Phishing is still the most common entry point for cybercrime against ordinary households. The FBI's Internet Crime Complaint Center (IC3) reports phishing as the most-reported cybercrime type year after year, well above ransomware or identity theft. The good news is that the techniques don't change much — a small set of checks catches the vast majority of attempts.
This guide walks through what phishing looks like in 2026, the specific tells that a message is not what it claims to be, and the few habits that protect you even when an attack slips past the obvious checks.
What phishing actually is
Phishing is any message that impersonates a legitimate sender to get you to click a malicious link, open a malicious attachment, hand over a password or one-time code, or send money. It arrives by email, SMS ("smishing"), voice call ("vishing"), and increasingly in messaging apps and direct messages on social platforms.
The most damaging version is "spear phishing," which targets a specific person and uses real details — your boss's name, a real invoice number, a service you actually use — to look legitimate. Generative AI has made spear phishing easier to produce at scale, which is one reason the volume has risen.
What to check, in order
The single highest-value check is the sender's actual email address (not the display name). Click or hover on the From field to see the real address. "Amazon Support <support@amaz0n-billing.com>" is the kind of mismatch that gives away most attempts. On mobile, this is harder to see — long-press the sender on most clients to reveal it.
Second, hover over every link before clicking. Real URLs and displayed text often don't match in phishing. Look at the actual domain at the start of the URL: "amazon.com" is legitimate, "amazon.com.account-secure.io" is not — the real domain in that example is "account-secure.io."
- Real sender domain (not just the display name)
- Actual link destination (hover before clicking)
- Spelling and grammar — though AI has made this less reliable
- Urgency cues ("Verify within 24 hours or your account will be locked")
- Requests for credentials, codes, or payment outside the normal channel
Common pretexts in 2026
The most common pretexts haven't changed much: package delivery problems (USPS, FedEx, UPS), bank or credit-card fraud alerts, IRS or tax-refund messages, streaming-service billing issues, password resets you didn't request, and Microsoft or Google "account security" warnings. Each impersonates a service you probably use.
A newer category: "MFA fatigue" attacks where attackers spam you with multi-factor authentication prompts hoping you'll approve one out of frustration. If you didn't initiate a login, deny the prompt — every time.
When in doubt, go to the source directly
If a message says there's a problem with an account, do not click the link in the message. Open a new browser tab, type the company's URL yourself (or use a bookmark), and log in normally. Legitimate alerts will appear in the account; phishing pages will not exist there.
For phone calls claiming to be from your bank, hang up and call the number on the back of your card. Caller ID can be spoofed; the number you dial yourself cannot.
Defenses that protect you even if you slip
Two safeguards matter more than any other and should be set up before you need them. First, use a password manager so every account has a unique password — that way, a stolen password from one site cannot be reused on others (credential stuffing). Second, turn on multi-factor authentication (MFA) for every important account, preferring app-based or hardware-key methods (which are phishing-resistant) over SMS where possible. CISA, the federal cybersecurity agency, considers MFA the single highest-leverage individual control.
Together, a password manager plus hardware-key MFA on email and financial accounts defeats the vast majority of real-world phishing — even when the user is fooled.
If you clicked something
Most clicks alone are recoverable. If you entered a password, change it immediately on the real site and anywhere else you've reused it. If you entered an MFA code, treat the account as compromised — change the password, revoke active sessions, and review recent login activity. For financial accounts, contact your bank's fraud line. Report the phishing message to the company being impersonated and to reportphishing@apwg.org or via the FTC at reportfraud.ftc.gov.
