Malicious emails, also known widely as phishing emails, are one of the most common methods scammers use to steal personal information, financial details, or even infect your phone or computer with dangerous tools. These deceptive messages are designed to look like they're from trusted organisations, such as your bank, government agencies, or well-known companies, making them difficult to spot at first glance.
In this section, you'll learn what phishing emails are, how to identify the warning signs of a phishing attempt, and the critical steps to take if you receive one. From spotting suspicious links to recognising fake email addresses and unusual language, you'll be equipped with the knowledge to protect yourself.
Understanding how phishing works and being able to recognise these threats is one of the first and most important steps to staying safe online. With the right awareness, you can avoid falling victim to these scams and keep your personal information secure.
A phishing email is a fake message that pretends to be from a trusted company, like your bank, an online shop, or a service you use. The goal is to trick you into clicking a link, opening an attachment, or giving away personal information such as passwords, bank details, or even your identity.
Phishing emails often use urgent or scary language to make you act quickly without thinking, such as threatening to close your account or warning of suspicious activity. Even though these emails can look very real, there are usually small signs - like strange email addresses, spelling mistakes, or suspicious links - that give them away.
Phishing emails can be tricky to spot, but you should always look out for the following:
If you are still unsure after checking these things, contacting the supposed sender of the email is the best course of action but do not use the contact details from the email, search the company online then contact via official, public details.
The image (above if you are on mobile, to the right if you are on computer/laptop) is an example of a phishing email. You can see from the senders address that there is a spelling mistake and also note the sense of urgency and generic tone (Dear Customer, please click the link below within 24hrs). These kinds of emails are more than likely dangerous, and you should not click any links or respond to the sender.
If you believe an email you've received is in fact phishing, you should ensure you check off the following:
If you have clicked on a link then entered credentials, you should change all your passwords immediately and contact your bank if any financial information was given. If you opened an attachment, you should run a virus scan on your device straight away to ensure there are no malicious applications or services. If you have suffered loss of data or money, please check out our "Get help after a scam" page for more info, by clicking this text.
Click the sections to expand the answers
This is false. Some malicious websites, if done correctly by the attackers, can cause damage simply by being on the website. Always check links before clicking.
This is true. A common way that threat actors learn about who you may be connected with is by them looking you up on social media platforms or public websites.
This is false. If the email uses urgent nature or language, it's actually more likely to be phishing.
This is true. Attackers often spoof the addresses of people you may be familiar with to make the email appear more legitimate. Always check the senders address and even check with them via existing contact methods to be sure.
This is false. Even if you have the most expensive mail protection, phishing emails can often quite easily bypass the checks they perform.