How to Spot a Phishing Attack Before It Fools You
A phishing attack goes like this: you get an email from your bank. Your bank says there’sa problem with your bank account and you need to log in right away to fix it. There is a link in the email. You click the link, and type your password into it. Just like that, you just gave your password to a hacker.
This is what phishing is, and phishing is a really popular and common way for people's accounts to get hacked. But, if you know the signs of a phishing attack, you can really easily tell if an email is a phishing attack. Below, learn about what phishing is, and how to stop it.
What phishing really is
Phishing is actually just a trick . Phishing is when a hacker tries to be someone you trust, like maybe a bank, or a delivery company, maybe a streaming service, or your workplace. The hacker tries to make you give them your password or other personal information. Phishing usually rushes you, so you don’t have time to think.
The fake login pages the hacker makes can look perfect.The fake login pages could have the same logos, colors and layout as the real login pages. This is why you can't tell if something is a phishing attack just because of how the login page looks. You have to look at other things.
The warning signs
Most phishing attacks all have a couple of things in common:
- Urgency:A phishing attack might say something like”Your account will be closed in 24 hours”.Actual, real companies never do this.
- Odd sender addresses: The name might say “Netflix,” but the actual email address is just a bunch of random letters or a weird domain.
- Links that do not match: Hover your mouse over a link before clicking it. If the text says one thing but the address is different, that's a sign that that’s a phishing attack.
- Requests for your password: Legitimate companies do not email you asking for your password or full account details. Actual companies don't ask you for your password or your account details.
- Small mistakes:Weird grammar, misspelled words, or not right logos usually means that it's a phishing attack.
A password manager quietly protects you here
Defending against phishing attacks is one of the most useful and good things about a password manager. They stop phishing attacks in amway your eyes can't.
A password manager fills in your login only on the real website it saved. If you saved your bank password for a real bank website, and you go to a fake copy with a different address, the password manager will not know it. It will not autofill. That’s a warning. If your password manager doesn’t fill in a login on a website, stop and check the address carefully. You're probably on a fake site.
Your own eyes can be fooled by a perfect copy. The manager checks the actual web address, which the fake site cannot truly fake.Your eyes probably can't tell the difference between a fake website and a real one. The password manager actually checks the web address, which a fake site can’t copy.
What to do if you are not sure
If you're not sure if a message is a phishing attack or not, don't click the links in the message. You should actually open a new tab and go to thecompany’s website by typing the address yourself, or use the app you already have. Login like you normally would and check for any alerts or other things there. If the message was a phishing attack, you'll see nothing wrong and you'll lose nothing.
You can also just contact the company using their phone number or address from their official site, and not from the weird message.
Stay calm, stay slow
Phishing attacks work because they rush you. The best thing to do is just slow down. Actual emergencies from actual real companies don't rush you. Phishing attacks only work if you panic and just click the link.
With HatePassword, your passwords stay encrypted and only fill in on the sites you actually saved them for.If you add using HatePassword with a habit for pausing before you actually click the link, that makes you really protected from phishing attacks.