Your inbox is a river, and most of what floats past is fine — a real receipt, a note from your actual boss, a delivery that is genuinely on its way. Mixed in are the fakes: messages built to look trustworthy just long enough to get a password, a payment, or a click. In Phish Frenzy the whole stream scrolls by fast, and your only job is to tap the scams before they slide off the screen. Miss one and it "arrives." Tap a real message and you have just reported your own utility bill as fraud.
Phishing is a fraudulent message that impersonates someone you already trust — a bank, a manager, a delivery service, a familiar app — to trick you into handing over credentials, sending money, or opening something that installs malware. The disguise changes but the machinery underneath rarely does, which is exactly why a fast game works as practice: the same tells keep repeating, and once you have seen them a hundred times they start jumping out on their own.
The red flags cluster. There is manufactured urgency ("act now," "your account has been suspended") designed to stop you thinking. There are lookalike or mismatched details — a sender address or link that is almost right but not quite, hovering one character off from the real domain. There are generic greetings where a real institution would use your name, unexpected links or attachments, and the tell that outranks the rest: any request for a password, a login code, or a payment. Add offers too good to be true, and you have most scams covered. Our how to spot a scam guide walks through each flag with real examples.
Phishing is a scam message that pretends to come from a sender you trust — your bank, your employer, a courier, a service you use — in order to steal login details, money, or to get you to install malicious software. The message is bait; the trusted name is the disguise.
Any unsolicited request for a password, a one-time login code, or a payment. Legitimate organizations do not ask you to confirm your password or read back a verification code. Manufactured urgency — "act now or lose access" — runs a close second, because its entire job is to rush you past that suspicion.
Do not enter anything on the page it opened. If you already typed a password, change it right away — and anywhere else you reused it — and turn on two-factor authentication. If you shared card or bank details, contact your bank directly using the number on your card, not any contact info from the message. Then report the message to the impersonated company.
Yes. Phishing rides any channel that can carry a message — email, text (sometimes called smishing), DMs, even phone calls. The medium changes but the tells are the same: a trusted-looking sender, false urgency, and a push toward a link, a login, or a payment.
For entertainment and education — not professional security advice.