Reviews

Phishing scams: costs, choices and current rules

Recognize phishing scams, verify messages through independent routes, protect accounts and payments, and respond safely after a click or disclosure.

Almost every phishing message is the same request wearing different clothes: use this route I am giving you, right now. The route is a link, a phone number, an attachment, a QR code, or an app. Take the route and you are on ground the sender controls. Refuse the route and the attack has nowhere left to go.

That is the whole defence, and it is why this page is organised around routes and pressure rather than around spotting bad grammar. Modern phishing is well written. Some of it is written by the same tools you use.

The one rule

Never verify a message using contact details the message supplies.

If the bank says your card is blocked, call the number on the back of your card. If the tax office says you owe money, go to the site you already have bookmarked. If a colleague emails asking you to change payment details, phone them on the number in your own contacts. If your child texts from a new number, call the old one.

This rule costs you a minute and it defeats the overwhelming majority of phishing, because the attacker's entire advantage is the channel they handed you. A real organisation will never be damaged by you hanging up and calling back. Anyone who objects to you doing that has told you what they are.

What the message is actually trying to get

There are only four prizes, and knowing which one is on the table tells you what happens next.

The prize What the message asks you to do Why it works
Your password Sign in on a page it links to The page looks exactly right, because it was copied
A one-time code Read out or forward a code you just received The code is arriving because they are logging in as you
A payment Pay a fee, a fine, a customs charge, a supplier invoice The amount is usually small enough not to trigger a second thought
Access to your device Install support software, open an attachment, enable macros Once running, it sees everything you type afterwards

The code one deserves its own sentence. No legitimate organisation ever needs a one-time code that was sent to you. Not your bank, not the platform, not the delivery company, not the police. The code exists to prove you are you; handing it over proves it for somebody else.

Channel by channel

The pitch adapts to where it finds you.

Email. Watch the actual sending address, not the display name: a display name is free text and can say anything. Watch for a reply-to that differs from the sender. Treat unexpected attachments as hostile, especially archives, documents that ask you to enable content, and files with a second extension. Treat a shared-document notification you were not expecting the same way as a link.

Text and messaging apps. Short, urgent, and link-led: a delivery that needs a small fee, a bank alert, a toll or fine, a job offer, a "wrong number" that turns into a conversation. Links are shortened, so you cannot read the destination, which is the point. Delivery companies and banks are reachable through their own apps and sites; use those instead.

Phone calls. Caller ID is not evidence. It can be set to any number, including one that matches the real organisation. The strongest version of this scam calls you, tells you your account is under attack, and asks you to move your money "somewhere safe" or read out codes to a "fraud team". No bank fraud team does either of those things. Hang up, wait a moment for the line to clear or use a different phone, and call the number on your card.

QR codes. A code is just a link you cannot read. The risk cases are physical: a sticker placed over the real code on a parking meter, a menu, a charging point, or a package; and codes inside emails and letters, which exist to move you onto a phone that has weaker filtering than your computer. Where a typed address is available, type it.

Search results and ads. People increasingly reach fake support pages and fake login pages by searching for them. Paid placements sit above real results and can be bought by anyone. For anything involving an account or money, use a bookmark or the app, not a search.

Social media messages. A message from a friend's account is a message from whoever currently controls that account. The usual openers are a giveaway you have supposedly won, a job or brand deal, an investment a friend is enthusiastic about, or a request to "vote for me in a competition" that leads to a login page. Verification is easy: contact the friend another way. There is a fuller treatment of the account-takeover version in impersonation scams.

Reading a link before you touch it

You do not need technical skill for this, just a habit of reading the right part.

  • The part that matters is the last two labels before the first single slash. In login.example-bank.security-check.com/verify, the real domain is security-check.com. Everything to the left is decoration.
  • A hyphen and a familiar word is the most common construction: brandname-support, brandname-verify, brandname-billing. Real organisations rarely need a second domain to log you in.
  • On a phone, long-press instead of tapping to see where a link goes. On a computer, hover and read the status bar.
  • Look-alike characters exist and you will not always catch them. That is fine: you do not have to, because the habits in the next section catch them for you.

Let your tools do the checking

Human vigilance is unreliable at three in the afternoon. Systems are not.

  • A password manager will not autofill on the wrong domain. If it does not offer the login you expect, that silence is a warning, and it is more reliable than your eyes. Do not copy and paste around it to "make it work".
  • Passkeys and hardware security keys are bound to the real site. A copied page cannot use them, which is what makes them phishing-resistant in a way that codes are not. Turn them on where offered, especially for email.
  • App over browser for banking and anything financial. There is no address to misread.
  • Keep the email account that receives your password resets separate and locked down. It is the master key, and it deserves the strongest sign-in method available.
  • Update the phone and the browser. A good share of attachment and drive-by attacks depend on something already fixed.

The pressure that makes people click

Phishing works on states of mind, not on gullibility. Recognising the state you are being put into is more useful than recognising a specific scam.

  • Time. A deadline measured in minutes or hours. Real problems tolerate you calling back.
  • Authority. A police force, a tax office, a court, a bank's security team, your own employer's leadership. Authority is exactly the thing you are entitled to verify.
  • Fear. An arrest, an account closure, a leaked photo, a fine. Fear narrows attention to the instruction being given.
  • Secrecy. "Do not discuss this with anyone", "do not tell the branch staff", "this is a confidential investigation". No genuine process needs you to hide it from your own bank.
  • Reward. A refund, a prize, a job, a package. Pleasant emotions suppress checking just as well as unpleasant ones.
  • Momentum. A long, friendly interaction that only turns into a request at the end. The earlier steps exist to make the last one feel continuous.

If you notice two of these at once, stop. Not because you have proved it is a scam, but because that combination is the point at which people stop checking.

If you already clicked

Most clicks are harmless. Act on what actually happened, in this order.

  1. You only opened a page. Close it. Nothing was typed, so nothing was taken. Do not enter anything if you go back.
  2. You entered a password. Change it now on the real site, and change it anywhere you reused it. Sign out all sessions. Then check the account's recovery email, recovery phone, and forwarding rules for anything you did not add.
  3. You approved a login or gave out a code. Assume someone is inside the account. Change the password, sign out all sessions, remove any unfamiliar device or connected app, and re-check recovery settings: attackers change those first so they can come back.
  4. You installed something or allowed remote access. Disconnect the device from the network, remove the software, and change passwords from a different device. Treat anything typed while it was running as seen.
  5. You paid. Contact the bank or payment provider now, before anything else on this list. What is possible depends heavily on how you paid.

Then take the wider sweep in account security, and if money or identity documents were involved, work through scam reporting and recovery.

Reporting it

Report the message to the provider, mail clients and messaging apps have a report-phishing action that feeds filtering, and it is more useful than deleting. Report an impersonated organisation to that organisation through its own site; banks, tax authorities, and delivery companies generally publish an address for forwarding fakes. In the US, consumer fraud reports go to the Federal Trade Commission and internet-enabled crime to the FBI's Internet Crime Complaint Center. CISA's guidance on recognising and reporting phishing is a reasonable starting point for the mechanics.

Reporting a near miss is worth the two minutes even though nothing happened to you. The number or address you report is the one about to reach somebody with more at stake.

Questions that come up

Is it dangerous just to open an email?

Opening a message is very rarely the risk. Opening its attachment, following its link, or acting on its instruction is. Load remote images off by default if you want to reduce even the small signal that a message was read.

They knew my name, my address, and my last order. Doesn't that prove it is real?

No. Those details circulate widely after breaches, and a convincing opening is exactly what they are used for. Personal knowledge raises how convincing a message is; it says nothing about whether it is genuine. Verify the way you would have anyway.

Can I tell by looking at the sender address?

Sometimes, and it is worth checking. But addresses can be spoofed and a real address can be sent from a genuinely compromised mailbox: a message from a colleague's actual account is still hostile if someone else is in there. Address checking narrows the field; the callback rule is what settles it.

What about voice messages that sound like someone I know?

Treat a voice as an unverified claim, the same as a display name. If a call from a familiar voice asks for money, a code, or secrecy, end it and call back on the number you already have. Agreeing a simple question within the family that an outsider could not answer is a cheap and effective backstop.

Filed underphishing scams