What is Phishing? How to Spot Phishing Emails, Texts & Calls
Fraudulent emails (phishing), texts (smishing), and phone calls (vishing) that appear to be from legitimate sources, designed to steal login credentials or personal information.
Why this scam works
Phishing is cheap to send at massive scale and only needs a tiny success rate to be profitable. Modern kits proxy real login pages so even 2FA codes can be stolen in real time.
What's happening now
- Phishing remained the #1 reported cybercrime by volume at the FBI IC3 in 2023, with nearly 300,000 complaints (FBI IC3 2023).
- Smishing volume (text-message scams) more than doubled in the US between 2021 and 2023 (FCC Consumer Help Center, FTC).
- Adversary-in-the-middle phishing kits (Evilginx, Tycoon) that bypass SMS and app-based 2FA are now sold as a service (CISA advisory).
Warning signs
- Urgency: 'verify in 24 hours or your account is closed.'
- Generic greeting ('Dear customer') from a company that knows your name.
- Sender domain is a near-look-alike: amaz0n-support.com, apple-id.help.
- Link hover preview doesn't match the supposed brand.
- Request for password, full SSN, or 2FA code by message.
- Texts about a package, toll, or delivery you don't remember.
How the scam plays out
Bank email
"'Your account is locked. Verify your identity at the link below to restore access.'"
Toll smishing
"'You have an unpaid toll of $6.99. Pay now to avoid a $50 fine: pay-tolls-now.com'"
Vishing
"'This is your bank's fraud team. We see a charge in another state — confirm your card number to cancel it.'"
What to do
- Never click links in unexpected messages — go to the company's site or app yourself.
- Use a password manager: it will refuse to autofill on a look-alike domain.
- Turn on app-based 2FA or passkeys; avoid SMS-only 2FA where possible.
- Forward suspicious texts to 7726 (SPAM) and report phishing emails to your provider.
If it already happened
- Change the password of any account whose credentials may have been entered.
- Sign out all sessions and review connected apps and email forwarding rules.
- If financial info was shared: alert your bank, freeze the card, and freeze your credit.
- Report the message to the FTC and IC3.
Train continuously — free
Sign up to track progress across every module, earn points, and get alerts when a new scam pattern matches messages you've been getting. Teams can roll the modules out as employee security awareness training.
Sources
Keep learning
Imposter Scams: How to Spot Fake IRS, Bank & Family Calls
Scammers pose as trusted figures — family members in trouble, IRS or police officers, Social Security, Medicare, or your own bank — to demand immediate payment or sensitive data.
ReadDeepfake Scams: How to Spot AI Video Call Fraud
Real-time face-swap and voice-clone filters let scammers impersonate executives, family members, romantic partners, or job candidates on Zoom, Teams, FaceTime, and WhatsApp video calls.
ReadTech Support Scams: How to Spot Fake Microsoft & Apple Pop-ups
Fraudsters claim your computer has a virus, your account has been hacked, or your refund went wrong, and demand payment or remote access to 'fix' it.
Read