What Is Phishing?
Phishing is a type of social engineering attack where a cybercriminal impersonates a trusted entity — such as your bank, a government agency, a popular online service, or even a colleague — to manipulate you into taking a harmful action. That action might be clicking a malicious link, downloading an infected attachment, or entering your credentials on a fake website that looks identical to the real one. Phishing is responsible for the majority of data breaches worldwide, and attacks have become increasingly sophisticated and personalized over time.Common Types of Phishing Attacks
Email Phishing
The most prevalent form, email phishing involves mass-sent messages designed to look like legitimate communications from trusted brands like PayPal, Amazon, Microsoft, or your bank. These emails often create a sense of urgency — claiming your account has been suspended or that you need to verify a transaction immediately.SMS Phishing (Smishing)
Smishing attacks arrive as text messages on your phone, often appearing to come from delivery services, banks, or government agencies. A typical smishing message might claim that a package could not be delivered and ask you to click a link to reschedule — but that link leads to a fake site designed to steal your personal information. Because text messages feel more personal and immediate than email, smishing attacks often have higher click-through rates.Voice Phishing (Vishing)
Vishing involves a live phone call or a robocall from someone impersonating a bank fraud department, the IRS, tech support, or another authority. The caller may already know some of your personal information — gathered from data breaches or social media — making them sound highly credible. They will pressure you to provide verification details, install remote access software, or make an urgent payment.Red Flags to Watch For
- Mismatched sender addresses: The display name says “PayPal Support” but the actual email address is something like
support@paypa1-alerts.net. - Generic greetings: Legitimate services typically address you by your name. “Dear Customer” or “Dear User” is a red flag.
- Suspicious links: Hover over any link (without clicking) to preview the actual URL. If it does not match the organization’s official domain, do not click it.
- Unexpected attachments: Be wary of email attachments you were not expecting — especially
.zip,.exe,.docm, or.xlsmfiles, which can carry malware. - Poor grammar and spelling: Many phishing emails contain awkward phrasing, unusual capitalization, or spelling errors that give away their illegitimate origin.
- Requests for sensitive information: Reputable organizations will never ask for your password, full credit card number, or Social Security number via email.
How Trend Micro Protects You
Email Defender (included with Trend Micro Maximum Security and available as a standalone tool) scans your Gmail and Outlook inboxes in real time, flagging suspicious messages and quarantining known phishing emails before you even see them. It identifies deceptive sender addresses, malicious links embedded in the email body, and dangerous attachments — giving each email a clear risk rating so you can make informed decisions. Web Threat Protection in the Trend Micro browser extension checks every URL you visit against a continuously updated global database of known phishing and malicious websites. If you accidentally click a phishing link — in an email, a text message, or a social media post — Trend Micro blocks the page from loading and displays a clear warning. Fraud Buster is a free tool from Trend Micro that lets you forward suspicious text messages for immediate analysis, telling you within seconds whether the message is a scam.Frequently Asked Questions
What should I do if I clicked a phishing link?
What should I do if I clicked a phishing link?
Act quickly but calmly. First, do not enter any information on the page that opened. Close the tab or window immediately. Then:
- Disconnect from the internet temporarily to prevent any potential malware from communicating with attacker servers.
- Run a full system scan with Trend Micro to check for malware that may have been silently installed.
- Change your passwords for any accounts that may have been compromised — starting with your email and banking accounts. Use unique passwords for each.
- Enable two-factor authentication (2FA) on important accounts if you have not already done so.
- Monitor your financial accounts for the next few weeks for any unauthorized transactions.
- If you entered financial information, contact your bank immediately to freeze your card and report potential fraud.
Does Trend Micro block phishing emails?
Does Trend Micro block phishing emails?
Yes. Trend Micro’s Email Defender integrates directly with Gmail and Microsoft Outlook to scan incoming messages for phishing indicators in real time. It uses machine learning and Trend Micro’s global threat intelligence network — which analyzes billions of threats every day — to identify deceptive emails, malicious links, and dangerous attachments. Flagged emails are clearly marked with a risk badge, and high-risk messages are moved to a separate quarantine folder automatically. You can review quarantined items at any time and release any that were incorrectly flagged.
How do I report a phishing email?
How do I report a phishing email?
Reporting phishing emails helps protect the broader community. Here are the key ways to report them:
- To your email provider: In Gmail, click the three-dot menu on the email and select Report Phishing. In Outlook, use the Report Message button in the toolbar.
- To the impersonated organization: Forward the phishing email to the company’s official abuse or security email (e.g.,
phishing@paypal.comorabuse@amazon.com). Most major companies have a dedicated team to investigate and take down fraudulent sites. - To the Anti-Phishing Working Group (APWG): Forward the email to
reportphishing@apwg.org. The APWG is an international coalition that aggregates phishing reports and works to disrupt cybercrime operations. - To Trend Micro: If you are a Trend Micro user, you can submit suspicious URLs or emails through the Trend Micro Site Safety Center at
global.sitesafety.trendmicro.comto help improve threat detection for all users.