Phishing Patterns: Email, Text, and Voice Scams Explained

Phishing is the umbrella term for any scam that uses a fake message — email, text, voice call, social media DM — to trick you into giving up something valuable: a password, a credit-card number, money, access to your computer. Phishing has gotten dramatically more sophisticated. The bad grammar and obvious mismatched logos are mostly gone; modern phishing messages look almost identical to real ones from real companies. The defense isn’t spotting the bad grammar — it’s understanding the patterns and having simple rules you follow regardless of how convincing a message looks.

The Common Patterns

  • Urgency — “Your account will be closed in 24 hours.” “Suspicious activity detected.” “Final notice.” Real companies almost never operate on these timelines
  • Authority + threat — impersonating a bank, the IRS, Medicare, the Social Security Administration, or law enforcement, combined with a threat (arrest, account closure, benefits cut off)
  • Click this link — nearly every phishing attempt has a link that, when clicked, takes you to a fake login page
  • Unusual payment method — gift cards, wire transfers, cryptocurrency, payment apps to strangers. Legitimate organizations never request these
  • Account verification — “We need to verify your account. Please confirm your password and Social Security number.” No legitimate institution does this via email or text
  • Too good to be true — refunds, prizes, inheritances, settlement money you didn’t expect
Six red flags of a phishing message

By Channel

Email phishing

  • Sender display name says “Bank of America” but the actual email address is something weird (`boa-security@mail-secure.tk`)
  • Hovering over a link shows a URL that doesn’t match the claimed sender
  • Generic greeting (“Dear Customer”) instead of your name
  • Includes a logo and formatting that looks real but the message is asking you to log in, confirm, or click

Text message phishing (“smishing”)

  • Delivery notification scams (“USPS package on hold — pay $1.99 redelivery fee”)
  • Bank account “alert” with a link to verify
  • Tax refund or unemployment-benefit “deposit” message
  • Random text starting a conversation (“Hi, is this still your number?”) — the front end of a longer scam, often crypto or romance

Voice phishing (“vishing”)

  • Caller ID can be spoofed to display ANY name or number, including your own bank’s real customer-service number. Never trust caller ID alone
  • Common scripts: “This is the IRS calling about your back taxes,” “This is Microsoft calling about a virus on your computer,” “This is your bank’s fraud department”
  • Common ask: confirm your account number, give a one-time code, install remote-access software, buy gift cards

Social media and DM phishing

  • Friend requests from people you don’t know, often with stolen profile photos
  • DMs claiming to be from a celebrity, brand, or platform support team
  • “You won a giveaway! Click here to claim”
  • Compromised accounts of real friends suddenly asking for money or sharing investment opportunities

Simple Rules That Stop Most Phishing

  1. If a message is unexpected, treat it as suspicious. Doesn’t matter how official it looks
  2. Don’t click links in messages. If the message claims to be from your bank, log in to your bank’s site directly (typed URL or bookmark), not via the link
  3. Verify by calling back — using a number YOU look up. Not the number in the message. Your bank’s real number is on the back of your card; the IRS’s is on irs.gov
  4. No legitimate organization will ask for gift cards, wire transfers to strangers, or cryptocurrency. If they do, it’s a scam, full stop
  5. Turn on two-factor authentication on your important accounts (email, bank, brokerage, Social Security). Use an authenticator app (not SMS) when possible
  6. Set up account alerts for withdrawals, logins, and password changes on financial accounts
  7. Never give a one-time verification code over the phone — these are NEVER requested by legitimate institutions
  8. Take 10 seconds before acting on urgency. Scammers manufacture pressure precisely to bypass careful thinking. If a message is real, a 10-minute pause to verify won’t cause harm

If You Clicked a Suspicious Link

  • If you entered a password, change it immediately on the real site, and on any other site where you used the same password
  • If you entered a credit card or bank info, contact the institution’s fraud department
  • If you downloaded a file or installed software, run a malware scan; if you can’t, take the device to a reputable repair shop
  • If you gave Social Security info, freeze your credit (see How to Freeze Your Credit) and review your IRS account at irs.gov
  • Watch your financial accounts closely for the next 30-60 days for unauthorized activity

Educational only. Scam tactics evolve constantly. If you believe you’ve been targeted or have lost money, report to: the Federal Trade Commission at reportfraud.ftc.gov, your state attorney general, your local police, and (for elder financial abuse) Adult Protective Services via eldercare.acl.gov or 1-800-677-1116. For lost funds, contact your bank and credit-card issuers immediately. This article is not a substitute for legal or financial advice.


Further Reading