At a glance
Phishing is a scam where cybercriminals trick you into sharing personal information. They pretend to be trusted organisations through emails, texts, calls or messages. These messages can look real and are an attempt to steal your passwords, bank details or access your accounts.
There are different types of phishing including spear phishing, quishing and vishing. To stay secure, look for warning signs, don’t click suspicious links and don’t share personal information. You should also check requests using trusted sources.
If you think you've fallen for a phishing scam, find out how to recover.
What are phishing scams
Phishing is a type of cyber threat where cybercriminals pretend to be a trusted person or organisation to trick you into giving away personal information. They send you fake emails or messages and pretend to be from trusted organisations such as a bank or government service. They may try to steal your online banking logins, credit card details, passwords, or gain access to your accounts.
Phishing messages can be sent through:
- text
- social media
- instant messaging platforms
- phone calls.
They can look very authentic and convincing. They can seem like real messages from trusted senders, with official logos and wording. It can be difficult to know if messages are really from who they say they are.
There are many different types of phishing attacks. For example:
- Spear phishing: highly targeted messages that pretend to be from someone you know and trust.
- Quishing: fake QR codes that redirect you to a fake or malicious website.
- Vishing: phone scams where cybercriminals impersonate people you know or trust.
Understanding quishing
Quishing is a type of phishing that uses QR codes instead of text-based links. QR codes are often trusted, but cybercriminals can use them to hide harmful links.
When you scan a fake QR code, it may take you to a malicious website. It may also make you download files that track your activity, steal your personal information or access your device. These fake websites can look very similar to real ones.
Quishing is harder to detect than normal phishing because QR codes are images, not text. This means security tools may miss harmful links and you can’t check the link before scanning it.
In workplaces, this can be riskier. Staff may scan QR codes on personal devices. These devices aren’t protected by work security controls. This makes attacks harder to stop or detect.
Understanding vishing
Vishing is a form of phishing where cybercriminals impersonate people. It’s a voice-based scam where they use tools like voice cloning, deepfake technology or fake caller IDs to sound real.
Cybercriminals use vishing to trick you into giving sensitive information or takings actions like password resets. It can be more convincing and harder to detect than other scams because it:
- feels personal: hearing a familiar voice makes you more likely to trust the caller
- creates urgency: scammers can pressure you to act quickly on the phone
- builds trust: they pretend to be someone important, like your bank or workplace
- can be harder to verify: caller ID and voices can be faked to look real.
Warning signs of phishing
Phishing is one of the most common ways cybercriminals try to steal your information. Be aware of these common warning signs:
- unexpected emails, texts, messages or phone calls
- pressure to act quickly or urgently
- requests for passwords, authentication codes or personal information
- suspicious links, attachments or QR codes you weren’t expecting
- caller IDs that look real but may be fake
- strange or misspelled email addresses
- generic greetings like ’Dear customer‘ and poor spelling, grammar or formatting
- callers asking you to skip normal security steps
- threats or warnings of serious consequences if you don’t act
- messages that seem too good to be true
- voices that sound unusual or too perfect (possible voice cloning).
What you can do about phishing
Taking a moment to stop and check before you act can help keep your information and accounts secure.
- Be careful with messages and calls: don’t click links, scan QR codes or download files you weren’t expecting.
- Use trusted sources: go directly to official websites or use known phone numbers instead of links in messages.
- Don’t share personal details: never give out passwords, authentication codes or banking details.
- Use strong security: use passkeys, set strong passwords and turn on multi-factor authentication.
- Keep devices and software updated: install updates and security patches regularly.
- Check before you act: if something feels urgent or unusual, stop and verify it.
- Protect your accounts: contact your bank or service provider if you think your details are at risk.
- Stay informed: learn to spot scams and common tricks used by scammers. For current scams check Scamwatch.
It’s also important for workplaces to build simple and effective practices to reduce the risk of phishing.
- Encourage staff awareness: check messages carefully and report anything suspicious.
- Limit QR code risk: avoid interacting with QR codes in emails where possible.
- Use secure QR tools: create QR codes using trusted and secure tools.
- Improve security systems: work with IT providers to strengthen email and security protections.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.