Cyber Defence
Cyber Security

What is Phishing? Types, Examples & How to Prevent It (2026)

What is phishing? A plain-English 2026 guide to phishing attacks, their types, real India examples like UPI and bank OTP scams, warning signs, and how to prevent them.

What is Phishing? Types, Examples & How to Prevent It (2026)
Amit Kumar
Amit KumarEthical Hacker & Founder
9 min read

Short answer: Phishing is a cyber attack where criminals impersonate a trusted person or brand, through email, SMS, calls or fake websites, to trick you into revealing passwords, OTPs, card details or money. It relies on urgency and deception rather than hacking your device directly.

Phishing is the single most common way people in India lose money and data online. You do not need to be careless, modern phishing messages look almost identical to genuine bank, UPI, courier and government communications. Understanding how phishing works is the first real defence.

How Phishing Actually Works

A phishing attack usually follows a simple pattern. The attacker sends a message that looks legitimate, creates a sense of fear or urgency ("your account will be blocked", "your KYC has expired", "you have won a reward"), and pushes you to act fast, before you think. The message contains a link to a fake website or a phone number that connects to the fraudster. Once you enter your credentials or OTP, or approve a UPI collect request, the attacker uses those details instantly.

Phishing works because it targets human psychology, not just technology. This is called social engineering. The attacker exploits trust, fear, curiosity and greed. That is why even technically skilled people fall for well-crafted phishing.

Why Phishing Is So Effective in 2026

Phishing keeps working because attackers have become far more convincing. Several trends make it more dangerous than ever:

  • AI-generated messages: Generative AI now writes grammatically perfect, personalised phishing emails and even deepfake voice calls, removing the old tell-tale spelling mistakes.
  • Brand impersonation: Fake pages copy the exact logos, fonts, colours and layout of banks, wallets and government portals, so they look identical to the real thing.
  • Multi-channel attacks: A single scam may combine an SMS, a follow-up call and an email to build false credibility.
  • Real-time OTP theft: Attackers relay your OTP the instant you enter it on a fake page, defeating one-time passwords if you are not careful.
  • Trusted platforms: Links are hidden inside Google Docs, shortened URLs, QR codes (called quishing) and even legitimate cloud services to bypass filters.

The lesson is simple: you can no longer judge a message as safe just because it "looks professional". You must verify the source through an independent channel.

Types of Phishing Attacks

Phishing has evolved into many specialised forms. The table below summarises the main types you should recognise.

TypeChannelHow It Works
Email phishingEmailMass fake emails from "banks", "couriers" or "IT teams" with malicious links or attachments.
Spear phishingEmailTargeted attack on a specific person using their name, role and real details to seem genuine.
WhalingEmailSpear phishing aimed at CEOs, directors and finance heads to authorise large payments.
SmishingSMS / WhatsAppFake SMS about KYC, electricity bill, parcel delivery or refund with a malicious link.
VishingPhone callVoice calls pretending to be bank, RBI, TRAI or police to extract OTP or remote access.
Clone phishingEmailA copy of a real email you received, with links swapped for malicious ones.
Angler phishingSocial mediaFake customer-support handles that reply to your complaint and steal credentials.

Real Phishing Examples in India

Indian users are targeted with locally tailored scams every day. Common examples include:

  • UPI collect-request scam: A fraudster sends a UPI "request money" pretending it is a payment TO you. When you enter your PIN to "receive" money, you actually send it.
  • Bank OTP / KYC scam: An SMS or call warns that your account or PAN-Aadhaar KYC will be blocked. You are asked to click a link or share the OTP, which lets the attacker drain your account.
  • Electricity bill scam: "Your power will be disconnected tonight, call this number." The number connects to a fraudster who installs remote-access apps.
  • Courier / parcel scam: A fake India Post or FedEx message says your parcel is held for a small customs fee, harvesting card details.
  • Job and loan scams: Fake offers ask for a registration fee or personal documents.

Red Flags: How to Spot a Phishing Message

  • Urgency and threats ("act within 2 hours or account blocked").
  • Requests for OTP, PIN, password, CVV or full card number, no genuine bank ever asks these.
  • Slightly wrong sender addresses or URLs, for example hdfc-bank-verify.com instead of the real domain.
  • Generic greetings like "Dear Customer" and spelling or grammar mistakes.
  • Links that do not match the displayed text (hover to check before clicking).
  • Unexpected attachments, especially .zip, .exe or macro-enabled Office files.
  • Offers that are too good to be true, lottery, cashback, or free gifts.

How to Prevent Phishing Attacks

You can defeat almost all phishing with a few strong habits:

  • Never share OTP, PIN or password with anyone, over any channel. Full stop.
  • Do not click links in unexpected messages. Instead, open the official app or type the website address yourself.
  • Enable multi-factor authentication (MFA) on email, banking and social accounts, so a stolen password alone is not enough.
  • Verify the sender independently. Call the bank on the number printed on your card, not the number in the message.
  • Remember UPI PIN is only for sending money, never for receiving. If someone asks you to enter your PIN to "get" money, it is a scam.
  • Keep your OS, browser and apps updated and use a reputable security tool that warns about known phishing sites.
  • Slow down. Urgency is the attacker's weapon, verifying for two minutes defeats it.

Organisations should add technical controls too: email filtering, SPF/DKIM/DMARC records, employee awareness training and simulated phishing tests. Phishing is closely linked to other threats, a single successful phishing click is one of the most common ways malware and ransomware get into a network.

Extra protection for businesses

For companies, phishing is the leading cause of data breaches, so defence must be organisation-wide:

  • Deploy DMARC, SPF and DKIM so attackers cannot spoof your official domain.
  • Run regular phishing simulations to measure and improve staff awareness.
  • Enforce MFA and least-privilege access so one stolen login cannot compromise everything.
  • Establish a clear reporting channel, employees should know exactly whom to alert when they receive a suspicious message.
  • Verify payment changes by phone using known contacts, defeating business email compromise (BEC) and whaling scams that redirect invoices.

Phishing vs a legitimate message

SignalLegitimate messagePhishing message
Sender addressExact official domainLook-alike or misspelled domain
ToneInformative, no pressureUrgent threats and deadlines
RequestsNever asks for OTP/PINAsks for OTP, PIN, password or payment
LinksPoint to the real domainRedirect to fake or shortened URLs
PersonalisationUses your correct account detailsGeneric "Dear Customer" greeting

How to Verify a Suspicious Message Safely

When something feels off, use this quick verification routine before you act:

  • Pause. Genuine institutions give you time; scammers manufacture urgency.
  • Check the source independently. Do not use the number, link or email in the message. Instead open your banking app, or dial the helpline printed on your card or the official website.
  • Inspect the URL. Look for the exact official domain and a padlock, but remember a padlock alone does not prove a site is genuine.
  • Never enter credentials from a link. Navigate to the site yourself by typing the address.
  • Ask, when unsure. Confirm with your bank, employer or the real person through a known channel before sending money or data.

These two minutes of verification defeat the vast majority of phishing attempts, no matter how convincing they look.

What To Do If You Have Been Phished

  • If money was debited, call the cyber-crime helpline 1930 immediately, ideally within the "golden hour", and report at cybercrime.gov.in. See our full guide on how to report cyber crime in India.
  • Change passwords of the affected and linked accounts from a clean device.
  • Inform your bank to freeze the card or account.
  • Enable MFA everywhere and scan your device for malware.

Learning to recognise and stop phishing is a core skill in cyber security. At Cyber Defence in Hisar, Haryana, we train students and professionals to detect social engineering, run phishing simulations and defend organisations, exactly the skills employers now demand. If you want to understand the bigger picture first, read what is cyber security.

FAQ

What is phishing in simple words?

Phishing is a scam where an attacker pretends to be a trusted brand or person to trick you into giving away sensitive information like passwords, OTPs or card details, or into sending money.

What is the difference between phishing and spear phishing?

Phishing is usually a mass, generic attack sent to many people. Spear phishing is targeted at a specific individual using personal details to appear far more convincing.

Can phishing happen through SMS or phone calls?

Yes. Phishing over SMS or WhatsApp is called smishing, and over voice calls it is called vishing. Both are extremely common in India, especially fake KYC, bank and electricity-bill messages.

What should I do if I clicked a phishing link?

Do not enter any details. Disconnect from the internet, change passwords from a clean device, enable MFA, scan for malware, and if money was lost call 1930 and report at cybercrime.gov.in.

Does a bank ever ask for OTP or PIN?

No. No legitimate bank, wallet or government body will ever ask for your OTP, PIN, CVV or password. Anyone who does is a fraudster.

How can I learn to protect against phishing professionally?

You can take a structured cyber security or ethical hacking course that covers social engineering, phishing simulation and defence. Cyber Defence in Hisar offers both, taught by CEH-certified trainers.

Want to master phishing defence and build a cyber security career? Explore our courses, our cyber security course (approx. 3-4 months, around Rs.15,000) and ethical hacking course (around 6 months, approx. Rs.60,000), led by founder Amit Kumar (CEH, CRTA). Cyber Defence is an ISO-certified, GeM-registered institute in Hisar, Haryana. Call +91-75175-72000 to enrol.

Talk to a Cyber Defence Expert

Get a free consultation on cybersecurity, training and certifications. Our team responds within 10 minutes during business hours.