Author: williamwhite

  • What Is a Phishing Link? How to Check a Link Before You Click

    What Is a Phishing Link? How to Check a Link Before You Click

    A phishing link is a deceptive link in an email, text, or message that looks legitimate but sends you to a fake website. Its goal is to trick you into handing over sensitive information such as passwords, banking details, or credit card numbers.

    You've probably seen one before. It might look like a note from your bank, a courier update, a password reset, or a message saying your account will be locked unless you act right away. The design may look polished, the logo may seem right, and the wording may sound urgent enough to make you click before you think.

    That's what makes phishing effective. It doesn't usually break into your account by force. It tries to get invited in.

    Last updated: 2026-07-13

    What Is a Phishing Link?

    A phishing link is a malicious web link disguised as something safe. You might get it in an email, text message, social media message, or chat app. It often claims to come from a trusted organisation, but the actual destination is controlled by a scammer.

    Imagine a fake storefront. From the street, it looks like your bank, your email provider, or a familiar shop. Once you step inside, the people running it try to take your wallet, copy your keys, or follow you home.

    That's why phishing is more than spam. Spam is often just unwanted noise. Phishing is fraud that uses trust as the bait.

    An infographic explaining what a phishing link is, detailing suspicious emails, impersonation, malicious URLs, and data theft risks.

    What the link is trying to do

    Most phishing links aim to push you into one of a few actions. They want you to sign in on a fake page, enter payment details, download malware, or approve access to your account.

    The danger usually starts with a believable story. A message says there's suspicious activity on your account, a missed delivery, or an invoice waiting. The link looks like the fastest way to fix the problem.

    Practical rule: If a message creates urgency and asks you to click, slow down before you do anything else.

    Nearly all phishing emails and internet scams involve a malicious URL, and link manipulation is a common trick where the visible text says one thing while the actual destination goes somewhere else, as KnowBe4 explains in its guide to phishing and link manipulation.

    Why this matters in Canada

    This isn't just bad online behaviour. The Canadian Anti-Fraud Centre states that phishing may constitute fraud under Section 380(1) of the Criminal Code, with a maximum penalty of 14 years' imprisonment, as outlined in its official page on phishing and related fraud offences.

    For everyday users, the more immediate issue is privacy and account security. If a fake site collects your login, that can expose email, financial records, saved contacts, and business information. Under PIPEDA, organisations handling personal information in Canada have obligations around protection and safeguards, which is one reason phishing remains a serious operational risk for businesses as well as individuals.

    How Phishing Links Work

    A phishing link works like a fake street sign. It points you toward a place that sounds familiar, but the road leads somewhere else.

    The scam usually has two parts working together. First, the message creates a reason to act. Then the link sends you to a page that copies a real service closely enough to catch people who are in a hurry. That page may ask for your password, payment details, a security code, or even permission to download a file.

    An infographic explaining how to identify malicious phishing URLs by analyzing their structure and domain components.

    Read the link from right to left

    When you inspect a link, start with the main domain near the far right. That tells you who controls the site.

    Take a link like this:

    secure-bank.example.com.malicioussite.net/login

    It is easy to notice "secure-bank" first and stop reading. The site owner is malicioussite.net. Everything before that can be arranged to look convincing, like a fake storefront sign placed in front of the wrong building.

    A few common tricks appear again and again:

    • Typos that look close enough like paypaI.com or a misspelt brand name

    • Subdomain tricks like yourbank.security-check.example.net

    • Shortened links that hide the final destination

    • Brand names in the path rather than the domain itself

    HTTPS doesn't prove the site is legitimate

    The padlock can mislead people. HTTPS only means the connection between your device and the site is encrypted.

    A fraud site can still use HTTPS. A sealed envelope comparison helps here. The envelope may protect the contents during delivery, but it does not confirm the sender is honest.

    HTTPS protects the connection. It does not verify the identity behind the page.

    What can happen after you click

    Sometimes the goal is obvious. A fake sign-in page asks for your email and password. Sometimes it is quieter than that. The page may try to load malicious code, trigger a file download, or collect technical details such as your IP address, browser, and device type for later targeting.

    If you click a phishing link but do not enter anything, that is still a warning sign, not always a disaster. In many cases, closing the page quickly limits the harm. You should still change your password if you were already signed in somewhere sensitive, run a device scan, and watch for follow-up emails or texts that build on that click. For Canadians, this matters at both a personal and business level. If a compromised account leads to exposure of personal information, PIPEDA can come into play for organisations that collect, use, or disclose that data. The scam itself can also connect back to fraud offences under the Criminal Code, as noted earlier.

    Phishing messages also hide clues outside the link itself. Sender names, reply-to addresses, tone, formatting, and unusual requests often give the scam away before you ever inspect the URL. Our guide on how to identify phishing emails with expert tips to stay safe explains those warning signs in plain language.

    How to Check a Link Safely

    The safest habit is simple. Don't click first. Inspect first.

    That pause matters because phishing often succeeds when people act on autopilot. If you build a routine for checking links, you turn a reflex into a security step.

    A close-up view of a person using a computer mouse to click on a phishing email link.

    Use hover to reveal the real destination

    On a desktop or laptop, place your mouse over the link without clicking. Most email apps and browsers will show the link's destination in a preview area.

    On a mobile device, you often need to press and hold the link to preview it. Don't tap quickly. A quick tap may open the page before you've checked anything.

    Look for signs like these:

    • Mismatched domains where the message says one company but the preview shows another

    • Odd strings of text with random letters, extra words, or long tracking fragments

    • Unfamiliar endings that don't match the service you expected

    • Brand names pushed left into a subdomain to distract you from the actual domain on the right

    Verify through a separate path

    If a message claims there's a problem with your bank, package, or email account, don't use the link in that message. Open a fresh browser tab and type the known website address yourself, or use the company's official app.

    This step feels slower, but it removes the attacker's shortcut. You're no longer trusting their route.

    A related clue lives in the message header. Headers show technical details about where a message came from and how it travelled through mail servers. They can look dense at first, but they're useful when a sender address seems off. Our article on how to read an email header and spot a fake sender breaks that process down.

    When a link preview still isn't enough

    Some links are shortened or heavily obfuscated. In those cases, it helps to get a second opinion before you visit the site.

    The short video below shows common patterns and reinforces the habit of checking before clicking.

    Quick habit: If you didn't ask for the message, don't trust the link inside it until you verify the destination another way.

    What to Do If You Clicked One

    If you clicked a phishing link, don't panic. Panic leads to rushed decisions, and rushed decisions can make a bad moment worse. What helps now is a calm, ordered response.

    The first question is simple. Did you only click, or did you also enter information? Those two situations overlap, but the next steps aren't exactly the same.

    An infographic detailing the immediate steps to take if you have accidentally clicked a phishing link.

    If you clicked but didn't enter anything

    Many people assume they're safe if they closed the page before typing a password. Sometimes that's true. Sometimes it isn't.

    The Canadian Centre for Cyber Security notes that phishing clicks can result in malware infection or session hijacking even when users don't submit credentials. The click itself can expose your device to infection, which is why avoiding suspicious links is as important as avoiding credential theft.

    Here's the immediate checklist:

    1. Disconnect from the internet if the page triggered a download, opened strange pop-ups, or redirected several times.

    2. Run a full malware scan with your trusted security software.

    3. Close your browser and reopen it. If you were signed into sensitive services, sign out and sign back in.

    4. Review active sessions for important accounts like email, banking, and work tools. If the service lets you sign out other sessions, use that option.

    5. Report the message to your email provider, workplace IT team, or the Canadian Anti-Fraud Centre if it appears to be part of a scam attempt.

    If you clicked and entered credentials or payment details

    Move faster here, but stay methodical.

    • Change the affected password immediately from the legitimate site, not the link you clicked.

    • Change any reused passwords on other accounts. Reuse is what turns one mistake into several account takeovers.

    • Turn on two-factor authentication if the service offers it.

    • Contact your bank or card provider if you entered payment information.

    • Watch for follow-up messages. Attackers often return after one successful interaction.

    If your password manager normally autofills on a real site and suddenly doesn't, treat that as a warning sign.

    If this happened on a work device, tell your IT or security team right away. If it happened on your personal email, report it through your provider's phishing report option and monitor the account closely for changes you didn't make.

    Tools to Scan Suspicious Links

    Manual checking should be your first move. A scanning tool is your second opinion when the link is shortened, hidden, or still looks suspicious after inspection.

    Here's a simple comparison of well-known options:

    Tool Best use What it helps with
    VirusTotal Unknown or suspicious URLs Checks a link against multiple security engines
    Google Safe Browsing Quick reputation check Flags many known dangerous websites
    URL expander tools Shortened links Reveals the full destination before you visit

    These services don't guarantee a link is harmless. New phishing sites can appear before scanners catch them. Still, they're useful when a link preview doesn't tell you enough.

    A good rule is to use a scanner when the destination is hidden, when the message is unusually urgent, or when the sender wants you to log in immediately. If the scan result is unclear, don't “test” the link yourself.

    If you're choosing protection for a team, our guide to anti-phishing programs for business protection compares the kinds of tools organisations use alongside user training.

    Preventing Phishing Attacks with Secure Habits and Email

    A phishing message usually asks you to make one bad decision quickly. Good protection comes from making a few calm decisions the same way every time.

    That matters in Canada for more than personal safety. If a phishing email exposes customer, employee, or vendor information, a business can end up dealing with privacy obligations under PIPEDA, along with the cost of investigation, notification, and recovery. For the criminal on the other side, creating or distributing phishing links can also lead to fraud charges under the Criminal Code.

    A simple routine works well:

    • Pause when a message creates urgency. Late fee notices, account warnings, and delivery problems are common bait.

    • Go to the company yourself. Type the known web address into your browser or use your saved bookmark instead of the link in the message.

    • Treat login pages like your front door key. If you did not expect to sign in, do not enter your password there.

    • Report suspicious messages so your provider, workplace, or the Canadian Anti-Fraud Centre can track patterns and warn others.

    Habits that lower your risk

    Daily habits do a lot of the work:

    • Use unique passwords so one stolen password does not open several accounts

    • Turn on two-factor authentication for email, banking, and work tools

    • Keep devices updated so your browser and operating system can block known malicious behaviour

    • Use a password manager because it can recognise the correct domain and stay silent on a fake one

    That last point helps in a very practical way. A password manager works a bit like a key cut for one lock only. If the site is a copycat, the manager usually will not offer to fill your login details, which is a useful warning sign.

    Your email provider matters more than people think

    Many phishing attacks start in the inbox, so your email setup affects how many risky messages you ever have to deal with. Filtering, attachment scanning, domain checks, and spy pixel blocking all help reduce the number of traps that reach you.

    Business model matters too. A provider focused on paid email and privacy has a clearer reason to invest in inbox protection without treating your messages as a source of ad data. Typewire, for example, runs its own infrastructure in Canada and focuses on practical protections like phishing detection, virus filtering, encrypted email, and spy pixel blocking—designed specifically so your inbox is easier to trust. That does not remove the need for careful habits, but it can cut down the number of suspicious emails that make it to your screen in the first place.

    Reporting matters too

    Online fraud is common enough that even careful people will run into phishing attempts. As noted earlier, phishing and spam operate at a very large scale. That is why reporting matters, even if you spotted the trick in time and did not lose money.

    If you click a phishing link but do not enter any information, do not assume nothing happened. Sometimes the click only opens a fake page. Sometimes it also confirms to the sender that your address is active, or tries to trigger a malicious download. Close the page, disconnect if something starts downloading, run a security scan, clear your browser if needed, and change your password if you entered it or if the site looked close enough to create doubt. If the account is important, review recent sign-in activity too.

    If you are in Canada, reporting the message to the Canadian Anti-Fraud Centre can help investigators connect separate complaints into a clearer pattern. Reporting it to your email provider or workplace also helps improve filtering for other people.

    Treat phishing like a stranger asking you to hand over your house key through a cracked door. You do not need to argue with them or prove they are suspicious. You close the door, check who they are through a trusted channel, and report the attempt if needed.

    If you want a private email service built for security, filtering, and Canadian data residency under PIPEDA, take a look at Typewire. We run our own infrastructure in Canada, avoid ads and data mining, and focus on practical protections like phishing detection, virus filtering, encrypted email, and spy pixel blocking so your inbox stays easier to trust.

  • What Is Quishing: Protecting Against QR Code Scams in 2026

    What Is Quishing: Protecting Against QR Code Scams in 2026

    Quishing is QR-code phishing. It hides a malicious link inside a QR code image. According to the Canadian Anti-Fraud Centre, fraudsters are increasingly using QR codes in various scams to steal personal information and money.

    If you've opened an email lately that asks you to scan a code to reset a password, review a bill, or track a package, you've already seen why this works. The message looks tidy. The QR code looks normal. Your phone makes scanning feel routine, so you move faster than you would with a plain text link.

    That small shift matters. With ordinary phishing, people often hover over a link and pause. With quishing, the dangerous part sits inside an image, and the scan usually happens on a phone where the full web address may be harder to inspect.

    Many business owners understand phishing in general, but quishing creates a new blind spot. If you'd like a refresher on the broader problem first, our guide to what email phishing looks like in practice covers the older pattern that quishing builds on.

    What Is Quishing

    A common situation looks like this. You get an email that says your Microsoft 365 session expired, or that a courier couldn't deliver a parcel. Instead of a button, the email tells you to scan a QR code to fix the issue on your phone.

    That is quishing, short for QR-code phishing. Attackers place a malicious link inside a QR code so you scan it, open a fake site, and hand over login details or trigger a malware download.

    An infographic explaining the concept of quishing, highlighting QR code-based phishing attacks and data theft risks.

    Why the scam feels normal

    QR codes are everywhere now. Restaurants use them for menus. Offices use them for guest Wi-Fi, forms, and sign-ins. Shipping notices, event check-ins, and support portals often include them too.

    Attackers rely on that familiarity. They don't need to invent a strange behaviour. They only need to copy a behaviour you already trust.

    Practical rule: A QR code is not proof that a message is legitimate. It's only another way to deliver a link.

    Why security teams pay attention to it

    Quishing isn't a niche trick. Malwarebytes describes it as a rapidly evolving cyber threat that bypasses traditional email security filters by embedding malicious links within QR codes, and notes that the Federal Trade Commission has reported a rising trend in these schemes (Malwarebytes on what quishing is).

    That warning matters because the attack changes where your attention goes. Instead of checking a visible link on your computer, you scan an image and jump to a site on your phone. The handoff feels smooth, which lowers your guard.

    For a small business owner, the risk is practical, not abstract. One employee scans a fake payroll code, enters credentials on a spoofed page, and the attacker may gain access to email, invoices, or internal messages. The QR code itself isn't dangerous. The hidden destination is.

    How QR-Code Phishing Works

    Most quishing attacks follow a simple chain. The criminal creates a fake login page, turns its address into a QR code, wraps that code in a convincing message, and waits for someone to scan it.

    An infographic showing the five steps of a QR-code phishing attack, also known as quishing, leading to data compromise.

    What the attacker does first

    The first step is usually a fake destination. It might copy a Microsoft 365 login, a bank sign-in page, or a document-sharing screen. The page often looks polished because criminals know the QR code already did the hard part, which is getting you to visit.

    Then they convert that web address into a QR code. According to IBM's security research, quishing differs from ordinary phishing because it uses a two-dimensional barcode, which stores data horizontally and vertically, to redirect people to spoofed login pages or malware.

    What you experience when you scan

    From your side, the process feels harmless. You open your phone camera, scan the code, and tap the prompt. On mobile, you may only see a shortened preview or a quick browser handoff, not a careful desktop-style inspection of the full address.

    That is one reason these attacks work so well. People scan in the middle of the day, often while moving between tasks. A rushed employee handling invoices or account alerts may treat the code as a shortcut instead of a risk.

    A few common paths look like this:

    1. Account reset
      An email says your password expired and asks you to scan a code to re-authenticate.

    2. Document review
      A message claims a secure file must be opened on mobile for compliance reasons.

    3. Payment or delivery
      A code promises to fix a failed delivery, confirm banking details, or release an invoice.

    The QR code is only the lure. The real theft happens on the page that opens after the scan.

    Proofpoint also notes that security teams now use QR code analysis engines with computer vision and machine learning to decode embedded URLs and assess risk. That tells us two things. First, defenders know this is a serious problem. Second, the basic email stack still needs extra help to inspect image-based threats well.

    Why Quishing Slips Past Email Filters

    A business owner gets an email that looks routine. It asks them to review a secure document or confirm an account detail, and instead of a blue link, it shows a QR code. The email gateway lets it through. The phone scan opens the risky page later.

    A computer monitor displaying complex digital data streams with a green sign saying Bypass Filters above it.

    The blind spot in many inboxes

    Traditional filters are built to inspect what they can read quickly. They check sender reputation, headers, attachment types, known phishing wording, and visible URLs. A QR code interrupts that process because the destination is tucked inside an image instead of written out in text.

    A simple comparison helps here. A normal phishing email is like a parcel with the address printed on the label, so scanners can read it right away. A quishing email hides that address inside a photo of the label. The message may still be suspicious, but the main clue is harder for basic filtering tools to parse.

    IBM describes quishing as a threat that hides in plain sight because attackers replace clickable links with QR codes that many email scanners do not inspect well (IBM on why scanners miss quishing).

    That is why an email can pass security checks and still lead to a phishing page later.

    If you want a plain-language explanation of how inbox protections usually inspect messages, our guide to spam filtering and email security basics explains what filters look for and where image-based threats can slip through.

    Why QR codes create a second layer of risk

    Quishing also shifts the attack onto a mobile device. That matters because the scan often happens outside the protected business environment. An employee may use a personal phone, open the page in a mobile browser, and never see the same warnings, URL previews, or security controls they would notice on a desktop.

    For Canadian businesses, that gap is especially important. Attackers have used QR-driven phishing in banking and payment scams, including cases reported in Canada that target mobile users with fake account prompts and phone-based credential theft. Generic guides often stop at "QR codes hide links." The more practical point is that the handoff to mobile can bypass both the email filter and the user's usual verification habits.

    The compliance side matters too. If a staff member scans a fake code and exposes customer or employee information, the problem extends beyond a password reset. Under PIPEDA, organisations must notify the Privacy Commissioner and affected individuals about breaches that pose a "real risk of significant harm," and they must document all breaches and retain those records for at least 24 months.

    This is especially critical for Canadian businesses. Email security isn't just about preventing the initial scan—it's about ensuring that if a breach occurs, your email infrastructure is designed to minimise exposure. Typewire was built with this in mind: by hosting email and audit data in Canada under Canadian jurisdiction, it ensures that if a quishing incident happens, the full record of that breach stays under your control and PIPEDA jurisdiction, rather than routing through US-based servers where retrieval for incident response becomes more complicated.

    A short explainer can help if you'd like to see the attack flow visually.

    Why this matters

    Quishing succeeds because many email defences were designed to judge written links, while the actual destination now sits inside a scannable image and opens on a phone. For a small business, the practical lesson is straightforward. Treat a QR code in email with the same caution you would give any unexpected login link, invoice update, or banking request.

    Real Quishing Examples

    The easiest way to spot quishing is to see how it shows up in everyday work. These aren't exotic attacks. They often arrive in ordinary business situations.

    A person holding a smartphone to scan a restaurant menu QR code standing on a wooden table.

    The fake IT reset

    A staff member receives an email that says multi-factor authentication needs to be reconfigured. The message avoids a visible button and instead says, "For security, scan this code on your mobile device." The destination opens a sign-in page that looks like a normal Microsoft or Google login.

    This catches people because the format feels more secure than a clickable link. In reality, the QR code only hides the same kind of phishing destination.

    The delivery problem that isn't real

    A small retailer gets a shipping notice saying a parcel is held at a depot. The message includes a QR code to reschedule delivery. The owner scans it between customer calls, lands on a payment page, and enters business contact details or card information.

    The trap works because it creates a small, believable inconvenience. People want the parcel released, so they act before they verify.

    The mobile banking and fake IVR trap

    A more worrying pattern involves banking. Malwarebytes notes that quishing can redirect people to fake IVR systems, and a CBC report cited in FuseCS says that in early 2025 31% of quishing victims in Vancouver lost money through fraudulent IVR calls after scanning malicious QR codes (FuseCS summary of quishing and fake IVR losses).

    This attack can unfold in a few steps:

    Scenario What the victim sees What the attacker wants
    Banking alert A QR code to "verify unusual account activity" Login details or phone-based verification data
    SMS or email follow-up A prompt to call a support number after scanning Trust and urgency
    Fake IVR system Automated prompts that sound bank-like PINs, account details, or one-time codes

    If a QR code leads you into a phone tree, treat it with the same suspicion as a surprise login page.

    How to Protect Yourself and Your Business

    The best defence is not to stop using QR codes entirely. It's to treat them like links, because that's what they are. Once you make that mental switch, your habits improve fast.

    Safer scanning habits for individuals

    Start with a pause. If a message is unsolicited and asks you to scan a code to fix a problem, slow down. Use a separate path to verify the request, such as typing the known website address yourself or calling the sender through a trusted number you already have.

    These habits help most:

    • Preview before opening. If your phone shows the destination, inspect it before tapping. If the address looks unfamiliar, misspelled, or unrelated to the organisation, stop.

    • Avoid urgency traps. Messages about account lockouts, invoices, and package issues often try to rush you.

    • Use the official app or site. If your bank or software provider needs action, open the app or website directly rather than entering through a QR code.

    • Keep work and personal caution aligned. A personal phone can still expose business accounts if you use it for email or sign-ins.

    Practical controls for businesses

    Staff training matters, but policy matters too. Teams need a simple rule they can follow under pressure: no one should scan a QR code from email to handle credentials, payroll, banking, or password resets unless the request is verified through a separate channel.

    The Canadian Centre for Cyber Security says quishing can circumvent DMARC (Domain-based Message Authentication, Reporting, and Conformance) compliance policies, and recommends DMARC-aligned anti-phishing software plus CIRA's Canadian Shield DNS resolver as defensive benchmarks (Canadian Centre guidance on phishing and quishing defences).

    A sensible business checklist looks like this:

    1. Train for the format, not just the concept
      Many teams train for suspicious links but not suspicious QR codes. Show employees examples from invoices, courier messages, and IT notices.

    2. Set a verification rule
      If a code asks for credentials, payment, or identity confirmation, employees should verify through another channel first.

    3. Review mobile exposure
      Quishing often succeeds on phones. Check whether your team uses personal devices for work sign-ins and whether your mobile browser habits are part of security training.

    4. Prepare for incident handling
      If someone scanned a malicious code, respond as you would to any phishing event. Reset passwords, review account activity, and document the incident.

    Key takeaway: The safest QR code is the one you don't scan until the context makes sense.

    The privacy and compliance side

    Security and privacy connect quickly here. If your organisation handles personal information, you remain responsible for it even when third-party vendors process it under PIPEDA, according to the practical summary linked earlier. That means your provider choices, staff practices, and incident records all matter.

    Data location matters too. A Canadian data sovereignty overview notes that organisations must obtain explicit consent before collecting, using, or disclosing personal information, and that individuals retain rights to access and correct their data under PIPEDA's fair information principles (overview of Canadian data sovereignty and PIPEDA duties).

    For businesses using outside providers, jurisdiction should be part of the discussion. OpsGuru's overview explains that data residency is not the same as data sovereignty, and that contractual safeguards and Transfer Impact Assessments can matter when foreign providers are involved (data sovereignty versus residency in Canada).

    If you want practical next steps for employee habits, our guide to avoiding phishing emails at work pairs well with a quishing policy.

    Staying Vigilant in a QR-Code World

    Quishing works because it hides an old scam inside a familiar format. The QR code isn't the problem on its own. The problem is an unverified destination combined with a moment of trust.

    The safest mindset is calm scepticism. If a code arrives unexpectedly, asks for credentials, or pushes you toward urgent action, stop and verify through a separate channel. That one habit will prevent many of the most common attacks.

    We should also be honest about limits. No filter catches everything, and no user spots every trick. Good protection comes from layers: better filtering, stronger policies, clearer training, careful mobile habits, and a provider that treats privacy and security seriously.

    Last updated: July 2026.


    If you want an email provider that keeps quishing incident data and email metadata under Canadian jurisdiction for compliance and incident response, Typewire is built for this. We run our own infrastructure in Vancouver, keep all data in Canada, and focus on straightforward, ad-free email designed around privacy and PIPEDA compliance.