Skip to main content
Phishing attacks are among the most common — and most effective — cyberthreats you will encounter online. Cybercriminals use deceptive emails, text messages, and fake websites to trick you into revealing passwords, credit card numbers, and other sensitive information. The good news is that once you know what to look for, you can spot these scams before they do any damage. Trend Micro’s suite of tools adds an extra layer of automated defense, catching threats that even a cautious eye might miss.

What Is Phishing?

Phishing is a type of social engineering attack where a cybercriminal impersonates a trusted entity — such as your bank, a government agency, a popular online service, or even a colleague — to manipulate you into taking a harmful action. That action might be clicking a malicious link, downloading an infected attachment, or entering your credentials on a fake website that looks identical to the real one. Phishing is responsible for the majority of data breaches worldwide, and attacks have become increasingly sophisticated and personalized over time.

Common Types of Phishing Attacks

Email Phishing

The most prevalent form, email phishing involves mass-sent messages designed to look like legitimate communications from trusted brands like PayPal, Amazon, Microsoft, or your bank. These emails often create a sense of urgency — claiming your account has been suspended or that you need to verify a transaction immediately.
Watch out for urgent-sounding emails that pressure you to act immediately. Messages that say things like “Your account will be permanently closed in 24 hours” or “Unusual sign-in activity detected — verify now” are classic phishing tactics. Legitimate companies almost never demand immediate action via email alone or ask you to confirm your password through a link. When in doubt, go directly to the company’s website by typing the URL yourself — never click the link in the email.

SMS Phishing (Smishing)

Smishing attacks arrive as text messages on your phone, often appearing to come from delivery services, banks, or government agencies. A typical smishing message might claim that a package could not be delivered and ask you to click a link to reschedule — but that link leads to a fake site designed to steal your personal information. Because text messages feel more personal and immediate than email, smishing attacks often have higher click-through rates.

Voice Phishing (Vishing)

Vishing involves a live phone call or a robocall from someone impersonating a bank fraud department, the IRS, tech support, or another authority. The caller may already know some of your personal information — gathered from data breaches or social media — making them sound highly credible. They will pressure you to provide verification details, install remote access software, or make an urgent payment.

Red Flags to Watch For

  • Mismatched sender addresses: The display name says “PayPal Support” but the actual email address is something like support@paypa1-alerts.net.
  • Generic greetings: Legitimate services typically address you by your name. “Dear Customer” or “Dear User” is a red flag.
  • Suspicious links: Hover over any link (without clicking) to preview the actual URL. If it does not match the organization’s official domain, do not click it.
  • Unexpected attachments: Be wary of email attachments you were not expecting — especially .zip, .exe, .docm, or .xlsm files, which can carry malware.
  • Poor grammar and spelling: Many phishing emails contain awkward phrasing, unusual capitalization, or spelling errors that give away their illegitimate origin.
  • Requests for sensitive information: Reputable organizations will never ask for your password, full credit card number, or Social Security number via email.

How Trend Micro Protects You

Email Defender (included with Trend Micro Maximum Security and available as a standalone tool) scans your Gmail and Outlook inboxes in real time, flagging suspicious messages and quarantining known phishing emails before you even see them. It identifies deceptive sender addresses, malicious links embedded in the email body, and dangerous attachments — giving each email a clear risk rating so you can make informed decisions. Web Threat Protection in the Trend Micro browser extension checks every URL you visit against a continuously updated global database of known phishing and malicious websites. If you accidentally click a phishing link — in an email, a text message, or a social media post — Trend Micro blocks the page from loading and displays a clear warning. Fraud Buster is a free tool from Trend Micro that lets you forward suspicious text messages for immediate analysis, telling you within seconds whether the message is a scam.

Frequently Asked Questions

Yes. Trend Micro’s Email Defender integrates directly with Gmail and Microsoft Outlook to scan incoming messages for phishing indicators in real time. It uses machine learning and Trend Micro’s global threat intelligence network — which analyzes billions of threats every day — to identify deceptive emails, malicious links, and dangerous attachments. Flagged emails are clearly marked with a risk badge, and high-risk messages are moved to a separate quarantine folder automatically. You can review quarantined items at any time and release any that were incorrectly flagged.
Reporting phishing emails helps protect the broader community. Here are the key ways to report them:
  • To your email provider: In Gmail, click the three-dot menu on the email and select Report Phishing. In Outlook, use the Report Message button in the toolbar.
  • To the impersonated organization: Forward the phishing email to the company’s official abuse or security email (e.g., phishing@paypal.com or abuse@amazon.com). Most major companies have a dedicated team to investigate and take down fraudulent sites.
  • To the Anti-Phishing Working Group (APWG): Forward the email to reportphishing@apwg.org. The APWG is an international coalition that aggregates phishing reports and works to disrupt cybercrime operations.
  • To Trend Micro: If you are a Trend Micro user, you can submit suspicious URLs or emails through the Trend Micro Site Safety Center at global.sitesafety.trendmicro.com to help improve threat detection for all users.