Costs

Part of Phishing scams: costs, choices and current rules

Phishing scams examples: patterns worth studying

Phishing examples without specimen messages: what to inspect, what each common situation really wants from you, and the independent route that settles it.

There are no sample messages on this page, and that is deliberate. Printing one would give anyone who wanted it a working draft, and it would teach you to recognize a wording that changes next week.

What does not change is the position you are in when one arrives: holding a message, on a device, with something being asked of you. So this page is written from there. What you are actually looking at, what each common situation is really doing, and the one check that settles it.

What to take away

  • Study the request and the route, not the wording. The wording is the part that gets rewritten.
  • Every situation below has a real version that lives somewhere you can reach on your own. Go there instead.
  • Personal detail in a message raises how convincing it is and says nothing about whether it is genuine.

The five things you are looking at

Before any specific situation, this is the whole inspection.

The sending address, not the display name. A display name is free text. It can say anything, including the exact name of your bank. On a phone the address is often hidden behind the name, and expanding it takes one tap.

Where the reply would go. A reply address that differs from the sender is a strong signal, and it is visible if you start a reply and then discard it.

The real domain in the link. The last two labels before the first single slash. Everything to the left of that is decoration and can be made to look like anything. Long press on a phone or hover on a computer.

Where it arrived. A message about an account that has never contacted you at that address before, or a text from a bank that has always used the app, is out of place regardless of content.

Whether it references something you actually did. Not something plausible. Something you specifically did. An unprompted message about an order you did not place is answering a question you never asked.

None of the five is conclusive alone. All five together are usually enough, and the check in the next section covers the case where they are not.

Situations, and what settles each

What arrives What it needs from you Where the real version lives
A parcel needs a small fee or a redelivery A payment and card details The courier's own app, or the retailer's order page
A sign-in alert about your own account A click into a login page Open the app and check the account's own security log
Your bank has spotted fraud A call back, a code, or a transfer The number printed on your card
A colleague's new bank details for an invoice A payment to a changed account A phone call to the number you already held
A shared document you were not expecting A sign-in to view it Ask the sender through a different channel
A code you did not request You reading it back Nobody. Change that password now
A job or brand offer in a direct message Personal details, a fee, or an app install The organization's own careers or contact page
A tax, fine, or benefit notice Payment, or identity documents The authority's site, typed or bookmarked
A family member texting from a new number Money, urgently The number you already have for them
A QR code on a poster, meter, or letter A scan you cannot read first A typed address, where one is offered

The right column is the whole method. Every legitimate version of these has an independent route, and taking it costs a minute. The consumer regulator's own version of this material, organized the same way, is the FTC's guidance on recognizing and avoiding phishing. Nothing in the left column has to be judged if you never use the route it supplies.

The situations that are always wrong

A few requests do not require any assessment at all.

A code that was sent to you is never needed by anybody else, and the code arriving means somebody is trying to sign in as you right now. A request to move money somewhere safer is not something any fraud team does. A demand to stay on the line, or to not discuss this with your bank or your family, is a request for isolation, and no genuine process needs it. Payment by a method that behaves like cash, insisted on after you suggested something else, is the insistence telling you what this is.

The same short list of unconditional refusals, in rule form, is on phishing scams rules.

Where the copy is perfect and where it is not

It is worth being honest about what modern examples look like, because outdated advice makes people overconfident.

The writing is usually good. Logos and layout are often copied exactly, because they can be. Login pages are frequently pixel accurate, since a page is public and can be duplicated. Phone numbers can be displayed as any number, including the real one. A voice can be convincing. None of these are reliable signals any more.

What still tends to be imperfect: the sending address, the actual domain behind the link, the channel it arrived on, and the absence of any reference to something you genuinely did. And the request itself, which cannot be disguised, because the request is the point of the exercise.

That is why the tooling matters more than the eye. A password manager will not fill on the wrong domain, and a passkey cannot be used on a copied page at all. Those two do the discrimination that you cannot reliably do at four in the afternoon, which is the same conclusion reached in CISA's advice on recognizing and reporting phishing.

Messages about your own accounts

A special case worth naming, because it catches careful people.

Notifications about restrictions, copyright complaints, payouts on hold, verification badges, and policy violations all arrive constantly, and platform messages genuinely do look like this. The check is the same and easier than it sounds: whatever the message claims, the platform will also say it inside the app. Open the app on your own and look for the notice there. If nothing is waiting for you, nothing is happening.

For the version aimed at buyers and sellers, where the pressure is a pending sale rather than an account, see marketplace scams. Where the message appears to come from someone you know, the account is the problem rather than the message, which is covered in impersonation scams.

Common questions

Why not show me a real example so I know what to look for?

Because it would teach the wrong lesson. Examples date quickly, and studying wording trains you to be confident about a signal that has already stopped working. The route and the request are what stay constant.

They used my full name and my address. Doesn't that mean something?

Only that those details are in circulation, which they widely are. Personal knowledge is the opening move, not evidence.

How do I check something without giving anything away?

Do not reply, do not call the number given, and do not scan the code. Go to the organization through a route you already had. Nothing you do that way tells the sender anything.

Is asking for identity documents always a scam?

No, and it is a common cover. Some services legitimately need them, and the safe ways to hand them over, plus the requests that are never legitimate, are in identity verification.

What should I do with the message once I have decided?

Report it in the app or mail client, which feeds filtering, then delete it. If you interacted with it at all, work through the sequence in the phishing scams checklist rather than assuming it was fine.

More in Costs

Reviews

Phishing scams: costs, choices and current rules

Phishing explained from the position you are in: what the message wants, the one rule that settles it, and what to do first when you have already clicked.

Features

Phishing scams checklist explained with examples

A phishing checklist in two speeds: a twenty second test for the message in your hand, and one afternoon of setup that stops most of them mattering.

Industry

Phishing scams risks: warning signs and safer responses

Phishing risk sized by what you actually gave away, what surfaces in the first week, and the follow-up offer that takes more money than the original.

Rules

Phishing scams rules 2027: current rules and clear examples

Phishing rules written while nothing is happening: money rules, code rules, install rules, and the callback rule that covers a familiar voice.