All terms
Glossary

Phishing

Fake emails, texts or websites that imitate a well-known brand to steal login or payment details.

DDennis BöllingFounder · QAD SoftUpdated 2026-07-26
Definition

What does Phishing mean?

Phishing refers to attempts to obtain sensitive data such as login credentials, credit card numbers or TANs via fake messages (email, SMS – then also called “smishing”) or rebuilt websites. Typical is the imitation of well-known senders – banks, parcel services, payment providers or well-known online shops – including a copied logo and layout.

With fake shops, phishing often overlaps with the actual fraud: after an order, fake “shipping” or “payment problem” emails follow, with links to rebuilt login or payment pages designed to skim bank details as well – beyond the original goods fraud.

The most important thing to check is always the address a link actually leads to. Fraudsters work with a handful of recurring tricks: swapped or substituted characters in the name (a digit one instead of a lowercase L, for instance), appended additions such as “-security” or “-service”, and above all the subdomain trick. In an address of the form “well-known-brand.com.login-check.xyz”, the actual domain is the trailing part – “login-check.xyz” – and everything before it is freely chosen text. What counts is always what stands immediately before the first single slash.

Another trick uses letters from other alphabets that look confusingly similar to Latin characters. Such addresses are visually almost indistinguishable from the real thing. Modern browsers display them in a decoded form beginning with “xn--” – if you see that in the address bar, leave the page immediately.

Further signs of a phishing message are: a sender address that is only similar to, but not identical with, the real domain; time pressure (“your account will be blocked”, “today only”); an impersonal salutation even though the supposed sender knows your name; and attachments you were not expecting. And the most important principle of all: no bank, no payment service and no shop will ever ask you by email to enter a password, PIN or TAN.

An everyday example: two days after an order, an email arrives bearing a parcel service’s logo, subject “customs fee of €2.99 outstanding”, with a link to a payment page. The sum is deliberately small so that nobody thinks twice. On the page, however, not only the €2.99 is requested but full card details including the security code. The amount is the bait – the card details are the goal.

The channel of the message has become secondary. Alongside classic emails there are texts about supposed parcel notifications, calls from alleged bank staff and QR codes on stickers that lead to forged payment pages. The pattern is always the same: a familiar brand, a plausible pretext and an action that must happen immediately. Anyone who knows the pretext recognises the scheme regardless of the channel.

Attachments deserve particular caution. Invoices or reminders for orders you never placed frequently carry malware rather than a document. Do not open such files “just to see what it is about” – the order number in the subject line is invented and exists precisely to trigger that curiosity.

An effective and often underrated protection is a password manager. It fills in credentials only on the domain they were saved for. If you land on a rebuilt page, the field simply stays empty – and that absence is a clearer warning signal than the human eye could ever be when reading an address.

Equally important: confirmation codes for two-factor authentication must never be passed on to third parties – not even to supposed staff on the phone who want to “unlock the process”. Such a code is the last key to your account; anyone asking for it already has the password and only needs you.

Reporting is worthwhile even when nothing happened. Consumer protection bodies collect phishing messages, and the imitated companies usually operate their own reporting addresses through which forged pages are taken down faster. Forwarding an email costs you a minute and shortens the life of the campaign for everyone else.

Anyone who has already clicked and entered data should act in this order: have the affected card or account blocked by the bank immediately, then change the passwords of every service where the same password was used, and enable two-factor authentication wherever possible. Afterwards file a police report and forward the message to the imitated company and to a consumer protection body – and when in doubt never log in via a link in an email, but always via the known address you type in yourself.

Unsure about a specific shop?

Our fake-shop check evaluates over 30 trust features – free and in seconds.

Check a shop for free