How to Recognize and Report Phishing
A practical guide for employees and business owners.
Phishing is the starting point for over 90% of data breaches. This guide covers how to spot it, what to do if you clicked, and exactly where to report it.
What Is Phishing?
Phishing is a social engineering attack where an attacker impersonates a trusted person or organization to trick you into revealing credentials, transferring money, or installing malware.
Modern phishing is highly sophisticated. Attackers research your organization, spoof legitimate domains, copy real email templates pixel-for-pixel, and use urgency and authority to bypass your critical thinking. It is not a sign of low intelligence to be targeted — it is a sign that attackers consider your organization worth attacking.
Common variants include spear phishing (targeted at a specific individual), whaling (targeted at executives), smishing (via SMS), and vishing (via phone call).
Warning Signs in an Email
No single indicator is definitive — sophisticated phishing often gets most of these right. The more boxes that check, the higher the risk.
If You Clicked or Interacted
Speed matters. The faster you act, the more damage can be contained.
Where to Report
Report whether or not you interacted — even a well-caught phishing attempt is worth logging so your IT team can block the sender and alert others.
Your IT or Security Team
This is always the first call. Forward the email as an attachment (not inline), include the headers if possible, and describe what actions you took. Most organizations have an abuse@ or security@ email address.
Your Email Provider
In Gmail: open the email → three-dot menu → "Report phishing." In Outlook: select the email → "Report" → "Report Phishing." This helps block the sender for all users.
US-CERT / CISA
Report to the Cybersecurity and Infrastructure Security Agency at us-cert.cisa.gov. Especially important for attacks targeting critical infrastructure or government contractors.
FTC
Report phishing to the Federal Trade Commission at reportfraud.ftc.gov. Important if financial fraud was involved or credentials were stolen.
Anti-Phishing Working Group (APWG)
Forward phishing emails to reportphishing@apwg.org. APWG aggregates reports to help shut down phishing infrastructure globally.
Train Your Team Before an Attack Does
Anchor runs phishing simulations that show you exactly how susceptible your organization is — and trains employees on what to do differently.