We've given Refundee a new look, learn more.
What is Phishing? Types, Examples and How To Stay Safe
Published September 21, 2026.jpg)
Phishing is when a criminal impersonates a trusted sender through digital messages to steal information, deliver malware, or trick the victim into taking an action they would not otherwise undertake.
If you have received an unusual email, text, or call asking for money or details, then you are not alone; phishing is a common tactic used by fraudsters to trick victims.
In this article, we will cover what phishing is, how it works, common types, examples, and what to do if you have lost money.
What is Phishing?
Phishing is when an attacker impersonates a trusted sender, such as the bank, the police, or a financial service, and creates a pretext requiring urgent action. The attacker would direct the victim to a fake login page, malicious attachment, or a direct request for information or payment.
It works because it touches on psychological factors within social engineering that criminals use to exploit victims.
Phishing is particularly common within fraud, where, according to UK Finance, £1.2 billion was lost to fraud in 2025, with a large factor of this coming from phishing tactics.
Types of Phishing Attacks
Email Phishing
- One of the most common and traditional phishing tactics used by fraudsters is email phishing, where a fraudulent email impersonating the bank, the police, or service provider contains a malicious link or payment instructions.
Spear Phishing
- A more targeted version of phishing aimed at attacking a specific individual using personal details to appear more convincing.
Smishing (SMS Phishing)
- Malicious links or urgent requests sent by text, often impersonating delivery services or banks.
Vishing (Voice Phishing)
- Phone calls, usually impersonating the bank or the police, using a spoofed caller ID. Particularly common within impersonation and scam accounts.
Quishing (QR Code Phishing)
- Malicious QR codes that direct to fake login pages or malicious links.
Clone Phishing
- A nearly identical copy of a previously received legitimate email, usually swapping links or payment information.
How to Spot a Phishing Email
If you have ever received an email that doesn’t look right, you are not alone, and it is probably a phishing email.
Here are some checks you can do to spot one:
- Sender address that is close, but does not match the domain
- Generic greetings such as ‘Dear customer’ rather than your name
- Urgent or threatening language pushing for immediate action
- Links that don’t match the destination when you hover over them
- Unexpected attachments, especially with unusual file types
- Requests for passwords, pins, or one-time codes - legitimate organisations would never ask for these
- Poor spelling, grammar, or communication that does not match previous emails
Phishing Scam Examples
Phishing is a common element in many fraud cases; whilst it may not always constitute the entire scam, it often plays a significant role in the overall attack.
Here are some examples:
- Fraudsters can impersonate your bank in multiple ways; they may claim that your account has been compromised by calling you and sending texts that are spoofed to appear as genuine bank messages. Most commonly, this leads to a safe account scam.
Delivery scam phishing
- A fake delivery request from Royal Mail or Evri that links to a ‘redelivery fee’ where card details are stolen and used for further fraud.
- A fraudulent invoice sent through a spoofed email that directs you to pay a different account.
- A fake tax rebate or penalty notice that urges you to pay a fee or provide personal details.
How to Protect Yourself From Phishing
There are steps you can take to protect yourself from phishing attacks and follow up fraudulent attacks:
- Verify the senders email address, not just the name
- Never click links in unsolicited messages, always go to the verified webpage
- Never share passwords, pins, or one-time passcodes with anyone
- Enable two-factor authentication, ideally through the App
- Hover over links before clicking on them
- Report suspicious emails to your bank/ IT team
- Report it to Report Fraud (previously Action Fraud)
What To Do If You’ve Been Targeted
If you have already been targeted by a phishing attack, then there are steps you can take to secure your money, account and details.
- Stop all contact with the scammer immediately
- Do not click on any further links or provide any further information
- Change any compromised passwords immediately, starting with your email and banking
- Report it to your bank if there was one involved
- Report it to Report Fraud
- Gather and preserve evidence
- Assess recovery options yourself for free, or through an FCA-regulated specialist Claims Management Company like Refundee
Can You Get Your Money Back From a Phishing Scam?
Recovery depends on what happened and if you used a UK bank account in the process. If you did use a UK bank account, then you may have options to recover.
New fraud reimbursement rules, such as the PSR’s Mandatory Reimbursement Model, have introduced stronger protections for fraud victims.
Key parts of the Mandatory Reimbursement rules:
- You made the payment after the 7th of October 2024
- Your payment was sent to another UK bank account
- Maximum refund of £85,000 per claim
- Banks can deduct an excess of £100 (doesn’t apply to vulnerable customers)
- Victims must report the scam within 13 months of the last payment
- Banks cannot delay the claim indefinitely
It is a free process to claim yourself from your bank and the Financial Ombudsman. We have written a guide here on how you can do this.
Alternatively, you can start your claim with Refundee for a free eligibility assessment.
We are regulated and authorised by the Financial Conduct Authority and we have recovered £140 million for our clients so far.
We work on a no-win, no-fee basis, so you only pay us if we are successful. You can read more about our fees on our website.
Conclusion
Phishing has always been popular with fraudsters, and it is a common way they can trick victims. It is important to know how to spot phishing attempts and, crucially, how to recover your funds if you have lost money.
If you have already been targeted and lost money, then you do have options for recovery. It is a free process to claim this back from your bank, or you can speak with Refundee to assess your options for recovery.
More about Refundee
Here are the technical bits:
Refundee Ltd is a claims management company authorised and regulated by the Financial Conduct Authority in respect of regulated claims management activity FRN: 937096.
Registered with the Information Commissioner's Office; registration number: A8986071.
Registered office address: Refundee, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE.
Registered as a company in England & Wales; number: 12855931.
Frequently asked questions
Phishing is when a criminal impersonates a trusted sender through digital messages to steal information, deliver malware, or trick the victim into taking an action they would not otherwise take.
One of the most common and traditional phishing tactics used by fraudsters is email phishing, where a fraudulent email impersonates the bank, the police, or a service provider and contains a malicious link or payment instructions.
Phishing is more general, and fraudsters target a large number of people, hoping to catch unsuspecting individuals out, whereas spear phishing targets an individual using their specific personal details with the aim of tricking the individual into sharing information, or sending money.
Do not click on any more links, secure your email and banking passwords, report the email and notify your bank, and look into recovery options if you have lost money.
Phishing has always been popular with scammers, however the tactics they use are becoming harder to spot. Learn what Phishing is, how to spot it, and how to keep your details and money safe from an attack.

.jpg)

