Phishing is a scam built around impersonation. The attacker pretends to be a trusted person or organization so you will click a link, enter information, approve access, or send money voluntarily.
Does this affect you?
Use this for suspicious emails, texts, calls, direct messages, social posts, and work messages that ask for urgent action or sensitive information.
Understand how phishing works
It is a con more than a movie-style hack.
- The message borrows trust by copying a bank, delivery company, government agency, employer, coworker, streaming service, or familiar brand.
- It creates urgency or fear with claims such as account locked, suspicious sign-in, package failed, payment declined, or legal action.
- It asks for something valuable: a password, one-time code, card number, Social Security number, wire transfer, gift card, or click to a fake login page.
- It appears across channels. SMS phishing is smishing, phone phishing is vishing, and social media direct-message scams use the same pattern.
- The destination may look almost identical to the real site but use a lookalike domain or unrelated address.
Spot the warning signs
Most phishing attempts leave clues when you slow down.
- Generic greetings are common in mass attempts, though targeted attacks may use your real name.
- Sender addresses and links may be slightly wrong, use extra words, hyphens, or unfamiliar endings. Hover or preview links before clicking.
- Urgency plus a specific action is a warning sign, especially verify now or confirm within 24 hours.
- Legitimate companies do not ask for full passwords, one-time codes, or Social Security numbers by email or text.
- Requests for gift cards, cryptocurrency, or wire transfers are strong scam signals regardless of the story.
More control
Verify independently
Go to the company website by typing the address yourself, or call a number from an official website, card, bill, or statement. Do not use contact information inside the suspicious message.
Do not reply
Replying can confirm your address or number is active. Report, block, and delete instead.
Report useful examples
Use Report phishing in Gmail, Outlook, or your provider. You can also report to the impersonated organization, the Anti-Phishing Working Group, or reportfraud.ftc.gov when money or information was involved.
Sources
- CISA – Avoiding Social Engineering and Phishing Attacks (2025)
- FTC – How to Recognize and Avoid Phishing Scams (2025)
- FBI – Phishing (2025)
