Skip to content
Cyber Unboxed
Attacks

Phishing: How a Simple Email Can Lead to a Big Problem

It only takes one click. Here is how phishing works, why it is so effective, and how you can spot it.

4 min readBeginner Aug 11, 2026

Explain Like I'm Not a Hacker

Phishing is like a fake knock at your door โ€” it looks and sounds like someone you know, but it's a stranger trying to get you to let them inside.

The 30-second explanation

Someone pretends to be a person, brand or coworker you already trust, manufactures a reason to act quickly, and asks you to click a link, open a file, or sign in somewhere. The message borrows real logos, familiar formatting and a domain that reads as legitimate unless you check it closely, so the deception works on the eye before it ever works on your judgement. The goal is almost always to get you to hand over credentials, install something, or approve a transaction the attacker benefits from.

How it works

  1. 1

    1. Fake message

    You receive an email, SMS or chat message that copies a real sender's name, logo and tone, often spoofing the visible From address.

  2. 2

    2. You click

    You click a link to a lookalike domain, download an attachment that runs a script, or type your username and password into a cloned sign-in form.

  3. 3

    3. Attacker gets access

    The attacker's page logs the submitted credentials, or the attachment installs malware that gives them code execution on your device.

  4. 4

    4. Damage

    They use that access to read your email, reset other passwords, move money, or send the same phishing message onward from your real, trusted account.

Phishing works by using fake emails, texts or websites built to look exactly like ones you already trust. The attacker impersonates a company, a coworker or a service you use, manufactures a reason for urgency (a suspended account, an unpaid invoice, a missed delivery), and asks you to click a link, open an attachment, or enter your details on a page that looks identical to the real thing. That page usually sits on a domain that only looks right if you don't check it: a hyphen added, a letter swapped, an extra subdomain tacked in front of the real brand name. Once you act on the message, the attacker has what they need, whether that's a password, a foothold on your device, or your direct cooperation moving money. From there they can get into your accounts, install further malware, or use your identity to go after people you know.

Real-world example

You get an email saying your account's been suspended over unusual activity, asking you to verify your identity within 24 hours or lose access. It looks real: same logo, same footer, same shade of blue as every other email that company sends. You click through, land on a sign-in page that matches pixel for pixel, and type in your username and password. A loading spinner, then a redirect to the real company's homepage โ€” nothing looks obviously wrong. Your credentials just went straight to the attacker, who now has a working login to try against your other accounts too. A genuine company will never ask you to confirm your password by clicking a link in an unsolicited email. That's the giveaway, not how convincing the email looks.

How to spot it

  • Check the sender address, not just the name

    The display name can say anything; the actual address or domain often reveals a slight misspelling or an unrelated domain entirely.

  • Watch for manufactured urgency

    Threats of account suspension, legal action, or a limited-time offer are designed to make you act before you think it through.

  • Hover over links before clicking

    Hovering, or long-pressing on mobile, reveals the actual destination URL, which frequently does not match the text or the brand it claims to be.

  • Think before acting on any request for credentials

    A legitimate service will never ask you to re-enter your password by following a link from an email or text message.

What to do

  1. 1Don't click links or open attachments in a message you weren't expecting, even if it appears to come from someone you know.
  2. 2Report it using your email provider's or organisation's built-in phishing-report button, so the message can be blocked for others too.
  3. 3If you already entered credentials, change that password immediately, enable MFA on the account, and check its recent sign-in and mail-forwarding-rule activity for anything you didn't set up.

Stay curious. Stay safer.

This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.

Explore More

Keep reading