Phishing is the internet's oldest con: a message pretending to be someone you trust, aiming to get your password, your money, or a foothold in your accounts. It works because it's designed to skip the part of your brain that checks. Here's how to slow it down.
Six Red Flags of a Phishing Email
The sender looks almost right
Scammers spoof familiar names — 'PayPaI' with a capital i, 'support@amaz0n-billing.com'. Hover the address; check the domain character-by-character.
Urgency and threats
'Your account will be suspended in 24 hours.' 'Unusual sign-in — verify now.' Real companies rarely rush you. Panic is the whole play.
A link that doesn't match the story
The email says 'bank' — but the link goes to a random subdomain, a shortened URL, or an IP address. Hover before clicking. On mobile, long-press to preview.
Attachments you didn't ask for
Invoices, shipping notices, resumes, .zip files. If you weren't expecting it, don't open it — especially Office docs asking you to 'Enable Content'.
Requests for credentials, codes, or gift cards
No legitimate company will ever ask for your password, your 2FA code, or payment in gift cards. Ever. This is 100% of the time a scam.
Off-brand writing
Odd grammar, generic greetings ('Dear Customer'), or a tone that just feels wrong. Trust the itch.
If You Think You've Been Phished
- Change your password for the affected account — and any other account using the same one.
- Turn on two-factor authentication if it isn't already. An authenticator app beats SMS.
- Check recent activity — logins, forwarding rules, connected apps. Scammers love inbox rules that quietly hide their tracks.
- Tell your bank if any financial info was shared. Fraud teams move faster than you'd think.
- Warn anyone who might get the follow-up. Compromised accounts get used to phish contacts.
Where to Report Phishing
- · Email: forward to reportphishing@apwg.org and to your email provider's abuse address.
- · Text messages: forward the message to 7726 (SPAM) in the US and most carriers.
- · Federal Trade Commission (US): reportfraud.ftc.gov.
- · The impersonated company: most have a security@ or abuse@ address.
Saw a scam in the wild?
If you've spotted a phishing site, a scam account, or a grifter running the same con on real people — send it to us. We read every tip. Screenshots welcome. Anonymous is fine.
→ File a Tip