Phishing is the umbrella term for any scam that uses a fake message — email, text, voice call, social media DM — to trick you into giving up something valuable: a password, a credit-card number, money, access to your computer. Phishing has gotten dramatically more sophisticated. The bad grammar and obvious mismatched logos are mostly gone; modern phishing messages look almost identical to real ones from real companies. The defense isn’t spotting the bad grammar — it’s understanding the patterns and having simple rules you follow regardless of how convincing a message looks.
The Common Patterns
- Urgency — “Your account will be closed in 24 hours.” “Suspicious activity detected.” “Final notice.” Real companies almost never operate on these timelines
- Authority + threat — impersonating a bank, the IRS, Medicare, the Social Security Administration, or law enforcement, combined with a threat (arrest, account closure, benefits cut off)
- Click this link — nearly every phishing attempt has a link that, when clicked, takes you to a fake login page
- Unusual payment method — gift cards, wire transfers, cryptocurrency, payment apps to strangers. Legitimate organizations never request these
- Account verification — “We need to verify your account. Please confirm your password and Social Security number.” No legitimate institution does this via email or text
- Too good to be true — refunds, prizes, inheritances, settlement money you didn’t expect

By Channel
Email phishing
- Sender display name says “Bank of America” but the actual email address is something weird (`boa-security@mail-secure.tk`)
- Hovering over a link shows a URL that doesn’t match the claimed sender
- Generic greeting (“Dear Customer”) instead of your name
- Includes a logo and formatting that looks real but the message is asking you to log in, confirm, or click
Text message phishing (“smishing”)
- Delivery notification scams (“USPS package on hold — pay $1.99 redelivery fee”)
- Bank account “alert” with a link to verify
- Tax refund or unemployment-benefit “deposit” message
- Random text starting a conversation (“Hi, is this still your number?”) — the front end of a longer scam, often crypto or romance
Voice phishing (“vishing”)
- Caller ID can be spoofed to display ANY name or number, including your own bank’s real customer-service number. Never trust caller ID alone
- Common scripts: “This is the IRS calling about your back taxes,” “This is Microsoft calling about a virus on your computer,” “This is your bank’s fraud department”
- Common ask: confirm your account number, give a one-time code, install remote-access software, buy gift cards
Social media and DM phishing
- Friend requests from people you don’t know, often with stolen profile photos
- DMs claiming to be from a celebrity, brand, or platform support team
- “You won a giveaway! Click here to claim”
- Compromised accounts of real friends suddenly asking for money or sharing investment opportunities
Simple Rules That Stop Most Phishing
- If a message is unexpected, treat it as suspicious. Doesn’t matter how official it looks
- Don’t click links in messages. If the message claims to be from your bank, log in to your bank’s site directly (typed URL or bookmark), not via the link
- Verify by calling back — using a number YOU look up. Not the number in the message. Your bank’s real number is on the back of your card; the IRS’s is on irs.gov
- No legitimate organization will ask for gift cards, wire transfers to strangers, or cryptocurrency. If they do, it’s a scam, full stop
- Turn on two-factor authentication on your important accounts (email, bank, brokerage, Social Security). Use an authenticator app (not SMS) when possible
- Set up account alerts for withdrawals, logins, and password changes on financial accounts
- Never give a one-time verification code over the phone — these are NEVER requested by legitimate institutions
- Take 10 seconds before acting on urgency. Scammers manufacture pressure precisely to bypass careful thinking. If a message is real, a 10-minute pause to verify won’t cause harm
If You Clicked a Suspicious Link
- If you entered a password, change it immediately on the real site, and on any other site where you used the same password
- If you entered a credit card or bank info, contact the institution’s fraud department
- If you downloaded a file or installed software, run a malware scan; if you can’t, take the device to a reputable repair shop
- If you gave Social Security info, freeze your credit (see How to Freeze Your Credit) and review your IRS account at irs.gov
- Watch your financial accounts closely for the next 30-60 days for unauthorized activity
Educational only. Scam tactics evolve constantly. If you believe you’ve been targeted or have lost money, report to: the Federal Trade Commission at reportfraud.ftc.gov, your state attorney general, your local police, and (for elder financial abuse) Adult Protective Services via eldercare.acl.gov or 1-800-677-1116. For lost funds, contact your bank and credit-card issuers immediately. This article is not a substitute for legal or financial advice.