What it is
Phishing is a message (usually an email) that imitates a trusted sender to steal credentials or data, or to get malware installed. With AI the text is flawless in any language, personalised with public information about the victim and produced at scale.
How it works
- 1The attacker gathers public information about you or your company.
- 2They write a believable email with a reason for urgency and a link to a fake login page.
- 3The credentials you enter reach the attacker, who uses them at once, sometimes bypassing codes with pages that relay them in real time.
- 4With the stolen account they try to hit your contacts and colleagues.
How to spot it
- Urgency or threats (“account suspended”, “payment pending”)
- Sender or domain slightly different from the real one
- A link whose real address does not match the one shown
- Unusual requests for passwords, codes or payments, or unexpected attachments
- Note: the absence of mistakes is no longer a sign of safety
How to defend
- Do not click: open the site by typing the address or from the official app
- Use passkeys or security keys, more phishing-resistant than SMS codes
- Use a password manager: it fills only on the correct domain
- Verify unusual requests on another channel
- In companies: email filters, DMARC, simulations and regular training
If you think you have been hit
- Change the password from a trusted device and sign out other sessions
- Enable (or restore) multi-factor authentication
- Tell IT or your bank if you entered payment details
- Report the message and warn contacts who may receive messages in your name
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026