What is phishing?
Kahu team·Updated 2 Oct 2026·5 min read
Phishing is a scam where someone pretends to be a trusted organisation or person to trick you into clicking a link, opening a file, sharing a password or paying money. It arrives by email, text message, phone call or social media. The best defence is to slow down and check through a channel you already trust.
How phishing works
A phishing message copies someone you would normally trust, such as your bank, a courier, a supplier, Microsoft, Google or even your own boss. It creates a reason to act quickly: an unpaid invoice, a locked account, a parcel that cannot be delivered. The link leads to a fake login page or a harmful download, and whatever you type goes straight to the scammer.
Common types
- Email phishing: fake invoices, delivery notices and password resets.
- Smishing: the same tricks by text message.
- Vishing: phone calls pretending to be a bank or a support team.
- Business email compromise: a message that seems to come from a supplier or manager asking to change bank details or make an urgent payment.
Warning signs
- Urgency or threats: act now or lose access.
- A sender address or link that is close to the real one, but not quite.
- A request for a password, a code or a payment.
- Unexpected attachments or shared files.
- A change to bank details, especially by email.
If you clicked
- 1Change the passwordChange it on the real site, and anywhere else you used the same password.
- 2Turn on two-factor authenticationSo a stolen password alone is not enough to get in.
- 3Call your bankIf you shared card or bank details or made a payment, call immediately.
- 4Report itTell your IT contact or email provider, and report it to your country’s cyber security agency.
Frequently asked questions
Can I get hacked just by opening a phishing email?
Opening it is rarely enough on its own. The risk comes from clicking links, opening attachments or replying with information.
How do I check if an email is real?
Do not use anything in the message. Log in through the website or app you normally use, or call the organisation on a number you already have.
How do I protect my team?
Turn on two-factor authentication everywhere, agree that bank detail changes are always confirmed by phone, and make it easy and blame-free to report a suspicious message.
