Skip to main content

report phishing

To report phishing is to notify the appropriate person, organization, or service that a received message is suspected to be a deceptive attempt to obtain sensitive information or make someone do something harmful by pretending to come from a trusted source.

In plain English

This means telling the right person, organisation, or service that a message may be pretending to come from someone trusted. The concern is that it is trying to get sensitive information or pressure someone into doing something harmful.

In context

Here, "report phishing" denotes an action to notify the relevant service or security team that the message is suspected to be a deceptive message posing as a trusted source in order to obtain sensitive information or cause harmful action.

Situation
Responding to phishing, suspicious activity, fraud, and compromise alerts
What it communicates
offers an action to flag the message to the service or security team.

Meaning limits

The term alone does not establish whether the suspicion is correct or what result will follow from making the report.

Examples

“After a text claiming to be from his bank asked for his PIN, he called support to report phishing.”

Core meaning

“Staff are told to report phishing to the security team when a message appears to come from a manager and demands a fast payment.”

In context