The Different Formats Phishing Actually Comes In Now

Sep 02, 2026By Jay Kells
Jay Kells

Most phishing advice pictures the same scene: an email with a slightly-off sender address and a link to a fake login page. That's still one of the ways it shows up, but it's far from the only one anymore, and treating email as the whole picture leaves the other formats free to catch me off guard. I've had close calls in a text message, over the phone, and once through a QR code stuck to a parking meter, none of which looked anything like a typical phishing email. Recognising which formats phishing actually turns up in matters just as much as recognising the warning signs inside any one of them.

Text Messages That Pretend to Be a Courier or My Bank

A text message strips away most of the things I'd normally check. There's no sender domain to inspect, no logo to compare, just a short line claiming a parcel couldn't be delivered or that my account's been flagged, with a link sitting right there ready to tap. The ones that get me thinking twice are timed well, arriving the same week I'm actually expecting a delivery, which is no accident. My rule now is simple: I never tap a link in a text claiming to be my bank or a courier, I go to the app or the official site directly instead, typed in myself rather than followed.


Phone Calls Built Around Urgency Before I Can Think It Through

A phone call adds a pressure an email or text can't easily create, a real voice on the line, sometimes recreated by AI now, telling me something needs sorting immediately. The pattern is always the same: a problem that supposedly can't wait, and a request to act, confirm, or pay before I've had a chance to check anything independently. I've started treating any unexpected call like this the same way regardless of how convincing it sounds, I say I'll call back on a number I already have for that organisation, and hang up. A genuine caller has no problem with that; a scammer usually does.


QR Codes That Skip Past Every Warning My Browser Would Give Me

A QR code is just a link wearing a disguise, but it skips the one thing that usually gives a bad link away, the visible web address. I scan it, my phone opens whatever's encoded in it, and I'm relying entirely on trusting where the code itself came from rather than anything I can read beforehand. The one that caught my attention was stuck over a genuine parking payment sticker, printed to look identical, redirecting to a fake payment page instead. Now I check whether a QR code looks stuck on rather than printed as part of the original sign before I ever scan it, and I look at the URL it opens before entering anything.

Macro close-up of gleaming brass coin slot mechanism with coin positioned mid-insert under studio lighting.


Adverts and Search Results Leading to a Convincing Fake Login Page

Search engines and social platforms both sell ad space, and that space isn't always policed as tightly as it should be. A paid advert or a sponsored search result can lead to a page built to look identical to a real bank, retailer, or software login screen, complete with the right logo and colour scheme, sitting just above the genuine result. My password manager has actually caught more of these than I have by eye, because it checks the exact domain before offering to fill anything in, and stays quiet on a page that isn't the real one no matter how convincing it looks. I treat that as one more reason not to skip using one.


Messages From Accounts Impersonating People I Actually Know

This one doesn't come from a stranger at all, at least not obviously. A cloned or hacked social media account belonging to someone I actually follow starts messaging with an urgent ask, a loan, a link to click, a codeword to confirm. The profile picture and name match exactly what I'd expect, because it's either a genuinely hacked account or a near-perfect copy of one. I've learned to verify anything unusual through a completely separate channel, a text or a call, rather than replying inside the same conversation where the impersonation is happening.


Why the Format Matters as Much as the Message Itself

Every one of these formats is doing the same underlying job, creating urgency and removing the normal checks I'd otherwise have time for. But each one closes off a different one of those checks: a text removes the sender domain, a call removes the time to think, a QR code removes the visible link, an advert removes the usual search-result trust signals, and an impersonated account removes the stranger-danger instinct entirely. I've written before about the layers of protection I rely on for email phishing specifically, and most of that same thinking carries across formats, but the specific check that catches each one is different, which is why I now think about the format first and the message second.


None of these are exotic. They're all just phishing wearing a different outfit, and the fact that phishing itself sits apart from most other online scams is worth remembering, because the same underlying defences, checking independently, never trusting urgency, using a password manager that checks the domain for me, work across every format even when the disguise changes. My free Safety Toolkit covers how to set most of that up, and NCSC has further guidance if you want to go deeper into spotting any one of these formats specifically.