The message designed to make you panic is usually the dangerous one. Phishing is a con where an attacker pretends to be someone you trust — your bank, a marketplace, a giveaway "admin", even a friend — to trick you into handing over a password, an OTP code, or card details. The moment you do, your account or balance can vanish in minutes. The good news: almost all phishing follows the same pattern, and once you know the pattern, you're hard to fool.

Three things to keep locked in

  • Real banks and services will never ask for your OTP, PIN, or password — not over chat, a call, or any link. Full stop.
  • Urgency is their weapon. "Account locked in 24 hours", "claim now before it expires" — built to make you panic before you think.
  • Check the address, not just the logo. Logos are easy to fake; the email address and the URL are much harder to hide.

So what is phishing, really?

Phishing (yes, like fishing) is a social-engineering attack: the attacker isn't hacking your computer — they're hacking you. They send official-looking bait, then steer you to a fake login page or ask you to reply with sensitive data. What they're after: credentials (username + password), OTP codes, card numbers, or access to your social accounts.

It all comes down to one thing: they want you to act fast, without checking first.

Not just email: know the channels

Phishing follows you wherever you are:

  • Email — the classic. Fake invoices, "verify your account", dangerous attachments.
  • SMS / WhatsApp (smishing) — "Your package is held, pay here", or an APK "invitation"/"receipt" file that's really a data-stealing app.
  • Phone calls (vishing) — someone posing as bank support, asking for an OTP to "cancel a suspicious transaction".
  • Social DMs — a "giveaway" or "admin" account telling you that you won, just fill in your details.
  • QR codes (quishing) — fake QR stickers slapped onto parking meters, restaurant tables, or e-wallet terminals.

5 signs you're being baited

  1. It rushes you. A threat or a countdown so you don't have time to verify.
  2. It asks for secrets. Password, OTP, PIN, CVV — no legit service needs these from you.
  3. An address that's "close but off". Like the banner's free-prize.click/claim. A weird domain, too many hyphens, or a subtle typo like bcaa.com or amaz0n.com.
  4. A prize too good to be true. You "won" a draw you never entered.
  5. Generic greeting + clunky language. "Dear valued customer", typos, or an awkward translation.

The myths that get people caught

"Only clueless people fall for phishing." — Very wrong.

Modern phishing is polished; it can copy a real email down to the smallest detail. It's not just beginners who get hit — IT pros have too. A few other myths:

  • "A padlock/HTTPS means it's safe." The padlock only means the connection is encrypted, not that the site is honest. Scammers use HTTPS too.
  • "It only happens by email." These days SMS, WhatsApp, and phone calls catch the most victims.
  • "As long as I don't type my password, I'm fine." Some attacks only need you to click or install a file to drop malware.

Already clicked or tapped? Do this now

  1. Stop and don't enter anything else. Close the page. If you already typed your password, go to the next step.
  2. Change that password — and any other account using the same one — from a device you trust.
  3. Turn on 2FA (two-step verification) so a password alone isn't enough to get in.
  4. Contact your bank via the official number (on the back of the card or in the official app) if money is involved. Don't use the number from the message.
  5. Report it (see below) and warn anyone who might be affected — for example, if your account was used to spread links.

How to protect yourself (and your circle)

  • Verify through official channels. Unsure about that "bank email"? Open the bank's app directly or call official support. Don't click links in the message.
  • Use 2FA on every important account. An authenticator app or a passkey is stronger than SMS OTP.
  • Use a password manager. It gives every account a unique password and won't autofill on a fake domain — a free alarm bell.
  • Slow down on links & attachments. Hover to see the real destination; never install an APK from a chat.
  • Warn the more vulnerable people around you. Younger siblings, parents, grandparents — they're prime targets.

Where to report

Quick recall

Without scrolling up: what's the one thing a real bank will never ask for through a link or a call?

Try it out

You get a text: "BCA: your account will be locked. Verify at bca-verify.click within 24 hours." Name at least two phishing signs in that message — then what's the safe move you'd make?

Still curious?

  • What's the difference between phishing, smishing, and vishing?
  • Why is SMS OTP considered weaker than an authenticator app?
  • What's a passkey, and why is it called "phishing-resistant"?
  • How do you read the sender's real email address?
  • What should you do if it's a younger sibling or a parent who got caught?

Sources & official channels