Explainer/Cybersecurity/Kenya
What is phishing?
Phishing is the scam behind most break-ins, and it aims at you rather than your computer. Learn how it works, how to spot a fake message, and what to do if you have already clicked.
Phishing means tricking a person into giving away information, money or access by pretending to be someone they trust. The message can arrive by email, SMS, WhatsApp, phone call or QR code. It usually copies a real brand and adds a reason to hurry. The prize is a password, a one-time code or a payment.
A man knocks on your gate. He wears the shirt of the power company. He says your meter is broken. He needs your account number and the code that just arrived on your phone. He is calm and he is in a hurry. You hand it over. He never worked for the power company.
That is phishing. The trick is old. Only the door is new. Now the knock arrives as a message.
Phishing attacks the person. It does not attack the machine. That is why it works so well. A firewall can block a bad file. A firewall cannot stop you from typing your password into a page that looks right.
What phishing means
Phishing is a scam. Someone pretends to be a person or a brand you trust. Then they ask you to do one small thing. Click a link. Open a file. Send a code. Move money.
The name is a play on fishing. The scammer casts bait at many people at once. Most ignore it. A few bite. That is enough, because sending a million messages costs almost nothing.
Phishing is the front door for most other attacks. Our guide to what cybersecurity is shows where it sits in the wider picture.
How a phishing attack works, step by step
The steps rarely change.
- The scammer picks a brand you know, such as a bank, a courier or your school.
- They copy the look of its real page or its real email.
- They send it out by email, SMS, WhatsApp, phone call or even a QR code on a poster.
- They add a reason to hurry. Your account closes today. Your parcel is held.
- You type your details into their page.
- They use those details at once, often within minutes.
Step four is the heart of it. Fear makes people skip checks. Therefore almost every phishing message carries a clock.
The main kinds of phishing
Plain phishing goes out to everybody. Spear phishing is aimed at you by name. It may quote your manager, your project or your street. It takes longer to build and it is much harder to spot.
Smishing arrives by SMS. Vishing arrives by voice call. Quishing hides the link inside a QR code, so you cannot see where it leads until you have scanned it.
There is also business email compromise. Here the scammer sits inside a real mailbox and waits. A real invoice goes out. The scammer changes only the bank account on it. No bad software is needed at all.
How to spot a fake message
Look at the address, and ignore the name above it. Anyone can set a sender name to read “Your Bank”. The address behind that name is harder to fake. Read it slowly, letter by letter.
Then check for these signs.
- The message pushes you to act right now.
- The greeting is vague, such as “Dear customer”.
- The link text and the real link do not match. Hold your finger on the link to see the true address.
- It asks for a password, a PIN or a one-time code. No real bank asks for those.
- A file is attached that you did not expect.
Poor spelling used to be a strong clue. It is a weak clue now. Cheap writing tools mean a scam can arrive in clean English, Swahili or French. Judge the request. Do not judge the grammar.
Phishing and mobile money
Mobile money changed the shape of this crime in East Africa. In Kenya, many people move cash through the phone every week. So a fake alert lands in a place people already trust.
One common version works like this. An SMS says money has reached you by mistake. A caller then begs you to send it back. The first message was fake. The money never came. You send real money to a stranger.
Another version starts with a SIM swap. The scammer gathers enough about you to talk a shop into moving your number to a new SIM card. After that, your codes go to them.
Therefore two habits matter more than any app. Check your true balance in the phone menu, never in an SMS. And never read a code out loud to anyone.
What to do if you already clicked
Do not spend time on shame. Speed matters more.
- Change the password on that account, using a different device.
- Change it anywhere else you used the same one.
- Turn on a second sign-in step if it is not on yet.
- Call your bank or your mobile money line and freeze what you can.
- Tell your workplace, even if it is late at night.
Why tell your workplace? Because one stolen login is how ransomware often gets in. An hour of warning can save a week of ruin.
How to protect yourself for good
Turn on a second sign-in step everywhere, starting with your email. Your email can reset every other account, so it is the master key to your life.
Use a password manager. It fills your details only on the real address. If it stays quiet on a login page, treat that page as fake.
Better still, use a passkey or a small security key where the service offers one. These check the web address for you. A copied site fails that check, so the login simply does not work.
Firms take this further with zero trust security. The rule is short. Trust no login by default, even one from a desk inside the office.
What is coming next
Two changes are already here. Voice cloning can make a call from “your boss” sound real. And live phishing pages now pass your code to the real site while you wait, which defeats codes sent by SMS.
So defence is moving away from secrets you can repeat. A code can be repeated. A passkey cannot. THE SAFEST SECRET IS ONE YOU CANNOT SAY OUT LOUD.
Encryption helps too, though it answers a different question. End-to-end encryption hides your message from outsiders. It cannot tell you that the sender is honest.
Open your email settings today. Find the security page. Turn on the second step, and pick an app or a key rather than SMS. It takes about five minutes, and it shuts the door that most attacks come through.
Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.
- Phishing works by attacking the person rather than the software, which is why technical defences on their own do not stop it.
- The strongest defence against phishing is a passkey or a small hardware security key, because these check the web address and fail on a copied page.
- Anyone who has clicked a phishing link should change that password at once from another device and tell their bank or workplace the same day.
Questions people ask
How can I tell if an email is phishing?
Check the sender address and ignore the display name above it, reading the address letter by letter. Hold your finger on any link, or hover over it, to see where it really goes. Treat any message that rushes you or asks for a password, a PIN or a one-time code as a scam.
What should I do if I clicked a phishing link?
Change the password on that account from another device, then change it anywhere else you used the same one. Turn on a second sign-in step if it is off. Call your bank or mobile money line if money or card details were involved. Tell your workplace the same day, even if you feel embarrassed.
Does two-factor sign-in stop phishing?
It stops most of it. Codes sent by SMS, and codes made by an app, can still be caught by a fake page that passes them straight to the real site while you wait. A passkey or a physical security key checks the address of the site itself, so a copied page fails.
What is the difference between phishing and spear phishing?
Plain phishing is sent to huge numbers of people with a general message. Spear phishing is written for one person or one company and often uses real names, real projects and real invoices. Spear phishing is much harder to spot, so check any unusual money request by phone.