Human Risk Management Institute

What is Phishing and How to Avoid It

Written by Mira Sibera | 24 Jan 2026

Phishing is a cyber threat that can harm anyone. Learn how to identify and avoid these traps to protect yourself online.

Understanding Phishing: A Lurking Cyber Threat

Phishing is a form of cybercrime that is often used to steal personal information, such as passwords, credit card numbers, and other sensitive data. Attackers usually pose as trusted entities and try to lure victims into revealing their personal information.

Phishing threats can come in various forms, such as emails, text messages, or even phone calls. The goal is to make victims believe that they are dealing with legitimate companies or individuals.

Read: Doxxing: What Is It and How to Avoid It?

How Phishing Works: Techniques and Tactics Used

Phishing works by exploiting social engineering techniques that make victims feel compelled to provide their information. One commonly used technique is phishing emails, where attackers send emails that appear to come from a trusted source, such as a bank or well-known company.

Other techniques include spear phishing, where attacks are targeted at specific individuals, and whaling, which targets company executives. Attackers may also use fake websites that mimic the original site to trick victims into entering their information.

Characteristics of Phishing Emails and Messages to Watch Out For

Phishing emails or messages often have several recognisable signs. One of them is an urgent request to provide personal information or take immediate action.

Other signs include the use of formal but unusual language, a suspicious sender's email address, and suspicious links or attachments. Always be cautious and verify the source if you receive a suspicious email or message.

Steps to Protect Yourself from Phishing Attacks

To protect yourself from phishing attacks, it is important to always be vigilant and sceptical of emails or messages that request personal information. Never click on links or download attachments from unknown sources.

SiberMate has a phishing simulation feature that can help train employees to be more sensitive to phishing email attacks. Phishing simulations in SiberMate are automated on a regular basis and integrated with e-learning cyber security awareness training features.

Read: 7 Effective Steps to Protect Company Data from Phishing and Malware

What to Do If You Become a Victim of Phishing

If you believe you have been a victim of phishing, immediately change the passwords of any accounts that may have been compromised and contact the relevant authorities or service providers to report the incident.

Always monitor your account activity to detect any signs of suspicious activity. Keeping your security software up to date can also help protect you from cyber threats.