GCSE · Computer Science · AQA · Spec 8525

Phishing

An email arrives with your bank's logo, the right colours and a worried tone. Real or fake? Here's the twist: the better it looks, the less that tells you.

Computer Science · Phishing

Take the email apart

For each feature of the message: is it a warning sign, or does it prove nothing either way?

Still to sort

Warning sign (0)

Something the message says, asks for, or where it really comes from.

Where the line is: A warning sign is about what the message demands or who really sent it. It is not about how polished it looks.

Proves nothing either way (0)

Looks that a fake can copy.

Where the line is: If a fake can copy it easily, it cannot be evidence that a message is genuine. It cannot be evidence that a message is fake either.

8 of 8 still to sort.

An invented email has just arrived. From: Northfield Bank Security <security@northfield-bank-help.example>. Subject: Urgent: your account will be locked. The bank's own address really ends in northfieldbank.example. Don't read it as a whole. Sort it feature by feature.

Watch out: The logo and the layout are the two features that made the message feel safe. Look closely at which column they end up in.

Computer Science · How an attack works

Now flip to the attacker's side

Put the stages of a phishing attack in the order they happen

1 · First stage5 · Last stage
  1. The attacker collects the details and uses them against the victim

    Account access, identity theft, financial loss, or malware on the victim's device.

  2. The recipient types their details into the site

  3. A message pretending to be a trusted organisation is sent to many people

  4. The link takes them to a fake copy of the genuine website

  5. A recipient follows the link in the message

Predict, then check

The attacker sends the same fake message to a huge number of people. Almost all of them ignore it or spot the signs.

What happens to the attack?

Computer Science · What would you do?

The urgent message from 'your bank'

A message says it is from your bank. It says your account will be locked unless you confirm your password. It includes a link and a contact address.

Which of these is closest to what you would do?
How sure are you?

Computer Science · Your turn to write

Protecting against phishing

Describe one way an individual and one way an organisation can protect against phishing, and explain why each helps. [4 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

What you need to know

  • Phishing is a social engineering attack: fake messages pretending to be a trusted organisation try to trick you into giving away details or following a link.
  • Warning signs include a generic greeting, urgency or threats, a request for passwords or personal details, a sender or link address that doesn't match the organisation, and poor spelling or grammar.
  • A familiar logo and an official-looking layout prove nothing either way, because fakes are made to look genuine.
  • The link leads to a fake copy of the genuine website, and whatever you type into it goes to the attacker.
  • Sending to huge numbers of people pays because even a small fraction responding is enough.
  • The safe response is to contact the organisation through a route you already know, and never to use the link or contact details in the message.

The big picture

Phishing is a social engineering attack: fake messages pretending to be a trusted organisation try to trick you into handing over details. How genuine a message looks proves nothing, because fakes are built to look genuine. The clues that matter are what it asks for and where it really comes from, and the safe response is to contact the organisation yourself through a route you already know.

Key points

1Phishing works by making a fake look genuine, so the real addresses and requests tell you more than the logo or layout.
2The attack is a chain: message sent, link followed, fake site reached, details entered, details collected and used.
3An attacker can use stolen details for account access, identity theft, financial loss, or to put malware on a device.
4Individuals protect themselves by checking real sender and link addresses and using official routes. Organisations add training for users and email filters.

Worked example

Problem

A text arrives: 'SwiftPost: Dear customer, your parcel is held. Pay a £1.50 fee now at swiftpost-fee-pay.example or it will be returned.' SwiftPost's own website address is swiftpost.example. Is it genuine?

⚠ Watch out

Thinking a message must be real because it has the right logo and looks official, or because the website it links to looks right. Fakes are made to look genuine, so looks prove nothing. Check the real sender and link addresses and what is being asked for.

🧠

Memory hook

Judge the address, not the outfit. Anyone can dress a message up; nobody can fake where it really came from.

✓

Check yourself

Without looking back: name three warning signs in a message, name one thing that looks official but proves nothing, and say what you would do instead of following the link.

Flashcards

(10)
What is phishing?
A social engineering attack. Fake messages pretend to be from a trusted organisation to trick people into handing over details or following a link.
Why does a familiar logo prove nothing?
Anyone can copy a logo, and fakes are made to look genuine. Looks tell you nothing either way.
Name five warning signs of a phishing message.
A generic greeting; urgency or threats; a request for passwords or personal details; a sender or link address that doesn't match the organisation; poor spelling or grammar.
What should you check instead of how a message looks?
The real sender address, the real address behind any link, and what the message is asking you for.
What is the fake website for?
It is a copy of the genuine site, built to look right, so the victim types in details that go to the attacker.
Why do attackers send the same message to huge numbers of people?
It costs very little, and the attack pays if even a small fraction respond.
What can an attacker do with stolen details?
Get into accounts, steal an identity, cause financial loss, or put malware on a device.
What is the safest response to a suspicious message from your bank?
Ignore its link and contact details. Contact the bank yourself through its known official website or phone number.
Do genuine organisations ask for your password by email?
No. A message asking for it is a warning sign.
Name two protections an organisation can use against phishing.
Training users to spot the signs, and email filters. Filters can't catch everything, so people still need to know the signs.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 2 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.