Scam & Fraud Glossary

Phishing

Fraudulent messages that impersonate a trusted brand to steal your passwords, card details or money.

Phishing is fraud by impersonation: a message pretending to come from a bank, retailer, courier or government body, engineered to make you hand over passwords, card details or money. Email is the classic carrier, though the same trick runs across every channel. The tell is nearly always a manufactured reason to act at once — a suspended account, a missed parcel, a refund waiting — paired with a link to a look-alike login page that quietly harvests whatever you type.

Good fakes copy branding closely, so the safest habit is never to act inside the message itself: open the organisation's site or app the way you normally would and check there instead. Learn to check an email properly before trusting it, and treat any unexpected request for credentials as suspect until proven otherwise. Related variants travel by text, phone and QR code; all lean on the same social engineering. In the UK you can forward suspect emails to [email protected], which feeds takedown efforts.