What is phishing?

Phishing is a form of internet fraud in which criminals pose as trustworthy organizations to steal personal information. This often happens by email, but also by text message (smishing) or phone (vishing). Phishing emails are designed to look as legitimate as possible, which means even experienced internet users can fall for them. In this article you learn how to recognize suspicious emails and how to protect yourself against this common form of cybercrime.

Why is phishing so dangerous?

Phishing is one of the most common and most successful forms of cybercrime. The consequences can be serious: identity theft, financial damage, access to your accounts, and even ransomware infections on your computer or network. What makes phishing extra dangerous is that it exploits human psychology (fear, urgency, curiosity) rather than just technical vulnerabilities.

Financial damage

If criminals get access to your bank details or credit card information, they can steal money directly. Recovering from this can take weeks and is not always fully possible.

Identity theft

With stolen personal information, criminals can open accounts in your name, take out loans, or carry out other fraudulent activities.

The 10-point phishing checklist

Use this checklist for every suspicious email. A single positive point is already a reason to be careful, and several are a clear warning sign.

1. Check the sender address

Don't just look at the display name, look at the actual email address. Phishers often use addresses that resemble real companies but are slightly different. For example: "support@faceb00k-security.com" instead of "support@facebook.com". Small changes such as swapped letters, extra characters, or different domains are red flags.

2. Watch for spelling and grammar mistakes

Professional organizations rarely send emails with spelling mistakes or odd sentence structures. Phishing emails are often written by non-native speakers or thrown together quickly, which results in errors. Be extra alert to unnatural Dutch that sounds like an automatic translation.

3. Analyze the greeting

Legitimate companies you are a customer of usually address you by name: "Dear John Smith". Phishing emails often use a generic greeting such as "Dear customer", "Dear user", or no greeting at all.

4. Be alert to urgency and threats

Phishing emails often create artificial urgency: "Your account will be blocked within 24 hours", "Respond immediately to avoid problems", "Final warning". Real companies give you plenty of time to respond and communicate through multiple channels about important matters.

Move your mouse over links (without clicking) to see where they lead. The URL shown should match the official website of the company. Phishers often use look-alike domains or long URLs that hide the real domain.

6. Distrust unexpected attachments

Never open attachments from unknown senders, especially not .exe, .zip, .scr, or Office documents with macros. Even a PDF can contain malicious code. If you aren't expecting an attachment, verify it through another channel first before you open it.

7. Check for HTTPS and certificates

If you do click a link, check whether the website uses HTTPS (the padlock in the address bar) and whether the certificate is valid. Note: HTTPS does not automatically mean a site is trustworthy; it only means the connection is encrypted.

8. Does the email ask for sensitive information?

Banks, government agencies and reputable companies never ask for passwords, PINs, credit card numbers, or BSN numbers (Dutch citizen service numbers) by email. Any email that asks for these is suspicious by definition.

9. Is the offer too good to be true?

Emails about lottery winnings for a lottery you never entered, inheritances from unknown relatives, or unbelievable discounts are almost always fraud. If something sounds too good to be true, it probably is.

10. Verify through another route

When in doubt, contact the organization yourself through their official website or phone number, not through the details in the suspicious email. Ask whether they sent the email.

Examples of phishing techniques

Phishers keep getting smarter. Here are some common techniques they use.

Bank phishing

An email that supposedly comes from your bank, saying suspicious activity has been detected. You have to verify your details "immediately" through a link that leads to a fake site. Real banks never ask for this by email.

Package phishing

A message from "PostNL" or "DHL" saying you missed a package and have to pay for redelivery. The link leads to a fake site that steals your payment details. These emails often arrive in periods when many people are ordering online.

CEO fraud

An email that appears to come from your manager or director, asking you to quickly make a payment or buy gift cards. The email address is subtly different or the message comes from a personal account.

The account warning

"Your Netflix/Spotify/Microsoft account has expired" or "Someone tried to log in to your account". The link leads to a login page that looks identical but steals your details.

What should you do with a suspicious email?

You have received a suspicious email. These are the steps to follow.

Don't click, don't open

Don't click links and don't open attachments. Even opening an image can confirm to the sender that your email address is active.

Mark it as spam or phishing

Most email programs have an option to report messages as phishing. This helps improve the filters and protects other users.

Delete the email

After reporting it, you can delete the email. Also empty your trash so you don't accidentally click a link in it later after all.

Warn others

If the phishing email appears to come from a company you are actually a customer of, consider informing that company. They can warn other customers.

What if you have already clicked?

If you have already clicked a link or entered information, take action right away.

Change your passwords

Immediately change the password of the account that may have been compromised. If you use the same password elsewhere, change it there as well.

Check your accounts

Check your bank accounts and credit cards for unauthorized transactions. Report suspicious activity to your bank right away.

Scan your computer

If you opened an attachment, run a full scan with your antivirus program. Consider getting a second opinion from an online scanner.

Report the incident

In the Netherlands you can report phishing to the Fraudehelpdesk (fraudehelpdesk.nl) and forward it to the company being impersonated. If you have suffered financial damage, file a report with the police.

Protecting yourself against phishing

Prevention is better than cure. Here are measures to protect yourself on a structural basis.

Use two-factor authentication

With two-factor authentication (2FA), your password alone is not enough for criminals. They also need access to your phone or authenticator app. Turn on 2FA for all your important accounts.

Keep your software up to date

Make sure your browser, operating system and antivirus program are always up to date. Updates often contain security patches against the latest threats.

Use a password manager

A password manager generates and remembers strong, unique passwords for all your accounts. This prevents a leaked password from giving access to other accounts.

Be critical

The most important protection is a healthy dose of skepticism. Don't blindly trust emails, even if they look professional. Take a moment to go through the checklist before you take action.

Conclusion

Phishing is a serious threat that can affect anyone, regardless of technical knowledge or experience. By learning to recognize the signs and applying the checklist in this article, you significantly reduce the chance of becoming a victim. Remember: real organizations never ask for sensitive information by email, don't create unnecessary urgency, and always have correct sender addresses. When in doubt: don't click, don't reply, and contact the organization yourself through official channels. Stay alert and protect your digital identity.

Frequently asked questions

Can a phishing email come from a known contact?

Yes. If the account of someone you know has been hacked, criminals can send phishing emails from that address. Be alert to unusual language, strange requests, or attachments you aren't expecting, even from known contacts.

No, logos are easy to copy. Phishers often use exact copies of official logos, house styles and email formats. The presence of a logo says nothing about whether an email is legitimate.

Change your passwords immediately, especially if you logged in somewhere. Check your accounts for suspicious activity, scan your computer with antivirus software, and report the incident. If you entered financial details, contact your bank.

How do I know whether a website is real?

Check the URL carefully for spelling mistakes or deviations. See whether HTTPS is used (the padlock). When in doubt, type the address into your browser manually instead of clicking a link. Use bookmarks for sites you visit regularly.

Looking for WordPress hosting? View our plans.