Last updated · first published · reviewed by the Smart Money Verified Team

Phishing, Smishing & Communication Scams

Fraudulent emails and texts steal billions annually. Learn how to identify phishing attacks and protect your accounts.

The key defense is to never click links in unexpected messages and always verify requests through official channels.

Even tech-savvy individuals can be caught off guard. Phishing and smishing impersonate trusted companies using urgency to bypass your judgment.

How do phishing and smishing scams work?

1Creating Convincing Messages

Scammers craft emails or texts that appear to come from trusted sources: banks, Amazon, Netflix, government agencies, or package delivery services. They use real logos, formatting, and language styles.

2Creating Urgency or Fear

Messages claim your account is suspended, a package can't be delivered, you owe taxes, or suspicious activity was detected. Urgency prevents careful evaluation.

3Directing to Fake Websites

Links lead to convincing fake versions of legitimate websites designed to capture login credentials, credit card numbers, or personal information.

4Harvesting Information

Victims enter their real credentials on fake sites, unknowingly giving scammers access to their accounts, payment methods, or identity information.

5Exploiting Access

Stolen credentials are used to drain accounts, make purchases, steal identities, or are sold on the dark web to other criminals.

What warning signs should you watch for?

Urgent demands for immediate action

Threats about account suspension, missed deliveries, or legal action create panic that bypasses careful evaluation.

Requests for passwords or sensitive data

Legitimate companies never ask for passwords, SSNs, or full credit card numbers via email or text.

Generic greetings like 'Dear Customer'

Real companies usually address you by name. Generic greetings suggest mass-sent scam messages.

Mismatched or suspicious sender addresses

The sender's email domain should match the company. Watch for subtle misspellings like 'arnazon.com'.

Links to unfamiliar or misspelled URLs

Hover over links before clicking. Scam sites use domains designed to look legitimate at a glance.

Unexpected attachments

Attachments from unknown senders may contain malware. Don't open them.

Grammar errors and poor formatting

Professional companies proofread communications. Errors suggest fraudulent messages.

What psychological tactics do scammers use?

Authority Impersonation

Pretending to be banks, government agencies, or major companies leverages trust in established institutions.

Fear and Urgency

Threats of account closure, legal action, or financial loss trigger emotional responses that bypass logical evaluation.

Curiosity

Messages about unexpected packages, prize winnings, or mysterious account activity exploit natural curiosity.

Familiarity

Using real company logos, formatting, and language makes fraudulent messages appear legitimate.

Who is most at risk?

  • Anyone with email or a mobile phone (everyone is a target)
  • Elderly individuals less familiar with digital threats
  • Busy professionals who scan messages quickly
  • People expecting deliveries or recent transactions
  • Those who reuse passwords across multiple accounts
  • Users who don't enable multi-factor authentication
  • People unfamiliar with URL structures and domain names

What does this scam look like in real life?

The Bank Security Alert

$8,000 stolen from bank account

A professional received a text claiming to be from her bank: 'Suspicious activity detected on your account. Click here to verify.' The link led to a perfect replica of her bank's login page. After entering her credentials, she was redirected to the real bank site. Within hours, scammers had changed her password and transferred $8,000 to an external account. The text had come from a regular phone number, not the bank's official SMS service.

Red Flags Present:

  • Urgent security warning via text
  • Link instead of direction to call the bank
  • Request to 'verify' by entering credentials
  • Sender was not the bank's official SMS number
  • Redirect to real site after data capture

How can you protect yourself?

Never Click Links in Suspicious Messages

Go directly to websites by typing the URL yourself or using bookmarks. Don't trust links in unexpected emails or texts.

Verify Sender Identity

Check that sender email addresses match the company's domain exactly. Be alert for subtle misspellings.

Enable Multi-Factor Authentication

MFA adds a second verification step, protecting your accounts even if passwords are compromised.

Use Unique Passwords

Don't reuse passwords across sites. A password manager can help you maintain unique, strong passwords.

Keep Software Updated

Update your operating system, browser, and antivirus software to protect against known vulnerabilities.

Report Suspicious Messages

Forward phishing emails to the impersonated company and reportphishing@apwg.org. Report smishing to 7726.

What should you do if you've been affected?

1

Change Passwords Immediately

Change the password for the compromised account and any other accounts using the same password.

2

Enable MFA

Add multi-factor authentication to the affected account and any others that support it.

3

Monitor Account Activity

Review recent account activity for unauthorized transactions or changes. Set up alerts for future activity.

4

Contact the Company

Notify the real company that their identity was used in a phishing attack. They may have additional recovery steps.

5

Run Security Scans

Run antivirus and anti-malware scans to check for any software installed by malicious links.

6

Report the Attack

File reports with the FTC and FBI IC3. Report to your company's IT department if work accounts were affected.

What to do next

Never act on a link in an unexpected message. Reach the company through an address you looked up, and check unfamiliar firms in public records.

Frequently Asked Questions

Phishing is a cyberattack where criminals send fraudulent emails impersonating legitimate companies to trick recipients into revealing sensitive information like passwords, credit card numbers, or Social Security numbers. These emails often contain links to fake websites designed to capture your data.

Smishing (SMS phishing) uses text messages instead of emails to deliver the same type of scam. Messages may claim to be from banks, delivery services, or government agencies, containing links to malicious websites or phone numbers that connect to scammers.

Look for: generic greetings instead of your name, urgent language demanding immediate action, suspicious sender addresses that don't match the company, misspellings or grammar errors, requests for personal information, and links that don't go to the company's real website.

If you entered credentials, immediately change your password for that account and any others using the same password. Enable MFA if available. Monitor your accounts for suspicious activity. Run antivirus software. Report the incident to the impersonated company.

Yes. Some phishing emails contain attachments that install malware when opened, or links that download malicious software. Never open attachments from unexpected sources, and keep your operating system and antivirus software updated.

Protect Your Investments

Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.

I agree to receive recurring automated text messages at the phone number provided. Consent is not a condition to purchase. Msg & data rates may apply. Reply HELP/STOP. Terms & Privacy.

Your information is secure and never sold

How do you check a company or person right now?

Use the free check on this site. Enter the name and it searches the official registers for you in one step, then shows you what those records say — registration status and anything reported against them. Every answer names the official source behind it, so you can confirm it yourself if you want to.

Who writes these guides

Written and reviewed by the Smart Money Verified Team. We build every guide from primary regulator material, we take no payment from any company we write about, and we say plainly when public records cannot answer a question. Our guides are education, not financial advice.

How we check things: our methodology · disclosures