What Phishing Is
Phishing is a message designed to make you act before you think — click a link, enter credentials, call a number, transfer money. It works because it exploits urgency, authority, and familiarity. The message appears to come from someone you trust — your bank, HMRC, a delivery company, a school, a friend — and demands immediate action.
Your children receive these messages on the same devices you gave them for school and socialising. They have less experience recognising them. They are more susceptible to urgency cues and authority claims. They are also more likely to comply without questioning, because they have been taught to follow instructions from adults and institutions. Teaching them to spot phishing is not optional — it is part of giving them a device.
Email Phishing
The sender's display name says "PayPal" but the actual email address is security-update@paypa1-verify.com. That display name is trivially forged — anyone can set it to anything. The address is what matters, and even the address can be spoofed unless the receiving server checks SPF, DKIM, and DMARC records, which many do not enforce strictly.
Look for these signals:
- Urgency language — "Your account will be suspended in 24 hours", "Immediate action required", "Final warning before account closure"
- Generic greetings — "Dear Customer" or "Dear User" instead of your name
- Suspicious links — hover over the link and read the actual URL in the browser's status bar, not the blue link text displayed in the message body
- Unexpected attachments — particularly .zip, .exe, .html, .iso, or macro-enabled Office files (.docm, .xlsm, .pptm)
- Slightly wrong branding — logos that are low resolution or subtly different, colours that do not quite match the real company's palette, inconsistent fonts, or missing elements
- Grammar and spelling errors — less reliable as a signal than it used to be, because attackers now use the same large language models and AI tools that everyone else does, producing clean, fluent text
Modern phishing emails are polished. They replicate branding accurately. They use correct grammar. They reference real services you actually use. The "obvious" phishing email with broken English and a Nigerian prince is still out there, but the sophisticated version is more dangerous precisely because it does not look wrong.
How to Check a URL
This is the single most important technical skill here. Teach it as a mechanical rule, not a judgement call. Judgement varies. The rule does not.
The domain is the part that matters. Read the URL from right to left, starting at the first single forward slash after the protocol prefix.
In https://paypal.security-update.com/verify, the domain is security-update.com. The word "paypal" to the left of it is a subdomain — controlled entirely by whoever owns security-update.com. This is not PayPal.
In https://www.paypal.com/verify, the domain is paypal.com. The www is a subdomain of paypal.com, controlled by PayPal. This is PayPal.
In https://signin.ebay.com.account-verify.net/login, the domain is account-verify.net. The words "signin", "ebay", and "com" are all subdomains — set to anything the attacker wants. This is not eBay. It is account-verify.net pretending to be eBay.
The rule: find the last dot before the first single forward slash. The word immediately to its left is the top-level domain (.com, .co.uk, .org). The word to the left of that is the domain name. Everything further left is a subdomain and can be set to anything by whoever controls the domain.
Teach your children this rule with examples. Write out five URLs on paper, mix real and fake, and have them identify the domain in each one. Practise until the process is automatic — until they read a URL the way they read a sentence, without conscious effort.
SMS Phishing — Smishing
Text message phishing — smishing — is particularly effective because SMS messages arrive on the same device, in the same messaging app, as legitimate messages. There is no spam folder. There is no display name to inspect independently. The messages are short, direct, and designed for instant action.
What it looks like on a teenager's phone:
- "Royal Mail: your package could not be delivered. Reschedule delivery: [link]"
- "Your Netflix payment failed. Update your details to avoid service interruption: [link]"
- "HMRC: you are owed a tax refund of £268.30. Claim here: [link]"
- "Mum, I've lost my phone. This is my new number. Can you send me £50 for a top-up? Xx"
- "Your Apple ID has been locked due to suspicious activity. Verify: [link]"
These messages are interleaved with real delivery notifications, real payment confirmations, and real messages from family members. The context makes them convincing. A text saying "your parcel could not be delivered" is plausible because parcels are delivered constantly. The attacker does not need to know you ordered something — statistically, you probably did.
The "Mum, I've lost my phone" variant targets parents directly. It uses familiarity and mild urgency. The amount is small enough not to trigger suspicion but large enough to be worth the attacker's time at scale. Do not respond to it. Call your child's actual number. If they really have lost their phone, you will find out through a channel you trust, not through an unsolicited text.
Verifying Messages
Never click the link in the message. This rule has no exceptions.
If a message claims to be from your bank, open a new browser tab and navigate to your bank's website directly by typing the address yourself. Or call the number on the back of your bank card — not the number in the message, not the number on the website the message links to.
HMRC will never send you a text message asking for payment or offering a refund via a link. Your bank will never ask for your full password, your PIN, or your one-time passcode by email or text. No legitimate organisation will ask you to buy gift cards as a form of payment, install remote access software, or keep the call secret from your family.
If you are unsure whether a message is real, contact the supposed sender through a channel you already trust — a phone number saved in your contacts, a website you navigate to by typing the address, an app you downloaded from the official app store. The message itself is not a trusted channel. The link in the message is not a trusted destination. The phone number in the message is not a trusted number.
Voice Phishing — Vishing
Phone calls from someone claiming to be your bank's fraud department, Microsoft technical support, HMRC, the police, or your internet provider. The caller may know your name, your address, and partial account details — information often sourced from data breaches, leaked databases, and social media profiles, then aggregated and sold in bulk.
The tell: they called you. Your bank's fraud department will never cold-call you and ask you to move money to a "safe account", read out one-time passwords, install software on your computer, or give them remote access to your device. If the call feels urgent and the caller insists you stay on the line — that insistence is the red flag. Legitimate fraud departments tell you to hang up and call back on a verified number. Scammers insist you do not hang up, because the moment you do, the spell breaks.
The correct response: hang up. Wait five minutes. Some sophisticated scammers keep the line open after you "hang up" — your outgoing call connects back to them rather than to your bank. Waiting five minutes or calling from a different phone defeats this technique. Then call your bank on the number printed on the back of your card.
Teach your children that it is always acceptable to hang up on a phone call that feels wrong. Politeness is not a reason to stay on a call that is manipulating you. No legitimate organisation will be offended if you hang up and call them back on a number you trust.
Social Engineering Beyond Phishing
Phishing is the most common form of social engineering, but it is not the only one. Understanding the broader category helps recognise attacks that do not arrive as messages.
Pretexting — constructing a plausible story to extract information. "I'm from IT, I need your password to fix the email issue." "I'm calling from your child's school, I need to confirm their date of birth and your home address for our records." The story sounds reasonable. The request hidden within it is not. Legitimate IT departments do not ask for passwords. Schools verify identity before sharing or requesting information, not the other way around.
Baiting — leaving infected USB drives in car parks, school grounds, or reception desks. Posting "free download" links for popular software, games, or media. Offering free Wi-Fi that intercepts traffic. Curiosity and the desire for something free are the levers. If your child finds a USB drive, they should not plug it into anything. If a download is free when it should not be, the product is not the software — the product is access to the device.
Tailgating — following someone through a security door or controlled entrance by looking like they belong. Less directly relevant for home security, but worth your children understanding. They will encounter controlled access at schools, workplaces, and institutions. The person behind them who asks them to hold the door open may be genuine, or may not.
The common thread across every form of social engineering: the attacker exploits trust, urgency, authority, or curiosity to override your normal caution. Recognising the technique matters more than memorising specific examples, because the examples change constantly while the techniques do not.
Teaching Children
Keep it practical, not frightening. The goal is a habit of caution, not a state of anxiety.
The Pause-and-Check Rule
If a message wants you to do something urgently, that urgency is the red flag. Legitimate organisations do not create artificial deadlines by text message. "Your account will be deleted in 2 hours unless you act now" is not how real companies operate. Real deadlines come with real notice — letters, multiple emails over weeks, account warnings that appear when you log in normally.
Teach your children to pause when they feel the impulse to act immediately. Read the message again. Check the sender's address. Check the URL without clicking. If anything feels off — even if they cannot articulate what — do not click. Show it to someone.
The Show-Me-First Agreement
Ask your children to show you any message that asks them to click a link, enter a password, download something, or send money. Not as surveillance — as a shared habit. Frame it the same way you would ask them to show you a letter from school before they sign anything.
Frame it as teamwork. "I get these messages too, and sometimes I have to look twice. Show me anything that looks like it wants you to do something, and I will show you mine." This works better than rules because it does not position the child as the one who cannot be trusted. It positions phishing as the adversary you are both facing.
Normalise Asking
"I got a weird message — is this real?" should be the easiest question in the house. No judgement. No "you should have known better." No exasperated sighing. The moment a child feels foolish for asking is the moment they stop asking and start clicking.
If they do click a phishing link, the response matters. Deal with the consequences — change the password, check the account, report the message — and then talk about what happened and what to look for next time. Blame ensures they hide the next incident instead of reporting it.
Reporting
Forward phishing emails to report@phishing.gov.uk — the National Cyber Security Centre collects these reports, analyses them, and takes down phishing sites. Every report contributes to taking the site offline faster.
Forward suspicious text messages to 7726 — this spells "SPAM" on a phone keypad. Your mobile provider investigates the number and blocks it. The process takes thirty seconds.
Report financial loss to Action Fraud on 0300 123 2040. Action Fraud is the UK's national reporting centre for fraud and cybercrime. They generate a crime reference number and pass the case to the relevant police force.
If personal data has been compromised — login credentials entered on a fake site, identity documents shared with a scammer, National Insurance number disclosed — consider a Cifas protective registration. This flags your identity with banks, lenders, and financial institutions, adding an extra verification step to any application made in your name. It does not prevent you from opening accounts or obtaining credit. It adds a pause — the same kind of pause this entire guide is trying to teach.
If Someone Has Already Clicked
Change the password for the affected account immediately. Not later. Not after dinner. Now. If the password was reused on other accounts — and be honest about whether it was — change it on every one of them. This is why password reuse is the problem and why password managers are the solution.
Enable multi-factor authentication on the affected account if it is not already active. Check the account for unauthorised transactions, forwarding rules on email accounts, changes to recovery email addresses or phone numbers, and new devices added to the account. Attackers who gain access often add their own recovery details so they can regain access even after you change the password.
If financial credentials were compromised — banking details, card numbers, or payment service logins — call your bank using the number on your card. Not the number in the phishing message. Not a number from a web search. The number embossed or printed on the physical card in your hand. They can freeze the account, issue a new card, and reverse unauthorised transactions if caught quickly.
Monitor the affected accounts and your credit file for the following weeks. The initial compromise may be the beginning of a longer campaign — credentials sold and resold, identity data aggregated with other breach data, targeted attacks built on the information already gathered. One click can have consequences that unfold over months.
The online safety tutorial elsewhere on this site covers the broader conversation about keeping children safe online. This guide focuses specifically on the messages that arrive uninvited.
Teach the URL-checking rule until it is automatic. Establish the show-me-first agreement before your children need it, not after. Make asking easy and judgement-free. Report every phishing message — to report@phishing.gov.uk for email, to 7726 for text. If someone has already clicked, change the password immediately, enable MFA, and call the bank. Phishing works because it exploits the gap between receiving a message and thinking about it. Close that gap.