Home/Digital threats

Scams & Fraud

Phishing attacks

Fake messages that trick you into handing over passwords, codes, or money.

What it is

Phishing is a message — email, text, call, or social-media DM — that pretends to come from someone you trust, such as your bank, a delivery company, or a government office. Its goal is to make you click a link, open an attachment, or reveal a password or one-time code. It is the single most common way ordinary accounts get broken into.

How it happens

An attacker sends a message crafted to trigger urgency or fear — a blocked account, a missed delivery, a suspicious charge. The link leads to a fake login page that looks identical to the real one. The moment you type your details, they are captured. If your account is protected by two-factor authentication, the fake page will also ask for the code, then use it within seconds.

Warning signs

  • Urgency or threats — act now or your account will be closed.
  • A link whose address does not quite match the real organisation.
  • Requests for a password, PIN, or one-time code.
  • Small errors in spelling, grammar, or the sender's address.

Who it targets

Everyone is a target, because phishing is sent in bulk to millions of addresses at once. Attackers pay special attention to people with access to money or accounts — small-business owners, finance staff, and older adults who may be less familiar with the tactics.

How to protect yourself

  • Never log in or pay through a link in an unexpected message — go to the site or app directly.
  • Turn on two-factor authentication, ideally with an app or security key rather than SMS.
  • Never share a one-time code; no genuine organisation will ever ask for one.
  • Use a password manager — it refuses to auto-fill on fake look-alike sites.
  • When in doubt, phone the organisation using the number on the back of your card.

If it happens to you

  1. If you entered a password, change it immediately — and anywhere else you reused it.
  2. Contact your bank if any payment or card details were shared; ask them to watch for fraud.
  3. Turn on or reset two-factor authentication on the affected account.
  4. Report the message to your email or phone provider, and to your national fraud service.