The message designed to make you panic is usually the dangerous one. Phishing is a con where an attacker pretends to be someone you trust — your bank, a marketplace, a giveaway "admin", even a friend — to trick you into handing over a password, an OTP code, or card details. The moment you do, your account or balance can vanish in minutes. The good news: almost all phishing follows the same pattern, and once you know the pattern, you're hard to fool.
Three things to keep locked in
- Real banks and services will never ask for your OTP, PIN, or password — not over chat, a call, or any link. Full stop.
- Urgency is their weapon. "Account locked in 24 hours", "claim now before it expires" — built to make you panic before you think.
- Check the address, not just the logo. Logos are easy to fake; the email address and the URL are much harder to hide.
So what is phishing, really?
Phishing (yes, like fishing) is a social-engineering attack: the attacker isn't hacking your computer — they're hacking you. They send official-looking bait, then steer you to a fake login page or ask you to reply with sensitive data. What they're after: credentials (username + password), OTP codes, card numbers, or access to your social accounts.
It all comes down to one thing: they want you to act fast, without checking first.
Not just email: know the channels
Phishing follows you wherever you are:
- Email — the classic. Fake invoices, "verify your account", dangerous attachments.
- SMS / WhatsApp (smishing) — "Your package is held, pay here", or an APK "invitation"/"receipt" file that's really a data-stealing app.
- Phone calls (vishing) — someone posing as bank support, asking for an OTP to "cancel a suspicious transaction".
- Social DMs — a "giveaway" or "admin" account telling you that you won, just fill in your details.
- QR codes (quishing) — fake QR stickers slapped onto parking meters, restaurant tables, or e-wallet terminals.
5 signs you're being baited
- It rushes you. A threat or a countdown so you don't have time to verify.
- It asks for secrets. Password, OTP, PIN, CVV — no legit service needs these from you.
- An address that's "close but off". Like the banner's
free-prize.click/claim. A weird domain, too many hyphens, or a subtle typo likebcaa.comoramaz0n.com. - A prize too good to be true. You "won" a draw you never entered.
- Generic greeting + clunky language. "Dear valued customer", typos, or an awkward translation.
The myths that get people caught
"Only clueless people fall for phishing." — Very wrong.
Modern phishing is polished; it can copy a real email down to the smallest detail. It's not just beginners who get hit — IT pros have too. A few other myths:
- "A padlock/HTTPS means it's safe." The padlock only means the connection is encrypted, not that the site is honest. Scammers use HTTPS too.
- "It only happens by email." These days SMS, WhatsApp, and phone calls catch the most victims.
- "As long as I don't type my password, I'm fine." Some attacks only need you to click or install a file to drop malware.
Already clicked or tapped? Do this now
- Stop and don't enter anything else. Close the page. If you already typed your password, go to the next step.
- Change that password — and any other account using the same one — from a device you trust.
- Turn on 2FA (two-step verification) so a password alone isn't enough to get in.
- Contact your bank via the official number (on the back of the card or in the official app) if money is involved. Don't use the number from the message.
- Report it (see below) and warn anyone who might be affected — for example, if your account was used to spread links.
How to protect yourself (and your circle)
- Verify through official channels. Unsure about that "bank email"? Open the bank's app directly or call official support. Don't click links in the message.
- Use 2FA on every important account. An authenticator app or a passkey is stronger than SMS OTP.
- Use a password manager. It gives every account a unique password and won't autofill on a fake domain — a free alarm bell.
- Slow down on links & attachments. Hover to see the real destination; never install an APK from a chat.
- Warn the more vulnerable people around you. Younger siblings, parents, grandparents — they're prime targets.
Where to report
- Report a phishing email: forward it to the impersonated company, and to [email protected] (Anti-Phishing Working Group).
- Report a phishing site: Google Safe Browsing so it gets blocked for everyone.
- In the US: file a report at reportfraud.ftc.gov.
- In Indonesia: check & report a scam bank account at cekrekening.id, scam content at aduankonten.id, and finance issues to OJK on 157.
Quick recall
Without scrolling up: what's the one thing a real bank will never ask for through a link or a call?
Try it out
You get a text: "BCA: your account will be locked. Verify at bca-verify.click within 24 hours." Name at least two phishing signs in that message — then what's the safe move you'd make?
Still curious?
- What's the difference between phishing, smishing, and vishing?
- Why is SMS OTP considered weaker than an authenticator app?
- What's a passkey, and why is it called "phishing-resistant"?
- How do you read the sender's real email address?
- What should you do if it's a younger sibling or a parent who got caught?
Sources & official channels
- US FTC — How to recognize and avoid phishing scams — solid basics that travel across countries.
- Anti-Phishing Working Group — report phishing to [email protected].
- Google Safe Browsing — report a phishing site so it gets blocked.
- cekrekening.id — Indonesia's official portal to check & report scam bank accounts.
- lapor.go.id — Indonesia's national public-complaint channel (SP4N-LAPOR).