# Phishing

A deceptive attempt, usually by email or message, to trick someone into revealing sensitive information or installing malware.

**Phishing[↗](/phishing)** is a deceptive attempt, typically delivered by email, text message, or a fake website, to trick someone into revealing sensitive information, passwords, card numbers, one-time codes, or into installing malware[↗](/malware), usually by impersonating a trusted brand, colleague, or service. It remains one of the most common ways attackers gain initial access to accounts and networks.

Phishing messages often create a false sense of urgency ("your account will be suspended"), impersonate a recognizable brand or person, or contain a link to a lookalike website designed to steal your login credentials the moment you type them in. Checking the actual sender address and link destination carefully, never entering credentials after clicking a link from an unsolicited message, and using multi-factor authentication[↗](/authentication) as a backstop are the best defenses.
