In simple terms — Phishing is a lure: someone pretends to be a trusted service or person and pushes you to click, log in, download a file, disclose a secret, or authorise an operation.
It is not limited to badly written email. Phishing can arrive through text messages, direct messages, calls, QR codes, adverts, or cloned pages, and it can look polished. The common signal is a request that moves urgency and trust away from the genuine channel and into one controlled by the attacker.
From the lure to the requested action
The message may report a suspicious login, urgent withdrawal, airdrop, or mandatory check. A link leads to a page copying an exchange, broker, or wallet; another version asks the user to install an app, disclose a code, or sign a request. Correct language, familiar branding, and knowledge of personal details do not make the contact authentic: automated tools and previously exposed data can produce convincing messages.
Phishing is the technique used to deliver deception, not necessarily the final fraud. It may lead to credential or seed phrase theft, a wallet drainer, or a clone website. An unsolicited message without impersonation or an attempt to extract something is not phishing by itself: it may be spam or another fraud. It can also distribute malware, but it is not synonymous with malware.
Verification and response after interaction
Do not reply through the suspicious message. Open the app from a known icon or type the official domain, then check notifications and support. If the request appears to come from a person, use another contact method already verified. A legitimate operator should not ask for a full password, one-time code, or recovery phrase through an unexpected contact.
If you entered credentials, change the password through the genuine service, revoke active sessions, enable multi-factor authentication, and check email forwarding rules. If you downloaded a file, keep that device away from sensitive activity and follow your organisation's security checks. If you signed with a wallet, examine the transaction and permissions: closing the page does not automatically revoke an approval already granted. Preserve the message and report the attempt to the impersonated service.
Sources
- NIST — Phishing — Defines impersonation of a trusted source to obtain sensitive information or direct someone to a counterfeit site.
- FTC — How to recognize and avoid phishing scams — Covers common requests, independent verification, and actions after a click.
- ESMA — Crypto frauds and scams — Links messages, QR codes, and fake applications to credential and crypto-asset theft.
Related entries
Anti-scam · Red flags · Clone website · Wallet drainer · Seed phrase theft