Rules

Part of Phishing scams: costs, choices and current rules

Phishing scams rules 2027: current rules and clear examples

Phishing rules written while nothing is happening: money rules, code rules, install rules, and the callback rule that covers a familiar voice.

A rule is a decision made in advance, when you are calm, so that it does not have to be made later, when you are not.

That is the entire reason to write any of this down. Nobody is at their best while a message is telling them their account will be closed in twenty minutes. The point of a rule is that it does not require you to be at your best.

What to take away

  • Write the rules while nothing is happening. Under pressure you will follow a rule you already have and improvise a bad one if you do not.
  • A good rule names an action, not a feeling. "Verify anything suspicious" is not a rule.
  • Rules need an agreed exception process, or people will break them silently rather than ask.

What makes a rule usable

Three properties, and most household advice fails at least one.

It is testable. You can tell whether you followed it. "Be careful with links" cannot be checked; "I open banking through the app, never from a message" can.

It survives new tactics. Rules about spelling mistakes and odd greetings expired years ago. Rules about routes and about what is being requested do not, because the request is the part that cannot change.

It costs little to follow. A rule that is expensive gets abandoned on the first busy day. Hanging up and calling back costs a minute, which is why it holds.

The single strongest rule of this kind, never verifying a message using contact details the message supplied, is set out in phishing scams.

Money rules

Money is where the loss becomes permanent, so these deserve to be explicit.

  • No payment details change on the strength of a message. Not an email, not a document, not a call. A change to bank details is confirmed by phoning a number you already held, and the check happens before the payment, not after.
  • Nothing gets paid to release something. A fee to receive a parcel, a refund, a prize, a job, or a loan is the shape of the scam rather than a step in a process.
  • No moving money to keep it safe. No genuine fraud team asks you to transfer funds to a new account, and it is the most costly single instruction people follow.
  • Payment method is a decision, not a detail. Some methods carry a dispute route and some are effectively cash. If someone insists on the second kind, that insistence is the information.
  • A second person signs off above an agreed amount. In a household or a small team, pick a number and stick to it. Most of the value is in the pause.

The consumer regulator's own summary of the same patterns, written for people rather than for teams, is the FTC's page on how to avoid a scam.

Code and credential rules

  • A code that arrives unprompted means someone has your password. It is not a message to answer. It is a signal to change that password.
  • Nobody ever receives a code from you. Not support, not a colleague, not a delivery firm, not the police, not a family member. There is no legitimate exception, which is what makes it a good rule.
  • Passwords are typed only into a page reached by your own route. A bookmark, the app, or an address you typed.
  • A password manager that declines to fill is an answer. Do not copy the credential across to make the page work.

The habit behind the last two rules, and why a manager beats memory, is set out in CISA's guidance on strong passwords.

Rules about installing and allowing

  • Nothing gets installed because a message asked for it. Support software, a viewer, an update, a security tool.
  • No remote access to your device, ever, from an inbound contact. If you called a company on a number you found yourself, that is a different situation and still deserves care.
  • Attachments from outside are opened only when expected. An invoice nobody mentioned, a document that asks you to enable something, a file with a second extension.

Rules for voice, video, and familiar people

A voice is a claim about identity, not proof of one, and video is now in the same category. Rules that assume otherwise are out of date.

  • A request for money, codes, or secrecy gets a callback, whoever appears to be asking and however they sound.
  • Agree a question in advance with family or a small team: something an outsider could not answer and that is not published anywhere. Use it without apology.
  • Secrecy voids the request. Any instruction that includes not telling your bank, your colleagues, or your family is refused on that basis alone. Genuine processes survive being discussed.

Writing the household or team version

A rulebook nobody has read is decoration. Keep it to one page and make three things explicit.

First, what your side will never do. A small business telling its customers and staff plainly that it never asks for codes, never emails new bank details, and never calls asking for remote access removes the ambiguity that the scam needs.

Second, how to report a mistake. Say clearly that reporting a click is never punished, because the alternative is people hiding it while the damage grows. A no-blame route is worth more than any amount of training, because the response to a click is time-sensitive in the way set out in scam reporting and recovery.

Third, the exception path. When a rule genuinely blocks something legitimate, name who can approve the exception and what evidence they need. Rules with no exception path get broken quietly.

When the rule is inconvenient

The moment a rule feels annoying is usually the moment it is doing its job. Real organizations tolerate being called back. Real colleagues tolerate a phone call. Real deadlines survive a five minute delay.

The reverse is diagnostic. Pressure to skip your own rule, from anybody, for any reason, is the strongest single signal available to you. It is worth more attention than anything in the wording of the message.

Common questions

Are rules better than just being careful?

Yes, because carefulness is a mood and a rule is not. The situations that catch people are precisely the ones where they were not at their most careful.

How many rules should there be?

Fewer than ten, on one page. A long list is a list nobody remembers, and the money and code rules carry most of the weight.

What if a legitimate company asks me to do something a rule forbids?

Follow the rule and reach them your own way. If the request is genuine it will still be there, and no honest organization is damaged by a customer verifying. Where the request involves proving who you are, the safer ways to do that are in identity verification.

Do these rules cover buying and selling online?

Partly. The code request aimed at sellers and the payment tricks specific to marketplaces have their own shapes, which are covered in marketplace scams.

Someone I know is asking me to break a rule. Now what?

Treat the account as unverified until you have reached the person another way. A message from a friend's account is a message from whoever controls it, which is the subject of impersonation scams.

More in Rules

Reviews

Phishing scams: costs, choices and current rules

Phishing explained from the position you are in: what the message wants, the one rule that settles it, and what to do first when you have already clicked.

Features

Phishing scams checklist explained with examples

A phishing checklist in two speeds: a twenty second test for the message in your hand, and one afternoon of setup that stops most of them mattering.

Costs

Phishing scams examples: patterns worth studying

Phishing examples without specimen messages: what to inspect, what each common situation really wants from you, and the independent route that settles it.

Industry

Phishing scams risks: warning signs and safer responses

Phishing risk sized by what you actually gave away, what surfaces in the first week, and the follow-up offer that takes more money than the original.