Lesson 3 of 7
Phishing
Unmask deceptive emails, fake websites, and social engineering tricks designed to steal your credentials.
Learn it
Have you ever received an urgent message saying you won a brand-new games console, or that your account will be deleted in ten minutes unless you click a link? That is called phishing!
Phishing is when scammers pretend to be a company or person you trust, like your school, a bank, or a gaming platform. They want you to click a dangerous link or type in your secret password.
Spotting phishing is like being a detective. Look out for spelling mistakes, strange sender email addresses, and messages that try to make you panic into acting without thinking.
Key terms
- Phishing
- A broad social engineering attack where fraudulent messages attempt to trick victims into revealing sensitive data.
- Spear Phishing
- A targeted phishing attack customized with personal information to deceive a specific individual or team.
- Smishing
- Phishing scams delivered directly through SMS text messages on mobile phones.
- Typosquatting
- Registering misspelled domains (e.g. netfllix.com) that resemble genuine sites to deceive visitors.
Dissecting a Suspicious Email
Inspect every section of an incoming message to uncover red flags before clicking anything.
- 1Check the Sender Address: Look beyond the display name to see the actual domain after the @ symbol (e.g. support@paypa1-security.co.uk).
- 2Gauge the Tone: Notice if the message creates manufactured panic, like 'Account suspended within 24 hours!'.
- 3Hover Over Hyperlinks: Hover your mouse over links without clicking to preview the destination URL in your browser status bar.
- 4Look for Generic Greetings: Watch out for vague greetings such as 'Dear Valued Customer' instead of your actual registered name.
- 5Report and Delete: Use your email provider's Report Phishing button and delete the message without opening any attachments.
Phishing Domain Detector
pythontrusted_domains = ['bankofcode.co.uk', 'schoolportal.org']
incoming_url = 'http://login.bankofc0de.co.uk/reset-pin'
# Extract domain
import urllib.parse
hostname = urllib.parse.urlparse(incoming_url).netloc
if hostname not in trusted_domains:
print(f'POTENTIAL PHISHING ALERT: Domain {hostname} is untrusted!')
else:
print('Domain matches trusted list.')This Python snippet extracts the domain name from an incoming web link and verifies it against an approved whitelist of trusted domains.
Sandbox lab
Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.
AI phishing simulator
Pick a difficulty. Harder lures are worth more XP per correct call.
Try it
Determine whether each message scenario is a Real communication or a Fake (Phishing) attempt.
An SMS from an unknown mobile number stating: 'Your parcel is held! Pay 2 pounds fee immediately at royalma1l-parcel-tracking.com or item will be destroyed.'
A password reset email received immediately after you pressed 'Forgot Password' on your gaming portal, from the official verified domain.
An email from 'IT Helpdesk' claiming you have won a 500 pound gift card, asking you to download a file named 'PrizeForm.exe'.
A notification in your school app dashboard reminding you that homework is due tomorrow morning.
Challenge
Create a mock phishing simulation scenario to train new staff members at a charity. Describe the sender, the lure, and the hidden clues.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/5 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
- Clue 4 locked — reveal it only if you get stuck.
- Clue 5 locked — reveal it only if you get stuck.
Each clue costs 4 XP (never below 18 XP). You'd earn 35 XP right now.
Extension: Explain what DMARC and SPF email records do to stop cyber attackers from spoofing company email domains.