What is Email Phishing?

Phishing emails are carefully crafted messages that impersonate trusted organisations — your bank, the income tax department, IRCTC, Amazon, or even the CEO of your company — to trick you into clicking a malicious link or giving up credentials.

The Anatomy of a Phishing Email

  • Sender: Looks official but the actual email domain is different (e.g., support@sbi-india-verify.com instead of sbi.co.in)
  • Subject: Creates urgency — "Your account will be closed," "Immediate action required," "You've won ₹50,000"
  • Link: Hover over links to see the real URL — they never match the displayed text
  • Attachment: .exe, .zip, or even .pdf files that install malware
One-second check: Before clicking any link in an email, hover over it (on desktop) or long-press it (on mobile) to see the actual URL. If it looks suspicious, don't click.

Advanced Phishing Tactics

Spear Phishing

Targeted attacks using your name, company, and personal details scraped from social media. Far more convincing than generic phishing.

Whaling

Targeting senior executives — scammers impersonate the CEO and ask finance teams to urgently wire money.

Protecting Yourself

  • Never enter credentials on a page you reached via an email link — go directly to the site
  • Use Gmail or Outlook — they have strong phishing filters
  • Enable 2FA so stolen passwords alone aren't enough
  • Report phishing to Google (Gmail → three dots → Report phishing) to protect others
If you clicked a suspicious link: Disconnect from the internet, run a virus scan, change the passwords of any accounts you accessed since clicking, and inform your IT department if it's a work device.