Skip to content

What is phishing?

Phishing tricks you into giving your credentials to an attacker, usually through a convincing copy of a login page reached from an email or message. It bypasses password strength entirely. A 32-character random password typed into a fake site is exposed as quickly as a weak one.

Topic
Attacks
Reading time
1 min
Reviewed
On this page

Why strong passwords do not help

Phishing does not guess your password; it asks you for it. This is why the security advice shifts here: check the domain before typing, use a password manager that refuses to autofill on the wrong domain, and prefer passkeys or hardware keys, which cryptographically verify the site's identity for you.

The autofill defence

A password manager's autofill is a quiet anti-phishing feature. It matches on the exact domain, so if it declines to fill a page that looks familiar, that hesitation is a signal worth trusting more than your own eyes.

Sources

These primary references support the terminology and current security guidance used in this definition.

Make one account easier today.

Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.

Free forever Works offline Phone or computer