Knowledge · Check before you click or pay · 8 minutes

What is phishing and how to spot a fake text or email

What phishing means, how to spot a fake text (parcels, extra fees) or email, how to report a scam text in Poland via 8080, and what to do after clicking.

Last updated: October 6, 2026

What does phishing mean?

Phishing is a social engineering scam: the criminal poses as someone you trust and persuades you to type in your password, copy a code or make a transfer yourself. The name is a play on "fishing": cast the bait and wait for a bite.

According to CERT Polska, the Polish national CSIRT, the scammer does not break into your phone or computer. They target the person. Variants are named by channel: smishing is phishing by text message, vishing by phone call and quishing by QR code. The pattern is always the same.

It is common. In 2025 CERT Polska registered 78,391 phishing incidents, 30% of all registered events. The brands most often impersonated were the classifieds site OLX (28,462 events) and the marketplace Allegro (22,513).

How to recognise phishing

A page's appearance proves nothing, because a logo and layout can be copied in minutes. According to CERT Polska, the one thing that cannot be faked is the domain in the address bar. Your browser highlights it and greys out the rest of the address. If the highlighted part does not contain your bank's or shop's name, you are not on its site.

Warning signs in the message itself: time pressure ("your account will be blocked"), strong emotion (a prize, a relative in trouble), a small extra fee, a request for a code, an app install or a transfer to a new account number, and unexpected contact from an unknown number. The absence of these signs guarantees nothing.

Do not trust the sender either. CERT Polska points out that the sender field of a text or email can be spoofed, and a request may come from a real but hijacked friend's account. We explain how to check an email sender in how to check if an email is genuine, and how to check an address before clicking in how to check if a link is safe.

How to spot a fake text: parcels, extra fees, delivery firms

Fake texts mimic messages you really get: about a parcel, an extra fee, an unpaid charge or a blocked account. They are sent in bulk, so they always reach someone who happens to be waiting for a delivery. In 2025 CERT Polska warned, among others, about texts impersonating the parcel locker company InPost that spread malware (4 June), the e-TOLL road toll system (24 March) and the tax office's e-Urzad Skarbowy service (24 October).

According to CERT Polska's 2025 report, parcel scams are less common than before. What is growing is texts that only try to get you to make contact: supposedly from your child who broke their phone, about profits on an investment account, or about a login to a crypto exchange.

What to check: are you really expecting this parcel from this carrier, does the link lead to the company's domain, are you paying in the app you normally use. Check parcel status in the official app or by typing the carrier's address yourself, not via the link in the text. A BLIK code (a Polish mobile payment code) is never used to receive money: whoever asks for it wants to pay with your account.

Where and how to report a fake text message

In Poland, forward the fake text unchanged to 8080. Forwarding is free: the Act of 28 July 2023 on combating abuse in electronic communications (Article 5) requires operators to handle this number at no cost. The report goes to CERT Polska (CSIRT NASK).

How to do it: press and hold the message, choose "Forward", enter 8080 as the recipient and send it without adding a comment. Then delete the message or block the sender.

It works. Based on reports, CERT Polska creates message patterns that operators fetch within 5 minutes and are required to block. In 2025 it received 295,169 text reports, and 790 patterns blocked 1,883,610 malicious messages.

Other reporting channels: the form at incydent.cert.pl (sites, emails, other scams), the Bezpiecznie w sieci (Safe online) service in the mObywatel government app, and cert@cert.pl. Also report a phishing email in your mailbox as phishing or spam.

I clicked a phishing link: what should I do?

Clicking alone is usually not dangerous. According to CERT Polska, the problem starts when you do something on the page: enter data, copy a code, confirm an operation or install an app. The exception is rare, expensive attacks on unpatched browser flaws, which updates protect against.

If you did not type or install anything: close the page, report the message and update your browser and system.

If you entered data, time matters. Steps according to CERT Polska: call your bank and ask it to block the card or online banking access; change the password on that service and everywhere you used the same one; sign out of all sessions and turn on two-factor authentication; check whether unknown devices were added to the account; if you gave ID details, freeze your PESEL number in mObywatel; if you lost money, report it to the police. If the scammer took over an account, read what to do when someone hacked your account.

If you installed an app from the link: disconnect the phone from the internet, uninstall the app, call your bank and change passwords from another, clean device.

How to protect yourself from phishing

The simplest habit: before you type, confirm or install anything, read the domain in the address bar. Confirm any request for money or data through another channel: call a number you already know.

Tools that work even when attention fails help too. A password manager will not offer your password on a fake domain. According to CERT Polska, passkeys and FIDO2 hardware keys are the most effective protection against phishing, because they are bound to the site address. Two-factor authentication raises the bar, though a text message code can be phished just like a password. More in how to create a strong password.

Before you confirm an operation with a text code or in your banking app, read the operation description, not just the digits. You can check a domain from a suspicious message for free: you will see whether it is on CERT Polska's warning list and when it was registered.

Is phishing a crime?

Yes. In Poland, the Act on combating abuse in electronic communications (Article 30) provides for 3 months to 5 years in prison for sending a text, MMS or chat message impersonating another entity in order to obtain data, money or passwords, or to get someone to open a site or install software. Where money is stolen, the fraud provisions of the Criminal Code also apply.

If you lost money, report it to the police, at a police station or through the form of the Central Cybercrime Bureau. Keep the message, the sender's number, the site address and transfer confirmations.

In short

  • Phishing means impersonating a trusted company or person to obtain data, a code or a transfer. It is social engineering, not a virus.
  • Do not judge by appearance or sender. Check the domain in the address bar and confirm the request through another channel.
  • In Poland, forward a fake text unchanged to the free number 8080 and report sites and emails at incydent.cert.pl.
  • Clicking alone usually does no harm. If you entered data, call your bank and change passwords right away.
  • Passkeys, a password manager and two-factor authentication protect you even when attention fails.

Have a website, app or email address that looks suspicious?

Frequently asked questions

How do you pronounce phishing?

Like "fishing". The word plays on fishing: the scammer casts bait and waits for someone to bite.

Is phishing a virus?

No. Phishing is a scam in which a person hands over data themselves. It can lead to malware, though, when the message pushes you to install an app or "update" from outside an official store.

Does reporting a text to 8080 cost anything?

No. Polish law requires operators to forward reports to 8080 free of charge. Forward the message unchanged, without adding anything.

How do I get rid of a phishing message?

Simply delete it, after reporting it to 8080 or incydent.cert.pl. If you installed an app from the link, uninstall it, call your bank and change passwords from another device.

What are some examples of phishing?

A text about an extra parcel fee, an email "from your bank" about a blocked account, a message from a "buyer" on a classifieds site with a link to collect payment, a friend asking for a payment code or a contest vote, and a fake investment ad featuring a celebrity.

Is it dangerous just to open a text or email?

Reading the message usually is not. The risk starts when you open the link and type, confirm or install something on the page. Keep your system updated to close the rare exceptions.

Sources

  1. CERT Polska: Phishing, how to recognise a scam (updated 2 September 2026, in Polish)
  2. CERT Polska: Annual report on CERT Polska activities in 2025 (in Polish)
  3. Act of 28 July 2023 on combating abuse in electronic communications (Journal of Laws 2023, item 1703, in Polish)
  4. CERT Polska: Report an incident
  5. CERT Polska: Phone security (in Polish)
  6. Central Cybercrime Bureau (Polish Police): Report cyber fraud

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also