How to Report a Phishing Attempt
How to Report a Phishing Attempt
Phishing — fraudulent attempts to steal your information, credentials, or money by impersonating trusted senders — is one of the most common online threats. Reporting phishing attempts helps protect you and others by alerting email providers, companies, and authorities so they can act. Knowing how and where to report phishing, and what to do if you fell for it, is valuable. This guide explains how to report a phishing attempt, in plain terms.
Why Reporting Phishing Matters
Reporting phishing has real benefits:
Protects others: Reporting helps providers and companies identify and act on phishing campaigns, protecting other potential victims.
Improves filters and defenses: Reporting phishing to your email provider helps train filters to catch similar attempts.
Helps companies respond: Reporting phishing that impersonates a company helps that company warn customers and take action against the impersonation.
Supports broader action: Reporting to authorities contributes to tracking and combating phishing and fraud.
How to Report Phishing Email
For phishing emails, report through these channels:
Use your email provider's "Report Phishing": Most email services have a "Report Phishing" option (often separate from "Report Spam"). Use it for phishing emails, as it helps your provider respond to the threat and train filters. This is the most important step for phishing email.
Report to the impersonated company: If the phishing impersonates a company (your bank, a service), report it to that company. Many companies have a dedicated address or page for reporting phishing that impersonates them, so they can warn customers and act.
Do not engage: Do not reply, click links, or provide information. Report and delete.
How to Report Phishing Texts and Calls
Phishing also comes by text (smishing) and calls (vishing):
Report phishing texts: Many regions and carriers offer ways to report phishing/spam texts (such as forwarding to a designated number). Use your carrier's or region's reporting method, and do not click links in suspicious texts.
Report scam calls: Report scam and phishing calls through your region's or carrier's reporting channels, and do not provide information to suspicious callers.
Block and report: Block phishing numbers and report them where possible.
How to Report Phishing Websites
For phishing websites (often linked from phishing messages):
Report to your browser: Browsers often have a way to report unsafe or phishing sites, helping protect other users.
Report to the impersonated company: Report phishing sites impersonating a company to that company.
Report to relevant services: Some services and authorities accept reports of phishing sites to help take them down.
Do not enter information: Never enter credentials or information on a suspected phishing site.
Reporting to Authorities
For broader reporting:
Report to relevant authorities: Many regions have authorities or agencies that accept reports of phishing, scams, and fraud. Reporting contributes to tracking and combating these threats. Look up the appropriate reporting body for your region.
Report fraud and financial loss: If phishing led to financial loss or fraud, report it to the relevant authorities and your financial institution.
What to Do If You Fell for a Phishing Attempt
If you responded to phishing or entered information:
Change affected passwords: If you entered credentials, change that password (and anywhere reused) immediately, and enable 2FA.
Contact financial institutions: If you provided payment or financial information, contact your bank or card issuer to stop and reverse fraud.
Watch for misuse: Monitor your accounts for unauthorized activity, and watch for further phishing using your information.
Scan for malware: If you clicked a link or downloaded something, consider running security software.
Report it: Report the phishing attempt through the channels above to help others.
Don't blame yourself: Phishing can be sophisticated; focus on responding rather than self-blame.
Frequently Asked Questions
How do I report a phishing email?
Use your email provider's "Report Phishing" option (often separate from "Report Spam"), which is the most important step — it helps your provider respond to the threat and train filters to catch similar attempts. If the phishing impersonates a company (like your bank or a service), also report it to that company, since many have a dedicated address or page for reporting phishing that impersonates them, allowing them to warn customers and act. Do not reply, click links, or provide information — just report and delete the phishing email.
Where do I report phishing texts, calls, and websites?
For phishing texts (smishing), use your carrier's or region's reporting method (such as forwarding to a designated number) and block the number. For scam calls (vishing), report through your region's or carrier's channels and block the number. For phishing websites, report them to your browser (which often has a way to report unsafe sites), to the impersonated company, and to relevant services or authorities that help take them down. Across all of these, do not click links, provide information, or engage — report and avoid.
What should I do if I fell for a phishing attempt?
Act quickly. If you entered login credentials, change that password (and anywhere reused) immediately and enable 2FA. If you provided payment or financial information, contact your bank or card issuer to stop and reverse fraud. Monitor your accounts for unauthorized activity, watch for further phishing using your information, and if you clicked a link or downloaded something, consider running security software. Report the phishing attempt through the appropriate channels to help others. Don't blame yourself — phishing can be sophisticated, so focus on responding promptly rather than self-blame.
Conclusion
Phishing — fraudulent attempts to steal your information, credentials, or money by impersonating trusted senders — is one of the most common online threats, and reporting it helps protect you and others by alerting email providers, companies, and authorities so they can act. For phishing email, use your email provider's "Report Phishing" option (the most important step) and report to the impersonated company if relevant. For phishing texts and calls, use your carrier's or region's reporting methods and block the numbers, and for phishing websites, report to your browser, the impersonated company, and relevant services. For broader impact, report phishing and any resulting fraud to the appropriate authorities for your region. If you fell for a phishing attempt, act quickly: change affected passwords and enable 2FA, contact your financial institutions if you provided payment information, monitor your accounts, scan for malware if you clicked or downloaded anything, and report it — without blaming yourself, since phishing can be sophisticated. By reporting phishing attempts through the right channels and responding promptly if you fall for one, you help protect yourself and contribute to combating phishing for everyone.