Forms and channels
Phishing refers to attempts to obtain sensitive data such as login credentials, credit card numbers or TANs via fake messages (email or SMS, then also called “smishing”) or rebuilt websites. Typical is the imitation of well-known senders such as banks, parcel services, payment providers or well-known online shops, including a copied logo and layout.
Phishing arrives through many channels. Alongside classic emails there are texts about supposed parcel notifications, calls from alleged bank staff and QR codes on stickers that lead to forged payment pages. The pattern is always the same: a familiar brand, a plausible pretext and an action that must happen immediately. Anyone who knows the pretext recognises the scheme regardless of the channel.
With fake shops, phishing often overlaps with the goods fraud: after an order, fake “shipping” or “payment problem” emails follow, with links to rebuilt login or payment pages designed to skim bank details as well. The loss then goes beyond the goods that were never delivered.
Spotting forged addresses
First check the address a link leads to. Fraudsters work with a handful of recurring tricks: swapped or substituted characters in the name (a digit one instead of a lowercase L, for instance), appended additions such as “-security” or “-service”, and above all the subdomain trick. In an address of the form “well-known-brand.com.login-check.xyz”, the registered domain is the trailing part, “login-check.xyz”. Everything before it is freely chosen text. What counts is always what stands immediately before the first single slash.
Another trick uses letters from other alphabets that look confusingly similar to Latin characters. Such addresses are visually almost indistinguishable from the real thing. Modern browsers display them in a decoded form beginning with “xn--”. If you see that in the address bar, leave the page immediately.
Signs of a phishing message
Further signs of a phishing message are: a sender address that resembles the real domain without matching it; time pressure (“your account will be blocked”, “today only”); an impersonal salutation even though the supposed sender knows your name; and attachments you were not expecting. No bank, no payment service and no shop will ask you by email to enter a password, PIN or TAN.
An everyday example: two days after an order, an email arrives bearing a parcel service’s logo, subject “customs fee of €2.99 outstanding”, with a link to a payment page. The sum is deliberately small so that nobody thinks twice. The page then asks for full card details including the security code. The amount is the bait, and the card details are the goal.
Attachments call for caution. Invoices or reminders for orders you never placed frequently carry malware rather than a document. Do not open such files “to see what it is about”. The order number in the subject line is invented and exists to trigger that curiosity.
Protecting your login details
An effective protection is a password manager. It fills in credentials only on the domain they were saved for. If you land on a rebuilt page, the field stays empty. That absence is a warning signal that works even when you overlook the forged address while reading it. When in doubt, always log in via the known address you type in yourself and never via a link in an email.
Never pass confirmation codes for two-factor authentication on to third parties, not even to supposed staff on the phone who want to “unlock the process”. Such a code is the last key to your account; anyone asking for it already has the password and only needs you.
Reporting and immediate steps
Reporting is worthwhile even when nothing happened. Consumer protection bodies collect phishing messages, and the imitated companies usually operate their own reporting addresses through which forged pages are taken down faster. Forwarding an email costs you little time and shortens the life of the campaign for everyone else. Anyone who has already clicked and entered data should act in this order: