Phishing is still the single most common way accounts get hacked — not because the code is clever, but because the message looks real enough that someone clicks. In 2026 that problem got worse: spammers now use AI to write near-perfect emails and texts, so the old advice (“just look for spelling mistakes”) no longer works. This guide gives you the red flags that actually hold up, how text-message scams (smishing) and QR-code scams work, and exactly what to do if you already clicked.
What phishing looks like in 2026
Phishing is when a message pretends to be a trusted company to steal your password, money, or device access. The volume is enormous: the Anti-Phishing Working Group (APWG) recorded roughly 3.8 million phishing attacks in 2025, and SMS-based fraud jumped nearly 35% in the second half of the year — the clearest sign that scammers are shifting to your phone.
The newer variations you will actually meet:
- AI-written emails — grammatically clean, personalised with your name and sometimes real details about you.
- Smishing (SMS phishing) — scam texts with a link, usually about a “package delivery” or “account alert”.
- QRishing (QR-code phishing) — a QR code in an email or pasted on a parking meter that points to a fake login page.
- Vishing (voice phishing) — a “bank fraud team” phone call asking you to verify your account.
The red flags that actually matter (skip the spelling test)
Spelling errors are gone — AI fixed them. Look for these instead, because they are hard to fake convincingly.
1. The real sender domain
Do not trust the display name — trust the domain in the From field. “Netflix Support” means nothing; support@netflix.com and support@netflix-security.xyz are different senders even though both may show as “Netflix”. Look for a spoofed or lookalike domain (nеtflix, microsoft-support.co).
2. The ask: your password, an MFA code, or payment
Legitimate companies almost never ask you to reply with a password, a one-time login code, or a card number in an email or text. If a message asks for any of those out of the blue, it is phishing — even if every other detail looks right.
3. The urgent threat
“Your account will be suspended in 24 hours.” Urgency is the scammer’s tool to stop you thinking. Real notifications rarely threaten immediate account loss over email; they tell you to log in and check.
4. The link target
On desktop, hover over a link (without clicking) and read the status bar: does the domain match the company? The link text can say anything; the destination URL is the truth. A good password manager helps too — many flag lookalike domains and gently refuse to autofill on a spoofed site, even when the page looks right.
Smishing: phishing by text message
Texts have higher open rates than email, which is exactly why scammers moved there. Typical lures: a delivery issue with a link to “reschedule”, a bank “suspicious login” with a link, or a free-gift offer. The rules above apply — plus one extra: if a text pressures you to “act now” or the link domain looks odd, delete it and go directly to the company’s app or website instead of using the link.
QRishing: the QR code you cannot inspect
A QR code hides its destination — you cannot hover over it. Scammers print fake QR codes over real parking-meter and restaurant codes, and send them in emails claiming to be from your bank. If you must scan, preview the destination in your camera app first and only type login details on the official site. Remember the password manager rule: never hand credentials to a page you reached by scanning an unprompted QR code.
What to do if you already clicked
- Change that password immediately — and any account that reuses it.
- Revoke the session — log out of that account on all devices, then log back in.
- Turn on multi-factor authentication (MFA) before you do anything else, so a stolen password stops being enough.
- Scan for the damage — run your home cybersecurity checklist to catch a logged-in stranger, new forwarding rule, or changed recovery details.
The quick habits that stop most attacks
- MFA on email and banking — it neutralises most phishing even when your password leaks.
- A password manager — it creates unique passwords and (in some apps) flags lookalike domains automatically. See our guide to choosing one.
- Go directly to the source — never click a link in a threat email; type the company’s official address.
- Treat unexpected attachments as dangerous, especially invoices and PDFs.
Frequently Asked Questions
What is the #1 defence against phishing?
Multi-factor authentication on your email and bank, plus a password manager that generates unique passwords. Even a successful phishing attempt then can’t get far.
How do I check if a link is safe without clicking?
Hover over it on desktop and read the destination domain in the status bar, or long-press on mobile to preview the URL. The visible link text can be anything — the destination is what matters.
Should I report phishing emails?
Yes. Use your email provider’s “Report phishing” button (it trains the spam filter for everyone), and report to the Anti-Phishing Working Group at reportphishing@apwg.org if the message targets a financial account.
Related Reads
- The Complete Home Cybersecurity Check: 24 Steps
- Router Security: 17 Settings That Matter in 2026
- How to Choose a Password Manager in 2026
- Best AI Chatbot in 2026 (for the AI-scam angle)
Update note (Aug 2026): Update note (Aug 2026): added the latest smishing and AI-voice scam patterns.