Computer Literacy · Foundations
Phishing
On this page 9 sections
In 30 seconds
Phishing A deceptive message that impersonates a trusted party to trick someone into revealing sensitive information, sending money, or opening a harmful link or attachment. Full entry → is a deceptive message that pretends to come from someone you trust, such as a bank, a store, an employer, or a coworker, to trick you into handing over a password or payment, or into opening a harmful link or attachment. It usually arrives by email but also by text or phone call. The classic warning signs are urgency, a request for Credentials The information used to prove who you are when logging in, most commonly a username and password. Full entry → or money, and a link or sender that does not quite match the real organization. The defense is simple: do not click or reply, verify through a channel you already trust, and report it.
Why this matters
Phishing is the entry point for a large share of account takeovers, financial fraud, and malware infections, and colleges, employers, and banks are all common targets and pretexts. As a student you will get messages about tuition, financial aid, grades, and job offers, and scammers imitate exactly those. Learning to pause on an unexpected request and verify it before acting protects your money, your accounts, and any organization whose systems you can reach. The skill also transfers: the same habits that catch a phishing email catch fake tech-support calls and text-message scams. Recognizing manipulation is now part of basic digital literacy, not an optional extra.
The college version
What phishing is
Phishing is an attempt to trick you into revealing sensitive information or taking a harmful action by pretending to be a party you trust. CISA describes it as criminals trying to get you to open harmful links or attachments, or to reveal personal and financial information, through a message designed to look like it comes from a trusted person or organization. It is a form of Social engineering Manipulating a person into giving up information or access by exploiting trust and human behavior rather than by defeating technical controls. Phishing is one form of it. Full entry →: rather than breaking through technical defenses, the attacker manipulates a person into opening the door. The bait usually arrives as an email, but it can also be a text message, a direct message on social media, or a phone call. The goal is almost always one of three things: to steal credentials (usernames and passwords), to obtain money or payment information, or to get you to install malware by opening an attachment or link. Because the message impersonates something familiar, it works by borrowing trust you have already extended to the real organization.
How to recognize it: red flags
Both CISA and the FTC publish overlapping lists of warning signs. Watch for urgent or emotionally charged language, especially a message claiming a dire consequence if you do not act immediately, such as an account being suspended or a payment failing. Be suspicious of any unexpected request to send personal or financial information, confirm a password, or make a payment. Look closely at the sender's address and at links: scammers use addresses and lookalike domains that closely resemble a real company by changing or omitting a few characters, for example amazan.com instead of the real domain, and they hide destinations behind shortened or mismatched URLs. Hovering over a link to see whether its true destination matches the visible text can expose a spoofed link. Other classic signs include a generic greeting like 'Dear Valued Customer' instead of your name, an unexpected attachment or an invoice you do not recognize, and offers that are too good to be true. Poor spelling and grammar used to be a reliable tell, but CISA now warns that AI-generated messages often have perfect grammar, so a polished message is not proof it is genuine.
The variants, by name
Most phishing is untargeted bulk email blasted to thousands of addresses. Spear phishing A highly targeted phishing attack aimed at a specific individual or organization, often personalized with details about the target to seem more credible. Full entry → is different: it is a highly targeted attack aimed at a specific person or organization, often using details about you (your role, your employer, a recent event) to make the message far more convincing. Whaling Spear phishing that specifically targets high-ranking members of an organization, such as senior executives. Full entry → is spear phishing aimed at high-ranking members of an organization such as executives, where a successful trick can authorize a large wire transfer or expose sensitive data. The variants are also named by channel. Smishing Phishing carried out through SMS or text messages, often containing a link or a number the victim is urged to use. Full entry → exploits SMS or text messages, which may carry links that open a browser, an email, or a phone dialer. Vishing Phishing carried out by voice call, frequently using a spoofed caller ID to appear to come from a trusted source. Full entry → uses voice communication; an attacker may leave a message urging you to call a number and reveal information, and because Voice over IP makes caller ID easy to spoof, a call that appears to come from a familiar number can still be fake. The tactic is the same across all of them, impersonate a trusted party and pressure you to act, only the delivery changes.
What to do: verify, resist, report
The core defense is to slow down and verify through a channel you already trust rather than one the message hands you. If a message asks you to click a link or call a number, do not use the contact details in the message. Instead, look the organization up independently: type its website address yourself or use a number from your card, a prior statement, or the official site. If a message seems to come from a friend or coworker, reach them another way, such as calling a number you already have, to confirm they sent it. Do not click links or open attachments in a suspicious message, and do not reply, not even to an 'unsubscribe' link; the safest action is to report and delete. Report phishing to the impersonated company, to your IT or security team if it targets a work or school account, and, in the United States, to the FTC at ReportFraud.ftc.gov; forwarded phishing texts can go to SPAM (7726) and phishing emails to the Anti-Phishing Working Group at [email protected]. Finally, Multifactor authentication (MFA) A login that requires more than a password, adding a second factor such as a one-time code or fingerprint, which limits the damage if a password is stolen. Full entry → is a critical safety net: even if you do surrender a password, MFA makes it much harder for an attacker to actually log in, because they still lack the second factor. If you think you already entered credentials or financial details, change the affected password, enable MFA, and use IdentityTheft.gov to plan recovery steps.

Eli explains
The same idea, in plain words
Explain it like I’m 10
Phishing is when a stranger sends you a message pretending to be someone you trust, like your bank or your school, and tries to scare or rush you into giving them a password or money, or into clicking something bad. The trick is the disguise: the message is dressed up to look real, and it usually says you must act right now. The way to beat it is boring on purpose. Slow down. Do not click the link in the message. Instead, reach the real company or person a way you already know, like the phone number on the back of your card or a website you type yourself, and ask if the message was really from them. If it is a scam, you delete it and report it, and you do not feel bad, because these tricks fool lots of people every single day.
Picture it like this
Phishing is like a stranger at your door wearing a delivery uniform they bought online, saying you must hand over your house key this instant or your package will be destroyed. The uniform is a costume, and the panic is the whole plan.
Where the picture stops working
The analogy understates the scale and disguise quality: a phishing attacker can send the same 'costume' to millions of people at once for almost no cost, can copy a real company's logo and wording perfectly, and never has to be physically present, so you cannot rely on face-to-face instincts to catch them.
Worked example
You get an email while registering for classes: 'Your tuition payment was declined. Your enrollment will be canceled within 24 hours unless you verify your billing information.' It has the school's logo and a blue 'Verify Now' button. Run the checklist. Urgency and a threat of a bad consequence: red flag. A request to enter payment and login details: red flag. You hover over 'Verify Now' and the status bar shows a link to a domain that is not your school's real address: red flag. The greeting is 'Dear Student,' not your name. Rather than clicking, you open a new tab, type your school's known portal address yourself, and log in there directly. No alert appears, and the billing office confirms your payment went through. The email was phishing. You report it to your school's IT help desk and delete it. Because your account also uses MFA, even a stolen password would not have been enough for the attacker to log in.
Key takeaway
Phishing wins by impersonating trust and manufacturing urgency; you beat it by refusing to act on the message itself, verifying through a channel you already trust, and reporting it, with MFA as a safety net if a password slips through.
Quick check
3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.
An email says 'Your account will be closed in 2 hours unless you confirm your password at this link.' Which combination of red flags is present?
A scammer sends a text message to your phone with a link claiming a package could not be delivered. What is this variant called?
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related
You’ll learn to
- Define phishing and explain how it works as a form of social engineering.
- Identify common red flags in a suspicious message, per CISA and FTC guidance.
- Distinguish the main variants: spear phishing, whaling, smishing, and vishing.
- Apply a verification-before-action routine to an unexpected request.
- Explain what to do after receiving or responding to a phishing attempt, including how to report it and how MFA limits damage.
Common mistakes
Believing a message is safe because it looks professional and has correct spelling and the right logo.
Appearance is easy to fake, and AI now helps scammers write clean, error-free messages. CISA warns that perfect grammar is no longer reassurance; judge the message by its requests and links, not its polish.
Clicking the link or calling the phone number provided in the suspicious message to 'check if it is real.'
The contact details in a phishing message lead back to the attacker. Verify only through a channel you already trust: a website you type yourself, or a number from your card or an official statement.
Assuming a caller or text is genuine because the caller ID or sender shows a familiar name or number.
Caller ID and sender addresses are easily spoofed, especially over Voice over IP. A recognizable number does not prove identity; hang up and call back on a number you look up independently.
Thinking that giving up a password to a phishing site means the account is automatically lost.
Act fast, but do not assume the worst is unavoidable. Change the password immediately and, if multifactor authentication is enabled, the attacker still needs the second factor, which often blocks the login entirely.
Deleting a phishing message but never reporting it.
Reporting helps protect others and lets IT or the impersonated company respond. Report to the company, to your IT or security team for work and school accounts, and to the FTC at ReportFraud.ftc.gov.
Easily confused
Phishing (bulk) vs. Spear phishing
Bulk phishing is a generic message blasted to many recipients; spear phishing is customized for a specific person or organization using details about them, which makes it more convincing and harder to spot.
Smishing vs. Vishing
Both are phishing by a non-email channel, but smishing arrives as a text (SMS) message, while vishing happens over a voice call; each relies on the same impersonation and pressure tactics.
Spear phishing vs. Whaling
Both are targeted, but whaling specifically aims at high-ranking people such as executives, where a single success can authorize large transfers or expose an entire organization.
Key vocabulary
- Phishing
- A deceptive message that impersonates a trusted party to trick someone into revealing sensitive information, sending money, or opening a harmful link or attachment.
- Social engineering
- Manipulating a person into giving up information or access by exploiting trust and human behavior rather than by defeating technical controls. Phishing is one form of it.
- Spear phishing
- A highly targeted phishing attack aimed at a specific individual or organization, often personalized with details about the target to seem more credible.
- Whaling
- Spear phishing that specifically targets high-ranking members of an organization, such as senior executives.
- Smishing
- Phishing carried out through SMS or text messages, often containing a link or a number the victim is urged to use.
- Vishing
- Phishing carried out by voice call, frequently using a spoofed caller ID to appear to come from a trusted source.
- Spoofing
- Faking the origin of a message or call so a sender address, link, website, or caller ID appears to belong to a legitimate party.
- Credentials
- The information used to prove who you are when logging in, most commonly a username and password.
- Multifactor authentication (MFA)
- A login that requires more than a password, adding a second factor such as a one-time code or fingerprint, which limits the damage if a password is stolen.
Sources & references
- Recognize and Report Phishing — CISA (Cybersecurity and Infrastructure Security Agency)
- How To Recognize and Avoid Phishing Scams — FTC Consumer Advice (Federal Trade Commission)
- Avoiding Social Engineering and Phishing Attacks (ST04-014) — CISA (Cybersecurity and Infrastructure Security Agency)
- whaling — Computer Security Resource Center Glossary — NIST (National Institute of Standards and Technology)
- spear phishing — Computer Security Resource Center Glossary — NIST (National Institute of Standards and Technology)
EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.
Researched 2026-08-19
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

