Phishing, Smishing & Communication Scams
Fraudulent emails and texts steal billions annually. Learn how to identify phishing attacks and protect your accounts.
The key defense is to never click links in unexpected messages and always verify requests through official channels.
Even tech-savvy individuals can be caught off guard. Phishing and smishing impersonate trusted companies using urgency to bypass your judgment.
How Phishing & Smishing Work
1Creating Convincing Messages
Scammers craft emails or texts that appear to come from trusted sources: banks, Amazon, Netflix, government agencies, or package delivery services. They use real logos, formatting, and language styles.
2Creating Urgency or Fear
Messages claim your account is suspended, a package can't be delivered, you owe taxes, or suspicious activity was detected. Urgency prevents careful evaluation.
3Directing to Fake Websites
Links lead to convincing fake versions of legitimate websites designed to capture login credentials, credit card numbers, or personal information.
4Harvesting Information
Victims enter their real credentials on fake sites, unknowingly giving scammers access to their accounts, payment methods, or identity information.
5Exploiting Access
Stolen credentials are used to drain accounts, make purchases, steal identities, or are sold on the dark web to other criminals.
Warning Signs to Watch For
Urgent demands for immediate action
Threats about account suspension, missed deliveries, or legal action create panic that bypasses careful evaluation.
Requests for passwords or sensitive data
Legitimate companies never ask for passwords, SSNs, or full credit card numbers via email or text.
Generic greetings like 'Dear Customer'
Real companies usually address you by name. Generic greetings suggest mass-sent scam messages.
Mismatched or suspicious sender addresses
The sender's email domain should match the company. Watch for subtle misspellings like 'arnazon.com'.
Links to unfamiliar or misspelled URLs
Hover over links before clicking. Scam sites use domains designed to look legitimate at a glance.
Unexpected attachments
Attachments from unknown senders may contain malware. Don't open them.
Grammar errors and poor formatting
Professional companies proofread communications. Errors suggest fraudulent messages.
Psychological Tactics Used
Authority Impersonation
Pretending to be banks, government agencies, or major companies leverages trust in established institutions.
Fear and Urgency
Threats of account closure, legal action, or financial loss trigger emotional responses that bypass logical evaluation.
Curiosity
Messages about unexpected packages, prize winnings, or mysterious account activity exploit natural curiosity.
Familiarity
Using real company logos, formatting, and language makes fraudulent messages appear legitimate.
Who Is Most at Risk
- Anyone with email or a mobile phone (everyone is a target)
- Elderly individuals less familiar with digital threats
- Busy professionals who scan messages quickly
- People expecting deliveries or recent transactions
- Those who reuse passwords across multiple accounts
- Users who don't enable multi-factor authentication
- People unfamiliar with URL structures and domain names
Real-World Scenario
The Bank Security Alert
$8,000 stolen from bank accountA professional received a text claiming to be from her bank: 'Suspicious activity detected on your account. Click here to verify.' The link led to a perfect replica of her bank's login page. After entering her credentials, she was redirected to the real bank site. Within hours, scammers had changed her password and transferred $8,000 to an external account. The text had come from a regular phone number, not the bank's official SMS service.
Red Flags Present:
- Urgent security warning via text
- Link instead of direction to call the bank
- Request to 'verify' by entering credentials
- Sender was not the bank's official SMS number
- Redirect to real site after data capture
How to Protect Yourself
Never Click Links in Suspicious Messages
Go directly to websites by typing the URL yourself or using bookmarks. Don't trust links in unexpected emails or texts.
Verify Sender Identity
Check that sender email addresses match the company's domain exactly. Be alert for subtle misspellings.
Enable Multi-Factor Authentication
MFA adds a second verification step, protecting your accounts even if passwords are compromised.
Use Unique Passwords
Don't reuse passwords across sites. A password manager can help you maintain unique, strong passwords.
Keep Software Updated
Update your operating system, browser, and antivirus software to protect against known vulnerabilities.
Report Suspicious Messages
Forward phishing emails to the impersonated company and reportphishing@apwg.org. Report smishing to 7726.
What to Do If You've Been Affected
Change Passwords Immediately
Change the password for the compromised account and any other accounts using the same password.
Enable MFA
Add multi-factor authentication to the affected account and any others that support it.
Monitor Account Activity
Review recent account activity for unauthorized transactions or changes. Set up alerts for future activity.
Contact the Company
Notify the real company that their identity was used in a phishing attack. They may have additional recovery steps.
Run Security Scans
Run antivirus and anti-malware scans to check for any software installed by malicious links.
Report the Attack
File reports with the FTC and FBI IC3. Report to your company's IT department if work accounts were affected.
Frequently Asked Questions
Protect Your Investments
Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.