Learn to spot a scam

Updated View source
Stay safe

Phishing is any scam that pretends to be someone you trust, a bank, a delivery company, an employer, or a friend, to trick you into handing over a password, a payment, or personal details. It works because it copies things that look normal and because it catches you in a hurry.

The good news is that phishing is not endlessly inventive. It reuses the same handful of tricks over and over, because they are cheap to run and they still work. The seven lessons below cover the patterns behind the large majority of scams a normal person actually runs into, from a fake login box to a QR code on a parking meter. Once you can name a trick, you can see it coming. Each lesson is short, written in plain language, and free.

Phishing is not only a problem for people who are careless or not technical. Modern scams are well made, they arrive at the exact moment you are expecting a message from a bank, a courier, or your workplace, and they lean on urgency so that you act before you think. Anyone can be caught on a bad day. Knowing the patterns is what tips the odds back in your favour, whoever you are.

The lessons

Read them in any order. If you only have time for one, start with the golden rules, then come back for the specific tricks when you want to go deeper.

How QR code phishing (quishing) scams workA scam link hidden inside a QR code, so you cannot read the address before you scan it. Learn why a printed square of dots is riskier than a normal link, and how to check one safely. What is a device-code phishing attack?A scam that gets you to approve a real sign-in code, handing the attacker a logged-in session without ever seeing your password. Learn where these prompts come from and when to refuse one. What is an AiTM (adversary-in-the-middle) attack?An attack that relays your login through the attacker's server in real time, so it can steal your session even when you use two-factor security. Learn how it beats MFA and what still stops it. How to spot a lookalike domainA web address built to imitate a trusted brand with small spelling changes or swapped characters. Learn the common tricks and how to read a domain from the right end to spot a fake. How to spot a fake login pageA near-perfect copy of a real sign-in screen whose only job is to capture what you type. Learn the tells that separate a genuine login from a trap before you enter a password. How to spot a disguised downloadA harmful program dressed up as a harmless file such as a PDF or an image. Learn how the disguise works and how to check a download before you open or run it. Golden rules for avoiding phishingThe short list of everyday habits that stop most phishing before it starts, whichever exact trick is being used. The best place to start if you read only one lesson.

Where to start

You do not need to memorise any of this. The goal is to recognise the shape of a scam, the sudden urgency, the address that is almost right, the login box that appeared a moment too conveniently, so the next unfamiliar trick still feels off even if you have never seen that exact version before.

Fish Catcher puts these same checks in your browser and warns you, in plain language, when a page looks like one of these tricks. It never blocks a page. It explains what it sees and leaves the decision to you, and the reason it gives is written to teach you the pattern, so over time you need it less.

None of the lessons assume any technical background. They use plain words, real examples, and the same language Fish Catcher uses in its own warnings, so what you read here and what you see in your browser reinforce each other. Come back to them whenever a message makes you pause. That pause is usually worth trusting.