Phishing attacks have grown increasingly sophisticated with automated scripts and lookalike domains. The old advice — "watch for spelling mistakes" — still applies, but it's no longer nearly enough. Modern phishing pages are pixel-perfect clones of real login screens, and the emails that link to them are often personalized using data pulled from previous breaches.
The warning signs that still matter
- Urgency and fear. "Your account will be suspended in 24 hours" is designed to make you click before you think. Legitimate companies rarely threaten immediate account loss over email.
- A mismatched sender domain. The display name might say "Netflix Support," but check the actual address after the @ symbol — it's frequently a domain that has nothing to do with the real company.
- Links that don't match their text. Hover over (or long-press on mobile) any link before tapping it. If the underlying URL looks unrelated to the company it claims to be from, don't click.
- Requests for credentials via email. No legitimate bank or major platform will ask you to "confirm your password" by replying to an email or filling out a form linked from one.
What's changed recently
Two shifts make phishing harder to catch on sight than it used to be. First, lookalike domains have gotten cheaper and easier to register in bulk, so attackers can burn through dozens of near-identical URLs before spam filters catch up. Second, breach data from unrelated services is now routinely combined to make phishing emails feel personal — a message that references your real name, a service you actually use, or even a past order number feels far more credible than a generic "Dear Customer."
A simple habit that blocks a lot of this
Because phishing usually arrives by impersonating a service you signed up for somewhere, using a unique, disposable address for every low-trust sign-up does double duty: if you start receiving phishing attempts at an address you only ever gave to one specific site, you immediately know exactly where the leak came from — and because that address isn't tied to your real identity or your main accounts, a convincing phishing email sent to it has far less to work with.
If you've already clicked
Don't panic, but act quickly: change the password for the real account on the real site (typed manually, not via the email link), enable two-factor authentication if you haven't already, and check whether the same password was reused anywhere else. If you entered financial information, contact your bank or card issuer directly using the number on the back of your card, not any number provided in the suspicious message.