Learn to spot a scam

Updated View source
Stay safe

Phishing is any scam that pretends to be someone you trust, a bank, a courier, an employer, to get a password, a payment, or personal details out of you. It works by copying what looks normal and catching you in a hurry.

The lessons

Seven short lessons, one trick each, in plain language. If you only read one, start with the golden rules.

How QR code phishing (quishing) scams workA scam link hidden inside a QR code, so you cannot read the address before you scan it. What is a device-code phishing attack?A scam that gets you to approve a real sign-in code, handing the attacker a logged-in session without your password. What is an AiTM (adversary-in-the-middle) attack?An attack that relays your login through the attacker's server so it can steal your session even with two-factor turned on. How to spot a lookalike domainA web address built to pass for a trusted brand with a swapped letter, an extra word, or the brand buried in a longer name. How to spot a fake login pageA copy of a real sign-in screen whose only job is to capture what you type. How to spot a disguised downloadA harmful program dressed up as a PDF, a photo, or a spreadsheet. Golden rules for avoiding phishingFive everyday habits that stop most phishing before it starts, whatever the trick.

Fish Catcher runs these same checks in your browser and explains what it sees in plain words, without ever blocking a page. Come back whenever a message makes you pause, since that pause is usually worth trusting.