Windows 11 just got a big upgrade to protect you from phishing attacks — here’s how it works

Windows 11 logo on a laptop screen
(Image credit: Shutterstock)

Falling victim to a phishing attack can be bad enough on its own, but hackers can take complete control of your PC if your Windows password falls into the wrong hands. This is why Microsoft is implementing a new phishing protection feature in Windows 11.

As reported by BleepingComputer, Microsoft is expanding Windows 11’s Enhanced Phishing Protection with a new feature that will warn users when they copy and paste their Windows password into both websites and documents.

The software giant first introduced its Enhanced Phishing protection feature back with the release of Windows 11 22H2, in order to protect users’ Windows credentials from being stolen by hackers. However, this security feature only warned users when they manually typed their Windows password into a document or a login page on a website.

While it’s highly recommended that you use one of the best password managers to securely store and autofill your passwords, many users still prefer to do things the old fashioned way by copying and pasting them from a list. Now though, Microsoft is adding copy and paste protection to its Windows Enhanced Phishing protection program. 

How to enable Enhanced Phishing Protection in Windows 11

Once enabled, this updated security feature will show a prompt about the dangers of password reuse when Windows 11 users copy and paste their Windows passwords into a document or on a website. 

As password reuse can allow hackers to gain access to your other accounts once they have one of your passwords, Microsoft now recommends that users change their local Windows account password once they’ve been found copying and pasting it. 

It’s worth noting that the company’s Phishing protection isn’t enabled by default in Windows 11 and you will need to turn it on manually for the extra protection it provides. This can be done by going to Windows Security > App & browser control > Reputation-based protection and then Phishing protection. Here, you’ll want to toggle the switch to on and add checkmarks to the other options below it.

According to BleepingComputer, Windows Enhanced Phishing Protection now works with Firefox and Excel — though it still doesn’t work with third-party note-taking apps like Notepad2 or Notepad++. 

If you manually enter your password to login into one of the best Windows laptops, you’ll be able to see these new warning messages when you copy and paste or type out your Windows password in documents or on webpages. However, if you use Windows Hello, the Windows 11 Phishing protection doesn’t work as you’re already using an extra layer of security in the form of a PIN or biometrics when logging into your computer.

Staying safe from phishing attacks on your Windows PC 

Fish hook on a keyboard

(Image credit: Shutterstock)

Even with Windows Enhanced Phishing Protection enabled, you still need to be on the lookout for phishing emails and attacks in order to stay safe online.

As such, you want to be really careful when opening emails from unknown senders while avoiding clicking on any links or attachments they may contain. If an email has a blank subject line or has one that looks suspicious, it’s best to just ignore it.

Another thing to look out for in phishing emails is a sense of urgency. Hackers and other cybercriminals often try to elicit an emotional response to get potential victims to respond to their messages. This is why you’re going to want to try and keep a clear head when going through your inbox as hackers will often trick you by providing a deadline you need to respond by or risk losing access to one of your accounts.

By following these tips and enabling Windows Enhanced Phishing Protection, you’re one step closer to staying safe from hackers. However, you should also install one of the best antivirus software suites on your computers just in case malware does manage to arrive on your PC via your inbox.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A person typing on a computer while hackers use phishing to steal a file from their computer
Phishing: What is it, and how to avoid it
iPhone 15 Pro Max shown in hand
iMessage under attack from scammers sending phishing messages — don’t fall for it
Microsoft Edge open on a laptop with the browser's app listing page open on a smartphone in front of it
Microsoft Edge will soon protect you from these scary scams that even Chrome can't
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Windows 11 logo on a laptop screen
I reviewed Windows 11, and these are the 5 new features I'm most excited about for 2025
A laptop on a windowsill in the middle of a Windows update
Microsoft is ending support for Windows 10 soon — 5 ways to make sure your PC is secure
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)