trust-security

Phishing Links: How They Work, Red Flags & How to Stay Safe (2026)

Phishing links stole $215M in 2025 alone. Here's how they actually work, the 10 red flags to spot them, and what to do if you clicked one.

Team U2L 18 min read

A phishing link is a URL that impersonates a trusted site to steal your credentials, payment details, or install malware. Attackers hide the destination behind lookalike domains, homoglyph characters, or short URLs, then use urgent messages to rush you into clicking. Hover to see the real URL, check the domain letter-by-letter, and scan any suspicious link with Google Safe Browsing before you click.

Table of Contents

Somebody in your inbox right now is pretending to be your bank. Or your CEO. Or DHL. The message is short, the tone is urgent, and there's a single link tucked inside that looks almost right. Phishing links are the internet's most consistent scam vehicle, and in 2025 they cost Americans roughly $215.8 million in reported losses. That number is up more than 200% from the year before, mostly because AI now writes cleaner emails than most junior copywriters.

This guide covers what phishing links actually are, how they work under the hood, the red flags that give them away, and what happens when a reputable link platform screens destinations before a link ever goes live. We'll be specific rather than hand-wavy: you'll see the exact patterns attackers use, the tools that catch them, and the recovery steps if you've already tapped. (Disclosure: U2L AI is our product, and we screen every link that passes through us. We'll get to how at the end.)

A phishing link is a URL crafted to look legitimate but pointing to a malicious destination that steals credentials, payment details, personal information, or installs malware. Attackers wrap the link in a socially engineered message (email, text, DM, ad) designed to rush you past your judgment and get you to click. The link itself is the delivery mechanism; the theft happens on the destination page.

That definition is dry on purpose. The reality is more human. Somebody wants your money or your access, and the cheapest way to get either is to convince you to hand it over voluntarily. A phishing link is the trigger. The message around it is the con. And the destination page, which usually looks pixel-identical to the real thing, is where the actual theft happens.

Phishing links aren't a single format. They can be raw URLs (https://amaz0n-billing-verify.co/login), shortened URLs that mask a nasty destination, buttons in HTML emails that hide their real target, QR codes on parking meters, or SMS links from a number that spoofs your bank's caller ID. The delivery channel keeps changing. The underlying trick, get someone to click and then hand over something valuable on the other side, doesn't.

For a broader look at how short URLs work and why they sometimes get abused for this, see our explainer on URL shortening.

Every phishing link follows the same three-step pattern: register, deliver, harvest.

Register. The attacker buys a lookalike domain (paypa1.com, microsoft-support-alerts.net, apple-icloud-verify.xyz) or compromises an existing site. Domain registration takes minutes and costs a few dollars. Modern phishing kits ship with pre-built templates that mirror the real login page down to the pixel; the attacker just points the kit at the fake domain and the whole storefront comes up. Free HTTPS certificates from Let's Encrypt provide the padlock, which is why the padlock icon is not a trust signal anymore.

Deliver. The message goes out. Email is still the biggest channel by volume, but SMS ("smishing"), voice ("vishing"), social DMs, and even QR codes in the physical world are all live vectors. AI has made this stage brutally efficient. Where a scam email used to have telltale broken English, generative models now write flawless, brand-appropriate copy in any language. The FTC has been warning since early 2026 that "check for typos" is no longer reliable as a phishing test. Clean grammar means nothing now.

Harvest. You click. The destination page loads. It's an exact clone of the login page you expected. You type your username and password. The form submits to the attacker's server, which logs your credentials, then usually forwards you to the real site so you don't notice the switch. Sometimes the flow is more sophisticated (real-time proxy attacks that also capture your 2FA code as you type it). Sometimes it's a straight download prompt that drops an infostealer.

The economics are absurd. A phishing kit costs $50 to $500 on underground markets. One successful credential set can be worth hundreds to thousands of dollars, depending on the account. That's why the volume keeps climbing.

Attackers keep inventing variations, but the eight patterns below cover the vast majority of what shows up in inboxes and phones.

1. Typosquatting. The classic. A domain that's one character off from a real brand. goggle.com instead of google.com. linkedln.com instead of linkedin.com. amaz0n.com. The digit-for-letter swap is the most common variant because it slips past a quick glance.

2. Homoglyph attacks. More advanced. The attacker uses Unicode characters that look identical to Latin letters but are technically different (Cyrillic а instead of Latin a). The URL displays as apple.com in your inbox but resolves to a totally different domain. Modern browsers block this in the address bar (they show the Punycode xn-- prefix) but email clients don't always.

3. Subdomain spoofing. The real brand name is buried in the subdomain, and the actual owned domain is the attacker's. microsoft.com.support-portal.xyz looks like Microsoft at a glance. It isn't. The rightmost part before the first single slash is what your browser resolves. Everything to the left of that is decoration.

4. Shortened URL abuse. Attackers use bit.ly, tinyurl, or a self-hosted shortener to mask the real destination. This is why a shortener that doesn't screen its destinations is such a gift to phishers. It hides the URL, wraps it in a trusted-looking short domain, and outsources the click. This is also why reputable shorteners (including us) scan destinations at creation time.

5. Open redirect abuse. Some legitimate sites have URL parameters that redirect to any URL. Attackers craft links like https://real-brand.com/redirect?url=https://phishing-site.evil where the visible domain is real but the redirect drops you on the fake page. Google, LinkedIn, and Facebook have all patched high-profile open redirects over the years.

6. Punycode homograph. A subset of homoglyphs where the entire domain is spelled with non-Latin characters that render identically to Latin. Registered as xn--80ak6aa92e.com, displayed as apple.com. Chrome and Firefox now show the raw Punycode as a defense.

7. QR phishing (quishing). A QR code printed on a parking meter, gas pump, restaurant receipt, or event badge that leads to a phishing site. The victim scans on their phone, where the URL is even easier to miss. Growing fast because scanners rarely think of a physical QR code as an attack vector. Our QR code security guide covers this in depth.

8. Cloned brand links in ads. Paid Google/Facebook ads for legitimate-sounding brands with a display URL that matches the real brand but a landing page that doesn't. Attackers bid on the real brand's keywords and let the ad network do the delivery. This is why the top ad result is not automatically trustworthy.

None of these are conclusive alone. Two or three in the same message and you're almost certainly looking at phishing.

1. Urgency you didn't create. "Your account will be suspended in 24 hours." "Confirm within 60 minutes or lose access." Real companies almost never impose hour-scale deadlines on you via email. Urgency is the tool that bypasses critical thinking.

2. The domain is almost right. paypa1.com, micros0ft-support.net, netflix-billing.co. Read every character. If your eyes need to slow down to parse the domain, someone probably built it that way on purpose.

3. Display name mismatch. Email says "PayPal Support" but the actual sender is alerts@paypal-notify.xyz. Hover over the sender name on desktop or long-press on mobile to see the real address. The FTC's consumer protection alerts hammer this point every quarter.

4. Generic greeting on a "personal" account. "Dear customer" or "Dear user" from your bank is a red flag. Real financial institutions address you by name because they have your name.

5. Requests for credentials, payment, or documents out of context. A password reset link you never asked for. A "verify your card details" email when nothing has changed. A W-2 request from your CEO on a Friday afternoon. Unsolicited requests for anything sensitive should default to no.

6. Link text and destination don't match. The email says "Click here to view your invoice at yourbank.com" but hovering reveals https://random-domain.co/login. Always check the underlying URL before clicking.

7. HTTP instead of HTTPS. Any login page on plain HTTP in 2026 is either abandoned, broken, or hostile. HTTPS alone doesn't mean safe (phishing sites use HTTPS too), but no HTTPS means definitely unsafe.

8. Shortened link in a transactional context. Your bank does not send account alerts using bit.ly links. Legitimate businesses shorten in social posts and SMS marketing; they don't shorten in transactional emails. If you see a shortener in a "your account" email, treat it as a hard flag.

9. Attachment plus link ("check this file"). A file the sender wasn't expected to send, especially in .zip, .iso, .htm, or .docm formats. The attachment is often the primary payload; the link in the body is bait.

10. You weren't expecting it. The single strongest signal in the list. A DHL delivery notice when you have no package. A tax refund alert in June. An IT password reset out of nowhere. Unsolicited contact from an account you haven't touched recently is where the vast majority of successful phishing starts.

Phishing by the Numbers (2025 Data)

A few reference points from the FBI Internet Crime Complaint Center's 2025 report, which is the closest thing to a shared truth on U.S. cybercrime figures:

  • Total reported cybercrime losses in 2025: $20.9 billion, up 26% year over year.
  • Phishing-specific losses: $215.8 million, up from $70 million in 2024 (a 208% increase).
  • Phishing complaints: 191,561, making phishing the #1 most-reported cybercrime category by count.
  • AI-attributed phishing complaints: 803, with $10.3 million in losses. This was the first year the FBI formally tracked AI as a factor.

The interesting shape in those numbers: complaint volume barely moved, but total losses tripled. That means individual phishing attacks are getting more sophisticated and stealing more per victim. Fewer amateur-hour scams that any careful reader can spot, more targeted, well-researched attempts that get through even to security-aware people. The bar for "obvious phishing" has moved up.

For a wider view of URL abuse patterns and how to defend against them, our safe link verification walkthrough covers the tools we mention below in more procedural detail.

Here's the workflow we run ourselves when a link in an inbox smells off. It takes about thirty seconds and never exposes your device to the destination.

Step 1: Copy the URL without clicking. Desktop: right-click and choose "Copy link address." Mobile: long-press until the menu appears, then tap "Copy." This step is the whole thing. If you click first and check second, you've already lost the game.

Step 2: Eyeball the domain. Before running scanners, just look. Is the domain spelled correctly? Is it the brand you expected? Is the path a reasonable-looking string or a wall of random characters? Two out of three phishing attempts get caught right here.

Step 3: If it's shortened, expand it. Paste into checkshorturl.com or unshorten.it to see the real destination without loading it yourself. Many shorteners also support a preview by appending + to the URL (this works for bit.ly, u2l.ai, and others). See where it actually points before deciding.

Step 4: Run it through Google Safe Browsing. Paste the expanded URL into transparencyreport.google.com/safe-browsing/search. Google checks it against its continuously updated global threat database. A flag means stop. A clean result means "not on the known list yet," which is not the same as "safe."

Step 5: Confirm on VirusTotal. VirusTotal checks the URL against 70+ antivirus engines and threat intelligence services in parallel. Multiple flags mean skip. Even one or two reputable engines flagging the URL is usually enough to walk away.

Step 6: Cross-check the message. Even if the scanners are clean, ask yourself: did I expect this message? Does the sender check out? Does the URL actually match the story the message is telling? Scanners are late to novel phishing sites (typically several hours to a day). The message context is usually the fastest tell.

A practical shortcut for mobile users: install a reputable link safety extension or browser (Bitdefender's TrafficLight, Brave's built-in shield, or a similar tool) and let it screen in-line as you tap. Not perfect, but a real speed bump for the moments you skip the manual check.

What to Do If You Already Clicked One

Do not panic. Most bad clicks do not compromise anything. The dangerous outcome happens after the click, when you interact with the destination page.

If you only loaded the page: close the tab. Don't tap buttons, don't enter anything, don't accept downloads. Clear your browser history and run a malware scan to be safe. On mobile, force-close the browser and clear cache.

If you entered a password: change it immediately from a different device if possible. Then change it on every account that used the same password (this is exactly why password reuse is so dangerous). Enable two-factor authentication using an authenticator app (Google Authenticator, Authy, 1Password), not SMS. Check recent login activity on the affected account for unfamiliar sessions.

If you entered payment details: call your card issuer or bank and freeze the affected card immediately. Dispute any unauthorized charges. Ask for a new card number. Watch the account daily for the next month.

If you downloaded a file: delete it without opening. Run a full malware scan with a reputable tool (Malwarebytes is the consumer standard). If you actually opened the download, disconnect from the internet immediately, run an offline scan, and consider restoring from a clean backup. For a corporate device, contact IT before you touch anything else.

Report the link. Forward suspicious emails to your provider's abuse address (Gmail and Outlook have "Report phishing" buttons right in the interface). Submit the URL to Google Safe Browsing's report page and to PhishTank. This is how the threat databases stay current. Fifteen seconds of your time saves the next person who almost fell for the same message.

We designed U2L AI's link layer assuming some percentage of URLs submitted to any shortener will be abusive. So every link runs through a set of safety checks in parallel the moment it's created, not after somebody reports it.

Here's what happens when you paste a URL into U2L AI's shortener. The destination is checked against Google Safe Browsing's threat database, scanned by an AI moderation model for phishing patterns and scam language, cross-referenced against a curated blocklist of known abusive slug patterns, and rate-limited per account to shut down bulk abuse attempts. All of these run at the same time and complete before the short link is issued. If the destination is flagged, the link is rejected right there. No "we'll review it later," no chance to spread first.

The practical effect: a short link created through U2L AI is meaningfully less likely to point at a phishing page than a short link from a shortener that doesn't run pre-creation checks. This isn't a guarantee. No safety system catches novel threats on their first day. But it's the difference between a tool that screens its output and one that doesn't.

The bigger point is this: safety has to happen before the link goes live, not after. Post-incident response is damage control, not security. We compared how the major players handle this in our Bitly vs Rebrandly vs U2L AI head-to-head, and you can see the full feature list at u2l.ai/features.

Frequently Asked Questions

A phishing link is a URL that impersonates a legitimate destination to steal credentials, payment information, or install malware. Attackers wrap the link in an urgent-sounding message so the target clicks before thinking. The theft happens on the fake destination page, not in the link itself.

Hover over the link (long-press on mobile) to see the real destination before clicking. Check the domain letter by letter for typos or lookalike characters. Verify the sender's real email address rather than just the display name. If the message is urgent, unexpected, or asks for credentials or payment, treat it as phishing until you can prove otherwise. Scan the URL with Google Safe Browsing or VirusTotal for confirmation.

Are shortened URLs like bit.ly always phishing?

No. Most shortened URLs are perfectly safe and legitimate. Reputable shorteners (U2L AI, Bitly, TinyURL) actively screen destinations against threat databases before issuing short links. The concern is context: a shortened URL in a transactional email from your bank is suspicious because banks don't shorten transactional emails. A shortened URL from a friend or a social post is normal.

Usually nothing dangerous, if you close the tab before interacting. Modern browsers have strong sandboxing, so simply loading a page rarely compromises a device on its own. The real damage happens when you enter credentials, download a file, or grant a permission on the destination page. Close the tab, clear browser history, and run a malware scan to be safe.

Can a URL by itself contain a virus?

No. A URL is text and cannot execute code. What matters is where the URL leads. The destination page can serve malicious JavaScript, exploit browser vulnerabilities, or trick you into downloading harmful files. That's why scanning the destination is what actually protects you.

How much money do phishing attacks steal each year?

According to the FBI's 2025 Internet Crime Report, phishing caused $215.8 million in reported U.S. losses in 2025 alone, up more than 200% from the previous year. Phishing was the single most-reported cybercrime category with 191,561 complaints. Global figures are significantly higher because many attacks go unreported.

No. HTTPS only means the connection is encrypted; it says nothing about whether the destination is trustworthy. Free TLS certificates from providers like Let's Encrypt are trivial for attackers to obtain, so phishing sites almost always show the padlock now. Treat HTTPS as necessary but not sufficient for trusting a site.

Forward phishing emails to your email provider's abuse button (Gmail and Outlook both have "Report phishing" built in). Submit the URL to Google Safe Browsing's report page and to PhishTank. If financial fraud occurred, report it to the FBI's Internet Crime Complaint Center at ic3.gov. Reporting is what keeps the threat databases current for everyone else.

Do URL shorteners protect against phishing?

Some do, some don't. U2L AI runs Google Safe Browsing checks plus AI moderation in parallel before any short link is issued, and rejects links that fail. Bitly and TinyURL also screen destinations. Less reputable shorteners don't scan at all, which is why some shortened links point at abusive destinations. Sticking with shorteners that publish their safety approach is the safer path.

Phishing links won't stop showing up in your messages, but the thirty seconds it takes to check a URL is always cheaper than the recovery if you click and hand over anything real. Use the workflow above, share it with the people around you who ask, and default to skeptical when a message pushes you to hurry.

Want the links you send to be safety-screened by default so the people on the other end get the same protection? Create your free U2L AI account and every link you shorten passes through our threat checks before it's issued.

Ready to try U2L AI?

Free forever plan. No credit card required.