Phishing
Phishing is a scam in which an attacker sends a message posing as a trusted person or organization, hoping you'll hand over passwords, payment details, verification codes, or other sensitive information. Typically the message steers you toward a fake login page or asks you to reply with private data. Its power comes from looking legitimate, not from breaking any technology.
How we check this: Written and reviewed by the Hunch team; recognition signs reflect how the FTC/FBI describe this scam. · Last reviewed: 2026-08
Check a suspicious message now
Example
You get an email that looks like it's from your bank saying your account is locked. It urges you to 'verify immediately' by clicking a link, which opens a page that looks exactly like your bank's login but is actually controlled by the scammer, capturing whatever you type.
How to recognize it
- Pressure to act right now or lose access, money, or a package
- A link whose real address doesn't match the brand it claims to be from
- Requests for your password, full card number, or a one-time code
- Generic greetings, odd grammar, or a sender address that's subtly wrong
How Hunch flags it
Hunch keys on signal categories like manufactured urgency, lookalike or mismatched domains, and any request for credentials or payment. It flags when a message combines a trusted-brand appearance with those pressure and data-collection signals.
FAQ
What is the goal of a phishing attack?
To get you to reveal something valuable, a password, a bank or card detail, or a verification code, or to click a link that installs malware or opens a fake login page.
How is phishing different from spam?
Spam is unwanted bulk advertising; phishing is deliberately deceptive and aims to steal information or money by pretending to be a source you trust.
What should I do if I clicked a phishing link?
Don't enter anything on the page, close it, and if you already typed a password, change it and enable two-factor authentication right away.