How to avoid phishing
Phishing is the art of tricking you into handing over your own credentials - passwords, card numbers, bank logins - by impersonating someone you trust. What started as clumsy “confirm your account” emails has grown into a polished criminal industry: fake delivery notifications, cloned bank login pages, text-message scams (“smishing”), fraudulent QR codes, and even AI-generated voice calls impersonating relatives or colleagues.
The good news: the defenses are mostly the same as they’ve always been, and they work. Here are 10 practical tips on how to avoid phishing, updated for how attackers actually operate today.
10 ways to protect yourself from phishing
1. Be cautious with emails and personal data
Keep PINs and passwords private, and never reuse the same password across accounts - one leaked credential shouldn’t unlock your whole life. A password manager makes unique passwords painless. Use common sense when reading messages: if something seems implausible or too good to be true, it is. Be especially wary of emails from unrecognized senders, generic greetings (“Dear customer”), and any request to confirm personal or financial information urgently.
2. Don't respond to messages about your bank or financial accounts
Legitimate banks and e-commerce companies never ask for your password, PIN, or full account details by email or text. Phishers rely on manufactured urgency - “your account has been suspended”, “suspicious activity detected, act now” - to make you click before you think. Pressure is itself a red flag. When a message demands immediate action on your money, slow down and verify through the company’s official app or website, reached by typing the address yourself.
3. Beware of pop-ups, attachments, and QR codes
Never enter personal information into a pop-up window, and don’t click links inside pop-ups. Treat unexpected attachments as hostile no matter who apparently sent them - a compromised friend’s account is a classic delivery route. And be careful with QR codes on posters, parking meters, or in emails: “quishing” scams paste malicious codes over real ones to send your phone to a fake payment page. Check the URL your phone shows before opening it.
4. Type important URLs yourself
Phishers use links in emails and texts to steer victims to spoofed sites at lookalike addresses - mybank-online.com instead of mybank.com, or subtle misspellings you won’t notice at a glance. Don’t follow links to any site where you’ll log in or pay. Type the address into the browser yourself, use a saved bookmark, or open the official app. If you suspect a phishing attempt, report it at apwg.org or via Google Safe Browsing.
5. Check that a site is secure - but don't stop there
Before submitting sensitive information, check for “https://” and the padlock icon in the address bar. But understand what that padlock means today: only that the connection is encrypted, not that the site is legitimate. Phishing sites routinely use HTTPS too. The padlock is necessary, not sufficient - the domain name itself is what you must verify.
6. Keep a smart eye on your accounts
Log into your online accounts regularly and review statements. Turn on transaction notifications from your bank so you hear about charges in real time. If you spot anything suspicious, report it immediately - speed matters, because stolen card data is used or resold fast.
7. Use two-factor authentication everywhere
Two-factor authentication (2FA) is the single biggest upgrade you can make: even if a phisher captures your password, they can’t log in without the second factor. Prefer an authenticator app or a hardware key over SMS codes where possible. And remember the golden rule - no legitimate service will ever call or message you asking you to read out a 2FA code. Anyone who asks for one is an attacker, full stop.
8. If you have the slightest doubt, don't take the risk
The most reliable anti-phishing policy is consistent refusal: never provide confidential data in response to an incoming message, ever. Delete the message and contact the organization through a channel you found yourself - the phone number on the back of your card, the official website, the official app. Even if the email might be genuine, verifying independently costs you two minutes; guessing wrong can cost far more.
9. Secure your devices and your connection
Some phishing emails carry more than fake links - attachments and downloads can install spyware that records your activity or trojans that open a backdoor into your device. Keep your operating system and browser updated, and use reputable security software.
Then protect the connection itself. A VPN encrypts everything between your device and the internet, which matters most on public Wi-Fi, where attackers can intercept traffic or impersonate hotspots. Le VPN adds two layers that directly counter phishing infrastructure: Threat Protection, a DNS-level filter that blocks known malicious and phishing domains before they load (available in the iOS, Android, and Windows apps), and Breach Detection, which scans leaked credential databases and emails you if your address appears in a known breach - your early warning to change passwords before criminals use them. With servers in 100+ locations and up to 10 simultaneous connections, one subscription covers your computer, phone, and tablet together.
10. Stay informed
Phishing techniques evolve constantly - new lures appear with every tax season, shopping holiday, and news cycle. Staying current is a defense in itself. Read the Le VPN blog and follow us on social media to keep up with the latest scams, malware trends, and practical advice for staying safe online.
The bottom line
Phishing succeeds through haste and trust, not technical brilliance. Slow down on anything involving money or logins, verify through official channels, use unique passwords with 2FA, and encrypt your connection with a VPN backed by DNS-level threat blocking. Do those things consistently and you’ll be a far harder target than the phishers are counting on.
About the author
Le VPN Blog Contributor
Julie Perrin writes for the Le VPN blog on online privacy, security, and the practical side of using a VPN day to day. Her articles help readers make sense of digital security topics and get the most out of their VPN connection.
Articles by Julie Perrin →