Monday, August 17, 2026 Independent journalism
MediaChannel

technology

What is phishing and how do you spot it?

Phishing is the most widespread form of online fraud targeting Australians, yet many people still can't spot it in time. Here's a clear, jargon-free guide to how it works and how to protect yourself.

Abstract representation of phishing with the text on a textured dark surface.

Photo by Ann H on Pexels

Phishing is a type of cyber attack where a criminal impersonates a trusted source, such as a bank, a government agency, or a well-known company, to trick you into handing over sensitive information. That might mean your password, your credit card number, or your tax file number. The name comes from "fishing": attackers cast a wide net and wait to see who bites. Millions of phishing messages are sent every day, and Australia is consistently among the top targeted countries in the world.

How phishing actually works

Most phishing attacks arrive by email, but the same tactics show up in text messages (called smishing), phone calls (vishing), and fake social media accounts. The core method is always the same. The attacker creates a message that looks convincing enough to make you act without thinking. A sense of urgency is the main lever: "Your account has been compromised", "Your parcel couldn't be delivered", "You owe a tax debt".

Clicking the link in a phishing email takes you to a fake website. It often looks almost identical to the real one, right down to the logo and colour scheme. The moment you type in your credentials, the attacker captures them. Some attacks go further and install malware on your device the instant the link is clicked, without any login page involved at all.

Understanding phishing sits alongside broader cybersecurity awareness, which covers the wider range of digital threats facing individuals and businesses. Phishing is one piece of that picture, but it's the one most likely to catch everyday Australians off guard because it targets human behaviour, not technical vulnerabilities.

The most common types of phishing

Not all phishing messages are the same. Spear phishing targets a specific person, using personal details scraped from LinkedIn or social media to make the message feel genuine. A spear phishing email might use your actual name, your employer's name, and reference a recent project. It's far harder to dismiss than a generic "Dear Customer" message.

Whaling is spear phishing aimed at executives. The goal is often to trick a CEO or CFO into authorising a large bank transfer. Business email compromise (BEC) works similarly: attackers compromise or impersonate a company email account and use it to redirect payments. The Australian Competition and Consumer Commission's Scamwatch has recorded hundreds of millions of dollars lost to BEC scams in recent years.

Clone phishing copies a legitimate email you've actually received, replaces the link or attachment with a malicious one, and resends it. Because the format matches something real, it passes a quick glance easily.

How to spot a phishing message

A few signals appear in nearly every phishing attempt. Check the sender's email address carefully, not just the display name. A message can say it's from "Commonwealth Bank" while the actual address is something like support@commbank-secure.xyz. That mismatch is the giveaway.

Look at the link before you click it. Hover over it on a desktop and the real destination appears in the status bar. A URL that doesn't match the organisation's official domain is a red flag. Watch for subtle misspellings: "paypa1.com" instead of "paypal.com", or a hyphen inserted where there shouldn't be one.

Urgency and threats are engineered to override caution. Real banks and government agencies don't demand immediate action via email or threaten to close your account in 24 hours. Unexpected attachments, especially .zip or .exe files, should never be opened from an unknown sender. Poor spelling and grammar still appear in many phishing emails, though AI-generated messages have made this less reliable as a signal on its own.

What to do if you receive a phishing message

Don't click anything. Don't reply. If the message claims to be from your bank or from the Australian Tax Office, go directly to the official website by typing the address yourself, or call the organisation on a number you find independently. Report the message to the Australian Cyber Security Centre at cyber.gov.au, and to Scamwatch if it's a consumer scam. Most email clients let you mark a message as phishing or junk, which helps filter future attempts.

If you did click a link and entered your credentials, act fast. Change the password on that account immediately, and on any other accounts where you use the same password. Contact your bank if financial details were involved. Enable two-factor authentication on every account that supports it. As our guide on two-factor authentication explains, that second layer of verification stops most attackers even when they have your password.

Why phishing is so hard to eliminate

Technical filters catch a lot, but not everything. Attackers constantly adapt: they use compromised legitimate domains, shift to messaging platforms less likely to have spam filters, and tailor messages to current events. A tax-time phishing wave lands in inboxes every July in Australia because it's plausible. A COVID-related scam, a bushfire donation fraud, a fake MyGov login page during budget season: timing and context are what make these attacks land.

Organisations invest heavily in email security, but one employee clicking one link can undo those defences. That's why phishing awareness training has become a standard part of corporate security programs across the country. The weakest link isn't the firewall. It's the moment a tired person reads a convincing email at 5pm on a Friday.

Staying sceptical costs nothing. Verifying before you click takes 30 seconds. Those two habits block the overwhelming majority of phishing attempts before they cause any damage.