1. What phishing is, explained simply
Phishing is a scam attempt where someone poses as a company, a bank or an official body to get you to hand over your personal details, your passwords or your card numbers. It usually arrives as a message (email, SMS or WhatsApp) that includes a link: when you click it, it takes you to a website that mimics the real one, where you're asked to "log in" or "verify your details". In reality, everything you type there goes straight to whoever set up the scam.
The name comes from "fishing": the same message is sent to thousands of people at once, knowing some will "bite". You don't need to be a computer expert to fall for it, because these messages are increasingly well made and play on urgency and fear.
2. Typical signs of a fraudulent SMS or email
Although every scam is different, almost all of them share a few traits that, once you learn to spot them, will put you on alert right away:
- A sense of urgency: "your account will be blocked in 24 hours", "package held, act now" or "suspicious activity detected". They want you to act fast and without thinking.
- Spelling mistakes or odd wording: missing accents, awkwardly translated sentences, or a tone that doesn't match how that company usually writes to you.
- A sender that doesn't match: the name shown may look like your bank's, but if you check the full email address or the SMS number, it has nothing to do with that company's official channels.
- Unexpected prizes or packages: you've won a giveaway you never entered, or you're notified of a delivery you don't remember ordering.
- Requests for details that company never asks for that way: no bank will ever ask for your full password or your card's security code by SMS or email.
3. How to check a link without clicking it
You don't need to click a link to know if it's suspicious. On your phone, press and hold your finger on the link for a few seconds without releasing: you'll see the destination URL appear without opening it. On a computer, just hover your mouse over the link (without clicking) and look at the address shown in the bottom corner of the window.
Once you see the full URL, look at the main domain, meaning the name right before the first slash ("/"). For example, in www.correos.es/seguimiento, the real domain is "correos.es". If instead you see something like "correos-envios-verificacion.com" or a combination of letters and numbers you don't recognize, it's a fake website that's only copying the design of the original.
4. Why you shouldn't trust an SMS about packages or bank issues
Two of the most used hooks are the "package pending delivery" notice and the "problem with your bank account" one. They work because almost everyone has some order on the way or an account at a bank, so the message fits anyone's life.
The golden rule is simple: never click the link in one of these messages without checking it first through another channel you control yourself. If you're worried about a supposed package, go directly to the courier's official website or app by typing the address yourself, or check the tracking number you were given when you bought it. If you're worried about your bank, call the number you have saved for your branch or open the official app from the icon you already have installed, never from the link in the message.
5. What to do if you've already clicked the link or given your details
If you've clicked a suspicious link, or worse, entered your username and password on a website that now raises doubts, don't freeze up: act as soon as possible with these steps.
- Change the password immediately from a trusted device, both on the affected service and on any other one where you use that same password.
- If you gave banking details (card number, bank app code), notify your bank immediately so they can block the card or watch for unusual activity. The sooner you do it, the lower the risk.
- Turn on two-step verification on the affected account and, if you can, on the rest of your important accounts, so a leaked password isn't enough to get in.
- Check your active devices and sessions on the services you use, in case there's an access you don't recognize.
6. How to report a phishing attempt
Reporting these messages helps get them blocked and stops other people from falling into the same trap. If the phishing arrived by email, most email providers have a "mark as phishing" or "report spam" option directly in the message's menu. If it arrived by SMS, in Spain you can forward it for free to 7726, a number set up so mobile carriers can identify and shut down these scam campaigns.
If you've also suffered a financial loss or had your data stolen, it's a good idea to file a report with the Policía Nacional or the Guardia Civil, who have units specialized in cybercrime, and also notify Spain's National Cybersecurity Institute (INCIBE) through its helpline.