INITIALIZING SYSTEM...
What is Phishing? How it Works URL Checker Quiz Report
CodSoft Task 2

Protect Yourself From
|

Learn to identify, avoid, and report cyber threats. Don't let attackers steal your digital identity. Join the awareness program today.

What is Phishing?

Phishing is a cyber attack that uses disguised email, websites, or messages to trick you into revealing sensitive information like passwords and credit card numbers.

Spear Phishing

Targeted attacks aimed at specific individuals or companies using gathered personal information to appear legitimate.

Whaling

Highly targeted phishing attacks aimed at senior executives or high-profile targets with access to valuable assets.

Smishing

Phishing attacks conducted via SMS or text messages, often containing malicious links disguised as alerts.

Vishing

Voice phishing where attackers call victims pretending to be from a trusted organization like a bank or tech support.

How Attackers Trick You

Understanding the anatomy of a phishing attack is the first step to defending against it.

1. The Bait (Fake Message)

You receive an urgent email or SMS claiming your account is locked, or you've won a prize. It creates a false sense of urgency.

2. The Hook (Malicious Link)

The message contains a link that looks legitimate but directs you to a fake website controlled by the attacker.

3. The Trap (Fake Website)

The fake website mimics a real service (like a bank or social media) and asks you to log in or provide personal details.

4. The Catch (Data Stolen)

Once you enter your credentials, passwords, or OTPs, the attacker captures them to access your real accounts.

Fake vs Genuine Email

Click on the warning signs in the fake email to learn how to spot red flags.

Fake URL Checker

Test suspicious links before you click. Enter a URL below to scan it (Simulation).

Enter a URL to see the analysis

Test Your Knowledge

Take this 10-question quiz to see if you can outsmart the scammers.

Phishing Awareness Quiz

10 Questions to test your cybersecurity skills.

Question 1/10

Question text goes here?

0%

Quiz Complete!

You scored 0 out of 10.

Cyber Security Tips

10 golden rules to keep your digital identity safe from attackers.

01

Enable 2FA

Always use Two-Factor Authentication for an extra layer of security on all accounts.

02

Check the URL

Always verify the domain name carefully before entering passwords. Look for typos.

03

Don't Rush

Scammers create urgency. Take a breath and think before acting on "urgent" emails.

04

Use Password Managers

They generate strong passwords and warn you if you're on a fake website.

05

Verify Callers

If your "bank" calls asking for details, hang up and call their official number directly.

06

Update Software

Keep your OS and browser updated to patch known security vulnerabilities.

07

Hover over Links

Hover over hyperlinks to preview the actual destination URL before clicking.

08

Never share OTPs

No legitimate organization will ever ask you to share your One-Time Password.

09

Beware of Attachments

Never open unexpected email attachments, especially .exe, .zip, or macros in Office files.

10

Educate Others

Share cybersecurity knowledge with friends and family to protect the community.

Real Case Studies

Learn from real-world scams that have tricked thousands of people.

Google Docs Scam

The Google Docs Worm

An email claimed a contact shared a Google Doc. Clicking it asked for permissions to a fake app disguised as Google Docs.

Lesson: Always verify app permissions before granting access to your account.
Bank KYC Scam

Fake Bank KYC Update

Victims received SMS claiming their bank account would be blocked unless they updated KYC via a provided malicious link.

Lesson: Banks never ask for sensitive info via SMS links. Use the official app.
UPI QR Scam

OLX/UPI "Receive Money" Scam

Scammers pretended to buy items online and sent QR codes, claiming scanning them would deposit money. Instead, it deducted money.

Lesson: You NEVER need to enter your UPI PIN to RECEIVE money.
WhatsApp Scam

The "Friend in Need" Hijack

Attackers hijack a WhatsApp account and message contacts urgently asking for money due to a medical emergency.

Lesson: Always verify urgent money requests by calling the person directly.

Frequently Asked Questions

Common questions about phishing and online security.

What should I do if I clicked a phishing link?

Disconnect from the internet immediately. Run a full antivirus scan. If you entered passwords, change them immediately from a different device, and enable Two-Factor Authentication (2FA) on the affected account.

Can I get hacked just by opening an email?

Generally, no. Simply opening an email is usually safe in modern email clients. The danger lies in clicking links, downloading attachments, or replying with personal information. However, you should still disable automatic image loading to prevent tracking pixels.

Is a website safe if it has a padlock icon?

Not necessarily! The padlock (HTTPS) only means the connection between you and the website is encrypted. A scammer can easily get an SSL certificate for their fake website. You must always check the actual domain name.

How do scammers get my email address?

Emails are often harvested from data breaches, public social media profiles, buying lists on the dark web, or by guessing common email formats. You can use services like 'Have I Been Pwned' to check if your email was in a breach.

Why do phishing emails often have bad grammar?

While sometimes they originate from non-native speakers, it's often an intentional tactic. By using poor grammar, attackers filter out cautious people and ensure they only spend time targeting the most vulnerable or careless individuals.

Report Phishing

Help make the internet safer by reporting suspicious websites and emails.

About Project

CodSoft Cyber Security Internship

This project is developed as part of the CodSoft Cyber Security Internship program. The objective is to design a modern educational web application that teaches users how phishing attacks work and how to protect themselves.

It demonstrates frontend development skills combined with cybersecurity awareness, utilizing modern web design principles like glassmorphism, responsive layouts, and interactive JavaScript simulations.

HTML5 CSS3 Vanilla JS