Phish Frenzy

Messages stream in - some real, some phishing. Tap the scams before they scroll off. Free, no signup.

How to play
  1. Messages drop down the screen
  2. Tap the phishing ones, leave the legit ones
  3. Each catch shows the red flag that gave it away

Why it matters: phishing is the No. 1 way ordinary people get hacked - and the tells are always the same once you know them. Read the guide →

📖 Guide

Next batch...

Continue in 5s...
Score: 0
good run.

Phishing works because it is fast and familiar. Urgency, a spoofed sender, a link that does not match, a request for a code or password - spot one tell and you spot the scam.

Get notified when new games drop
About this game

Phish Frenzy

Your inbox is a river, and most of what floats past is fine — a real receipt, a note from your actual boss, a delivery that is genuinely on its way. Mixed in are the fakes: messages built to look trustworthy just long enough to get a password, a payment, or a click. In Phish Frenzy the whole stream scrolls by fast, and your only job is to tap the scams before they slide off the screen. Miss one and it "arrives." Tap a real message and you have just reported your own utility bill as fraud.

How to play

  1. Messages stream in from the top — emails, texts, DMs, a mix of legitimate and fake.
  2. Tap the ones you think are phishing before they scroll out of view.
  3. Leave the real messages alone; flagging a genuine sender costs you.
  4. Read the tell on each reveal so you spot the same trick faster next round.
  5. Survive the stream as it speeds up and the fakes get less obvious.

What it actually teaches

Phishing is a fraudulent message that impersonates someone you already trust — a bank, a manager, a delivery service, a familiar app — to trick you into handing over credentials, sending money, or opening something that installs malware. The disguise changes but the machinery underneath rarely does, which is exactly why a fast game works as practice: the same tells keep repeating, and once you have seen them a hundred times they start jumping out on their own.

The red flags cluster. There is manufactured urgency ("act now," "your account has been suspended") designed to stop you thinking. There are lookalike or mismatched details — a sender address or link that is almost right but not quite, hovering one character off from the real domain. There are generic greetings where a real institution would use your name, unexpected links or attachments, and the tell that outranks the rest: any request for a password, a login code, or a payment. Add offers too good to be true, and you have most scams covered. Our how to spot a scam guide walks through each flag with real examples.

Frequently asked questions

What is phishing?

Phishing is a scam message that pretends to come from a sender you trust — your bank, your employer, a courier, a service you use — in order to steal login details, money, or to get you to install malicious software. The message is bait; the trusted name is the disguise.

What is the biggest red flag?

Any unsolicited request for a password, a one-time login code, or a payment. Legitimate organizations do not ask you to confirm your password or read back a verification code. Manufactured urgency — "act now or lose access" — runs a close second, because its entire job is to rush you past that suspicion.

What should I do if I clicked?

Do not enter anything on the page it opened. If you already typed a password, change it right away — and anywhere else you reused it — and turn on two-factor authentication. If you shared card or bank details, contact your bank directly using the number on your card, not any contact info from the message. Then report the message to the impersonated company.

Are texts and emails both phishing?

Yes. Phishing rides any channel that can carry a message — email, text (sometimes called smishing), DMs, even phone calls. The medium changes but the tells are the same: a trusted-looking sender, false urgency, and a push toward a link, a login, or a payment.

Related

For entertainment and education — not professional security advice.