Features
Part of Phishing scams: costs, choices and current rules
Phishing scams checklist explained with examples
A phishing checklist in two speeds: a twenty second test for the message in your hand, and one afternoon of setup that stops most of them mattering.
There are two checklists here and they run on completely different clocks. One takes twenty seconds and you run it on a message you are holding right now. The other takes an afternoon and you run it once, so that the first one almost never has to save you.
Do the afternoon one first if you have the choice. Almost everything that goes wrong goes wrong because the setup was doing none of the work.
What to take away
- The in-the-moment check is four questions long. Anything longer will not get used.
- Most of the protection is configuration, not vigilance, and it is done once.
- After a click, order matters more than speed. Money first, then credentials, then the settings that let someone come back.
The twenty second check
Run this on any message asking you to do something. Four questions, in order.
- What is being asked for? A password, a code, a payment, or an installation. Those four are the entire set of things worth this much attention. Anything else can wait until you feel like dealing with it.
- Did I start this? A message that continues something you were already doing is different from one that arrives on its own. Unprompted plus one of the four above is the combination.
- Is it giving me the route? A link, a number to call, a QR code, an attachment, an app to install. The route is the attacker's only real asset, and refusing it costs nothing.
- Is there time pressure or secrecy? Either one on its own is a reason to slow down. Both together is close to conclusive.
If the answers point the wrong way, do the one thing that settles it: reach the organization or person your own way, through a bookmark, the app, a number on a card, or a number already in your contacts. That is the rule the whole of phishing scams is built around, and it does not require you to be right about anything else.
The afternoon check
Done once, this removes the categories rather than the instances.
Sign-in
- A password used nowhere else on your email account, your password manager, and anything holding money.
- A password manager doing the filling, so a wrong domain produces silence instead of a login.
- The strongest second factor the service offers on your top accounts, ideally one a copied page cannot use.
- Backup codes printed and stored away from the device.
The reasoning for the second factor, and which kinds a copied page cannot use, is set out in CISA's guidance on turning on multi-factor authentication.
Recovery
- Recovery email and phone current and under your control on every account that matters.
- Nothing listed that you no longer own.
- Alerting turned on and pointed somewhere you actually read.
The email account specifically
- No forwarding rules or filters you did not create.
- No alternate addresses on the account that are not yours.
- No delegated access you did not grant.
Devices and apps
- Phone, computer, and browser updated.
- Connected apps reviewed, and anything unused removed.
- Banking and payments done through apps rather than links.
Money
- A rule about payment detail changes, agreed with whoever else can move money.
- Card and account alerts on, so a small test transaction is visible.
The full ordering for the account side is in the social media account security audit, and the standing rules that make the moment easier are in phishing scams rules.
The check you run on your own reaction
Worth adding because the failure is rarely technical.
- Am I in a hurry for a reason that came from this message?
- Am I being asked to keep this from someone who would normally know?
- Does the request depend on me being embarrassed?
- Have I been told not to hang up, or not to close the page?
- Am I doing this because it is easier than arguing?
Any yes is enough to stop. You are not deciding whether it is a scam. You are declining to decide under conditions chosen by somebody else.
After a click, in order
Most clicks are nothing. Act on what actually happened rather than on how alarming it felt.
- If money moved, contact the bank or payment provider before anything else on this list. What can be done depends heavily on how you paid and on how quickly you call.
- If you typed a password, change it on the real site, change it anywhere you reused it, and sign out all sessions.
- If you approved a sign-in or gave a code, assume someone is inside. After the password change, check recovery email, recovery phone, forwarding, filters, and connected apps, because those are what an intruder alters to keep access.
- If you installed something or allowed remote access, disconnect the device, remove it, and change passwords from a different device. Treat anything typed while it was running as seen.
- If it was a work device or a work account, tell whoever handles this immediately. Speed matters more than embarrassment, and a delay is the only part of this you will actually be judged on.
- Preserve what you can before cleaning up. Screenshots, the sender address, the number, timestamps. That record is what makes reporting useful, and the rest of the sequence is in scam reporting and recovery.
- Report it, to the provider, to the impersonated organization, and to your national fraud reporting body if money or identity documents were involved. In the US that is the Federal Trade Commission's reporting route.
The three day follow-up
The part nobody does, and where the second wave lands.
Check statements for small unfamiliar transactions, since a small test often precedes a large one. Re-check the recovery settings you fixed, because they get changed back. Watch for a new approach referencing the first, because being a known victim is itself a qualification, and any offer to recover what you lost for a fee is a second scam rather than a rescue.
Common questions
I clicked but did not type anything. What now?
Almost certainly nothing. Close the page, do not go back, and keep an eye out for a follow-up message that references it. Opening a page is very rarely the thing that causes harm.
The message knew my order details. Does that change the answer?
No. Personal detail makes a message convincing, not genuine. Check it the way you would have anyway, through the retailer's own app or site.
Should I reply and ask if it is real?
Never on the same channel. A reply confirms the address is live and is answered by the same person who sent it. Reach the organization independently.
How do I check a link without opening it?
Long press on a phone, or hover on a computer, and read the last two labels before the first single slash. That is the real domain. Everything to the left of it is decoration and can say anything.
Is reporting worth it if nothing happened to me?
Yes. It takes two minutes, it feeds filtering, and the same message is on its way to someone with more to lose.