, service providers, or familiar brands. Attackers may combine several channels—for example an email that directs you to a text message—to make the interaction seem normal. Recognising that phishing often layers deception across channels makes multi‑step verification more important.

Spotting phishing messages and common red flags

Common warning signs to look for include unexpected requests for passwords, payment details, or identity documents; mismatched link destinations and display text; odd sender addresses; and messages that pressure you to act quickly. Poor spelling and awkward phrasing can be a clue, but well‑crafted scams can be grammatically correct and still fraudulent. Attachments with uncommon file types or unexpected archives deserve extra caution. Treat any message that asks you to bypass your usual security habits—such as disabling protections or sharing one‑time codes—as potentially malicious.

When you suspect a message may be phishing, verify it through a channel you trust. Contact the person or organisation using contact details from your own records or an official website rather than replying to the suspicious message. Hover over links to check the destination before clicking, and avoid opening attachments unless you can confirm their origin. Consider using device‑level protections such as up‑to‑date security software and browser privacy settings to reduce exposure. Where possible, use separate accounts or dedicated contact addresses for sensitive services to limit cross‑account compromise.

Practical steps to reduce risk and respond if something goes wrong

Routine account hygiene reduces the impact of a successful phishing attempt. Use unique, strong passwords for different accounts and consider a password manager to store them securely. Enable multi‑factor authentication on accounts that offer it; additional factors such as a hardware key or authenticator app add layers of defence even if a password is exposed. Keep operating systems and applications current with security updates, and review account recovery settings and contact information regularly so unauthorised changes are easier to detect and reverse.

If you suspect you have fallen for a phishing attack, act promptly but calmly. Change passwords on affected accounts and any other accounts that share those credentials, prioritising accounts that control finances or personal identity records. Review recent account activity and, if available, set alerts for unusual transactions. Preserve the original message and any headers or screenshots to help investigations, and notify the service providers involved so they can take protective measures. Consider reporting the incident to relevant consumer protection or cybercrime authorities in your area and seek professional advice when necessary.

A practical next step

Take a few minutes to review how you verify unexpected messages and update account recovery contacts where needed.