Phishing messages try to persuade you to reveal information, send money, download a file, or approve an account action. They can arrive by email, text, messaging apps, phone calls, or social media. Some are poorly written; others copy a real organization's style. Treat unexpected urgency as a reason to verify, not proof a message is genuine.
Focus on the request
Requests to confirm a password, share a one-time code, buy gift cards, approve a login, install remote-access software, or pay an unusual invoice deserve careful checking. Legitimate organizations generally do not need you to send a password or authentication code in a reply.
Attackers can copy logos, names, and signatures. Check the full sender address, but remember that addresses can be spoofed or a real account compromised. The request and independent verification matter too.
Verify without using the message link
Warnings about account closure, missed deliveries, penalties, or a manager's emergency may pressure you to act. Open the official app or type the organization's known address yourself instead of clicking. Contact a coworker, bank, or family member through a number or channel you already trust—not contact details supplied in the suspicious message.
Hovering over a link can reveal its destination, but does not guarantee safety. On a phone, previews may be inconsistent. If a domain is unfamiliar, misspelled, or adds words before the real domain, do not sign in through it.
Handle attachments and QR codes cautiously
Confirm unexpected invoices or documents through another channel before opening. Be especially cautious if a file asks you to enable macros, install software, or enter credentials. QR codes can lead to fake sign-in pages just like ordinary links; inspect the destination before continuing.
Protect accounts
- Use unique passwords stored in a password manager.
- Enable multi-factor authentication or passkeys where offered; never share one-time codes.
- Keep your phone, computer, browser, and security software updated through official settings.
- Turn on account alerts for sign-ins and payment or recovery-setting changes.
- Limit personal details posted publicly, which scammers may use to sound convincing.
If you already clicked or shared information
If you entered a password, visit the real service directly and change it immediately, including anywhere else it was reused. Revoke suspicious sessions or connected apps if available and enable multi-factor authentication. If you shared banking details, contact the provider through its official number. If you installed a file or remote-access tool, stop using affected accounts and seek help from a trusted technician or your organization's IT team.
Report the message using the platform's phishing option. Do not forward active links or attachments to others. A simple pause before sensitive actions—then verification through a separate trusted channel—can prevent many avoidable mistakes.
