CYBER WELFARE

Protect your Digital Privacy

How to Recognize Phishing When It Is Built to Be Convincing

Additional resource for the lesson “Phishing: Recognising Pages Built to Convince” — Online Security course

The advice to look for spelling mistakes stopped being useful some time ago. Learning how to recognize phishing now means relying less on spotting the fake and more on habits that make the fake harmless even when you do not spot it.

A. Why this matters

Phishing means a message designed to get you to hand something over: credentials, a one-time code, payment details. It arrives by email, text, message or phone call.

The advice most people carry — look for bad grammar, odd logos, strange greetings — was written when those things were common. Today a convincing phishing page is a copy of the real one, and the message that leads to it reads correctly.

The key idea: build the habit rather than the vigilance. Reach financial services and important accounts from a bookmark or the official app, never from a link you received. Then a convincing message has nowhere to lead you.

B. Key concepts

Seven ideas, including the one that explains why a second factor is not always enough.

Phishing

A message imitating a legitimate sender to obtain credentials, codes or payment.

Why it matters to you: The volume is enormous and indiscriminate. Most of it is filtered; the ones that reach you are, by definition, the ones that got through the filters.

The cloned site

A copy of a real login page, often pixel-perfect because it was copied directly from the original.

Why it matters to you: Judging by appearance does not work against something copied from the genuine article. The address is the only thing that differs.

Lookalike domains

Addresses that differ by a character, a hyphen, or a letter from a different alphabet that renders identically.

Why it matters to you: Some of these are genuinely indistinguishable to the eye. This is why the address bar is a weak check and autofill is a strong one.

Real-time phishing

The fake site relays your credentials to the real one as you type, then asks you for the one-time code and relays that too, within its validity window.

Why it matters to you: This is the important one, and it is rarely explained. It means a code from an app can be captured. Only a hardware key or a passkey resists it, because they refuse to respond to the wrong domain.

Spear phishing

A message written for you specifically, using details from your social profiles, your employer, or a real conversation you are part of.

Why it matters to you: Rarer and much more convincing. The defence is not detection but process: verifying an unusual request through a channel you chose yourself.

Bookmarks and official apps

Reaching a service by an address you saved, or through its app, rather than through a link.

Why it matters to you: This is the single most effective habit here, and it is free. It removes the entire class of attack that begins with a link.

Your password manager as a check

Autofill only offers on the domain it has stored.

Why it matters to you: If the manager does not fill, the address is not the one you saved. Treating that silence as a warning is more reliable than reading the address yourself.

C. A practical example: the message that was correct

An email arrives from your bank. Correct logo, correct tone, no spelling errors, your name spelled properly. It says a payment was blocked and asks you to confirm your identity.

  • The link leads to a page identical to your bank’s login.
  • You enter your credentials. The page accepts them and asks for the code from your authenticator app.
  • You enter the code. The page says thank you and redirects you to the real bank site, where everything looks normal.

In those seconds, both your credentials and your code were relayed to the real site by whoever built the page. The second factor worked exactly as designed and was passed through.

What would have stopped it

  • Not arriving from the link: opening the bank from a bookmark and checking the account there.
  • The password manager not offering to fill, which would have happened on the fake domain.
  • A hardware key or passkey, which would not have responded to a domain it does not recognise.

Note that none of the three involves noticing anything about the message. The message was designed to survive being read carefully.

D. Try it yourself: build the habit

Twenty minutes to set up, then it works without further thought.

Step 1 — Bookmark the services that matter

  • Bank, payment services, primary email, work portal.
  • Type each address by hand once, verify it is right, and save it.
  • From now on, reach them only that way.

Step 2 — Set the autofill rule

  • If your password manager does not offer to fill, stop.
  • Do not work around it by copying and pasting. The silence is the information.

Step 3 — Decide your verification channel

  • For any unusual request — a change of bank details, an urgent transfer, a colleague asking for something out of process — verify through a number or address you already had.
  • Never through the contact details in the message itself.

Step 4 — Know where to report

  • Most countries have a national reporting address for suspicious messages.
  • Reporting takes a minute and improves the filters for everyone.

Step 1 is the whole lesson in practice. Everything else is a supporting check for the times you forget.

E. Videos, articles and further resources

Independent and institutional sources in English.

NCSC (UK) — Phishing: spot and report scam messages
How to recognise and, importantly, where to report suspicious messages in the UK.
https://www.ncsc.gov.uk/collection/phishing-scams

CISA — Recognize and report phishing
The US agency’s guidance, including the signals still worth knowing.
https://www.cisa.gov/secure-our-world/recognize-and-report-phishing

FTC — How to recognize and avoid phishing scams
Real examples with what makes each recognisable.
https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams

NCSC (UK) — Passkeys are more secure than traditional ways to log in
Why passkeys resist the real-time technique described above, where codes do not.
https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in

NCSC (UK) — What to do if your account is hacked
What to do in the first hour if you entered something you should not have.
https://www.ncsc.gov.uk/section/respond-recover/hacked-accounts

FTC — How to spot, avoid and report tech support scams
The rule worth remembering: a genuine security warning never asks you to call a number.
https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Awareness pillar at level FL2, and its conclusion is a behaviour rather than a skill.

Skills

  • Reaching services from bookmarks and official apps.
  • Reading autofill behaviour as a signal.
  • Verifying unusual requests through an independent channel.

For professionals and organizations

  • Establishing a verification process for payment and data requests, so nobody has to judge alone under time pressure.

Awareness

  • Understanding that appearance is no longer a reliable indicator.
  • Knowing that real-time phishing can capture one-time codes.
  • Recognising urgency as the common ingredient across otherwise different messages.

For future instructors and ambassadors

  • Never implying that people who fall for phishing were careless. The good ones are designed to work on attentive people, and saying otherwise stops anyone reporting.

Secure Behavior

  • Never signing in from a link received in a message.
  • Verifying unusual requests before acting on them.
  • Reporting suspicious messages rather than only deleting them.

For organizations

  • Making it safe to report a mistake quickly. The hour after matters more than the click.

G. Questions to sit with

  1. How do you usually reach your bank — a bookmark, the app, or a search?
  2. If a message arrived right now saying a payment was blocked, what would you do first?
  3. Have you ever entered credentials on a page you reached from a link? Most people have.
  4. Do you know where to report a suspicious message in your country?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to phishing.

The habits

  • R17 — Do not open attachments or links from unknown sources, and treat unexpected ones from known senders the same way.
  • R9 — Connect over HTTPS, and reach services from a bookmark rather than a link.
  • MS2 — Let the password manager fill: its silence on an unrecognised domain is a warning.

The protections behind them

  • R4 — Multi-factor authentication, preferring a hardware key or passkey where the service supports it.
  • R1, R2, R3 — Unique credentials, so a single compromise stays contained.
  • R8 — Login alerts, so an unexpected sign-in reaches you quickly.
  • MS17 — The strongest protection on the email address linked to your bank.

Minimum commitment: If a service offers passkeys or a hardware key, that is the upgrade that specifically defeats the technique described in this resource.

In short

  • Convincing phishing pages are copies of real ones — appearance no longer distinguishes them.
  • Real-time phishing can relay one-time codes; only hardware keys and passkeys refuse.
  • Bookmarks remove the entire class of attacks that begin with a link.
  • If the password manager does not offer to fill, stop and check the address.

Related resources in this course

The protections that hold when a message is convincing:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program