What is Phishing? Types, Examples and How To Stay Safe

Published September 21, 2026
0 min read
Stuart McFadden
Director
Share

Phishing is when a criminal impersonates a trusted sender through digital messages to steal information, deliver malware, or trick the victim into taking an action they would not otherwise undertake.

If you have received an unusual email, text, or call asking for money or details, then you are not alone; phishing is a common tactic used by fraudsters to trick victims.

In this article, we will cover what phishing is, how it works, common types, examples, and what to do if you have lost money.

What is Phishing?

Phishing is when an attacker impersonates a trusted sender, such as the bank, the police, or a financial service, and creates a pretext requiring urgent action. The attacker would direct the victim to a fake login page, malicious attachment, or a direct request for information or payment.

It works because it touches on psychological factors within social engineering that criminals use to exploit victims.

Phishing is particularly common within fraud, where, according to UK Finance, £1.2 billion was lost to fraud in 2025, with a large factor of this coming from phishing tactics. 

Types of Phishing Attacks

Email Phishing  

  • One of the most common and traditional phishing tactics used by fraudsters is email phishing, where a fraudulent email impersonating the bank, the police, or service provider contains a malicious link or payment instructions.  

Spear Phishing  

  • A more targeted version of phishing aimed at attacking a specific individual using personal details to appear more convincing.  

Smishing (SMS Phishing)  

  • Malicious links or urgent requests sent by text, often impersonating delivery services or banks.  

Vishing (Voice Phishing)  

  • Phone calls, usually impersonating the bank or the police, using a spoofed caller ID. Particularly common within impersonation and scam accounts.  

Quishing (QR Code Phishing)  

  • Malicious QR codes that direct to fake login pages or malicious links.  

Clone Phishing  

  • A nearly identical copy of a previously received legitimate email, usually swapping links or payment information.

How to Spot a Phishing Email

If you have ever received an email that doesn’t look right, you are not alone, and it is probably a phishing email. 

Here are some checks you can do to spot one:

  • Sender address that is close, but does not match the domain  
  • Generic greetings such as ‘Dear customer’ rather than your name  
  • Urgent or threatening language pushing for immediate action  
  • Links that don’t match the destination when you hover over them  
  • Unexpected attachments, especially with unusual file types  
  • Requests for passwords, pins, or one-time codes - legitimate organisations would never ask for these  
  • Poor spelling, grammar, or communication that does not match previous emails

Phishing Scam Examples

Phishing is a common element in many fraud cases; whilst it may not always constitute the entire scam, it often plays a significant role in the overall attack.

Here are some examples:

Bank impersonation phishing

  • Fraudsters can impersonate your bank in multiple ways; they may claim that your account has been compromised by calling you and sending texts that are spoofed to appear as genuine bank messages. Most commonly, this leads to a safe account scam.  

Delivery scam phishing

  • A fake delivery request from Royal Mail or Evri that links to a ‘redelivery fee’ where card details are stolen and used for further fraud. 

Invoice phishing

  • A fraudulent invoice sent through a spoofed email that directs you to pay a different account. 

HMRC/Government phishing

  • A fake tax rebate or penalty notice that urges you to pay a fee or provide personal details.  

How to Protect Yourself From Phishing

There are steps you can take to protect yourself from phishing attacks and follow up fraudulent attacks:

  • Verify the senders email address, not just the name
  • Never click links in unsolicited messages, always go to the verified webpage
  • Never share passwords, pins, or one-time passcodes with anyone
  • Enable two-factor authentication, ideally through the App
  • Hover over links before clicking on them
  • Report suspicious emails to your bank/ IT team
  • Report it to Report Fraud (previously Action Fraud)

What To Do If You’ve Been Targeted

If you have already been targeted by a phishing attack, then there are steps you can take to secure your money, account and details.

  1. Stop all contact with the scammer immediately 
  2. Do not click on any further links or provide any further information
  3. Change any compromised passwords immediately, starting with your email and banking
  4. Report it to your bank if there was one involved
  5. Report it to Report Fraud
  6. Gather and preserve evidence
  7. Assess recovery options yourself for free, or through an FCA-regulated specialist Claims Management Company like Refundee

Can You Get Your Money Back From a Phishing Scam?

Recovery depends on what happened and if you used a UK bank account in the process. If you did use a UK bank account, then you may have options to recover.

New fraud reimbursement rules, such as the PSR’s Mandatory Reimbursement Model, have introduced stronger protections for fraud victims.

Key parts of the Mandatory Reimbursement rules:

  • You made the payment after the 7th of October 2024
  • Your payment was sent to another UK bank account
  • Maximum refund of £85,000 per claim
  • Banks can deduct an excess of £100 (doesn’t apply to vulnerable customers)
  • Victims must report the scam within 13 months of the last payment
  • Banks cannot delay the claim indefinitely

It is a free process to claim yourself from your bank and the Financial Ombudsman. We have written a guide here on how you can do this.

Alternatively, you can start your claim with Refundee for a free eligibility assessment.

We are regulated and authorised by the Financial Conduct Authority and we have recovered £140 million for our clients so far.

We work on a no-win, no-fee basis, so you only pay us if we are successful. You can read more about our fees on our website.

Conclusion

Phishing has always been popular with fraudsters, and it is a common way they can trick victims. It is important to know how to spot phishing attempts and, crucially, how to recover your funds if you have lost money.

If you have already been targeted and lost money, then you do have options for recovery. It is a free process to claim this back from your bank, or you can speak with Refundee to assess your options for recovery.

Learn more 

More about Refundee 

Here are the technical bits: 

Refundee Ltd is a claims management company authorised and regulated by the Financial Conduct Authority in respect of regulated claims management activity FRN: 937096. 

Registered with the Information Commissioner's Office; registration number: A8986071. 

Registered office address: Refundee, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE. 

Registered as a company in England & Wales; number: 12855931.

Frequently asked questions

What is phishing?
What is one example of phishing?
What’s the difference between phishing and spear phishing?
What should I do if I clicked a phishing link?
Stuart McFadden
Director
Share
Summary

Phishing has always been popular with scammers, however the tactics they use are becoming harder to spot. Learn what Phishing is, how to spot it, and how to keep your details and money safe from an attack.

New here? We're Refundee.
We help victims of fraud get their money back from their bank. FCA regulated. No win, no fee.
It's free to find out if we can help

We've already helped over 
{{total-customers-text}}
 people recover 
{{money-recovered-text}}
 and we're ready to help you too.