Skip to main content

Technology & Cyber · Fraud Guide

Phishing

Also known as: Email Scam, Smishing, Vishing, Text Scam
HIGH
Severity
$500–$10,000
Typical Loss
8,635
Articles in Archive
Who is targeted: Everyone, but older adults are particularly vulnerable to phishing attacks that impersonate banks, Medicare, the SSA, or online retailers.
Phishing is the most common initial attack vector. It is often the entry point for other fraud types — a phishing email may lead to identity theft, account takeover, or a tech support scam.
Phase 1 · Awareness

A fake email, text, or message tricks you into giving up passwords or personal information.

▼

Phishing is the art of impersonation at scale. Scammers send emails, text messages, or social media messages that look like they're from a trusted source — your bank, Amazon, the IRS, Medicare, a deli...

Key signs: ⚠ The email creates urgency or fear — 'Act now or your account will be closed.' ⚠ The sender's email address doesn't quite match the real organization (e.g., [email protected]). ⚠ Links in the message go to URLs that don't match the legitimate site.
Phishing is the art of impersonation at scale. Scammers send emails, text messages, or social media messages that look like they're from a trusted source — your bank, Amazon, the IRS, Medicare, a delivery company. The message creates urgency: your account is locked, a package can't be delivered, suspicious activity was detected. It includes a link to a fake website that captures your login credentials, personal information, or financial data.

How It Works

1 The victim receives an email, text, or message that appears to be from a legitimate organization.
2 The message contains urgent language: 'Your account has been compromised,' 'Action required,' 'Verify your information immediately.'
3 A link leads to a website that looks identical to the real organization's site.
4 The victim enters their login credentials, personal information, or financial details on the fake site.
5 The scammer now has access to the victim's real accounts, or has enough personal information to commit identity theft.
6 In 'smishing' variants, the attack comes via text message. In 'vishing,' it's a phone call.

All Warning Signs

⚠ The email creates urgency or fear — 'Act now or your account will be closed.'
⚠ The sender's email address doesn't quite match the real organization (e.g., [email protected]).
⚠ Links in the message go to URLs that don't match the legitimate site.
⚠ The message contains grammatical errors or awkward phrasing.
⚠ You're asked to 'verify' or 'confirm' personal information via a link.
⚠ You weren't expecting the communication.
Phase 2 · Prevention

Defending against phishing attacks.

▼
Never click links in unexpected emails or texts. If you receive a message about your bank account, go directly to your bank's website by typing the URL yourself. Do not use the link in the message.
Check the sender's actual email address. Look beyond the display name. The actual email address often reveals the fraud: 'Chase Bank <[email protected]>' is not from Chase.
Enable two-factor authentication on all important accounts. Even if a scammer captures your password through phishing, two-factor authentication (2FA) adds a second barrier. Use an authenticator app rather than SMS when possible.
Never click links in unexpected emails or texts.
If you receive a message about your bank account, go directly to your bank's website by typing the URL yourself. Do not use the link in the message.
Check the sender's actual email address.
Look beyond the display name. The actual email address often reveals the fraud: 'Chase Bank <[email protected]>' is not from Chase.
Enable two-factor authentication on all important accounts.
Even if a scammer captures your password through phishing, two-factor authentication (2FA) adds a second barrier. Use an authenticator app rather than SMS when possible.
Keep software updated.
Updated browsers and email clients are better at detecting and blocking phishing attempts.
Phase 3 · Detection

Recognizing that you may have fallen for a phishing attack.

▼
Watch for: 🔍 You clicked a link in an email and entered your login credentials on a page that now seems suspicious. 🔍 You're receiving unexpected password reset emails or security alerts from legitimate services. 🔍 You notice unauthorized activity on financial or email accounts.
Immediate action: → Change the compromised password immediately — from a different device if possible.

All Warning Signals

🔍 You clicked a link in an email and entered your login credentials on a page that now seems suspicious.
🔍 You're receiving unexpected password reset emails or security alerts from legitimate services.
🔍 You notice unauthorized activity on financial or email accounts.
🔍 You've received confirmation for purchases or account changes you didn't make.

What To Do Right Now

→ Change the compromised password immediately — from a different device if possible.
→ Enable two-factor authentication on the affected account.
→ Check your email's 'sent' folder for messages you didn't send.
→ Review financial accounts for unauthorized transactions.
→ Run a virus scan on your device.
Phase 4 · Recovery

Recovering from a phishing attack.

▼
First steps: → Contact your bank immediately if financial information was compromised. → Change passwords on all accounts that used the same or similar password. → Place fraud alerts on your credit reports if personal information was stolen.

Financial Recovery

→ Contact your bank immediately if financial information was compromised.
→ Change passwords on all accounts that used the same or similar password.
→ Place fraud alerts on your credit reports if personal information was stolen.
→ Report to the FTC at ReportFraud.ftc.gov.
→ Report phishing emails by forwarding them to [email protected].
→ If tax information was compromised, contact the IRS Identity Protection unit.
→ Step-by-step help by how you paid, and where to report: If you were scammed

Emotional Recovery

Phishing attacks are designed by professionals to fool people. Even cybersecurity experts have been tricked.
The experience can be a useful catalyst for strengthening your digital security overall.

From the Archive

8,635 articles about phishing

Browse all articles →  ·  Search within this category →

crypto.news · 2026-10-03
Greek police arrested 17 people, including nine military personnel, for operating a cryptocurrency investment pyramid scheme that defrauded at least 10,000 participants of over $8 million since 2025. The operation used fake online platforms across multiple Greek cities to promise guaranteed high returns and double investments within 50 days, while failing to return deposited funds. Police seized €295,090 in cash along with computers and mobile devices during raids on five offices.
japantoday.com · 2026-10-03
A woman in her 60s in Aichi Prefecture, Japan, lost approximately ¥178 million (about $1.2 million USD) in a romance scam involving cryptocurrency between July and September. A man she met on social media built a romantic relationship with her starting in May, then convinced her to invest in crypto assets across 27 transactions by initially showing false returns on small deposits. The scammer has not been recovered, and police have confirmed the victim will likely never retrieve her money.
news.rthk.hk · 2026-10-03
Hong Kong police warned of new scamming tactics where fraudsters impersonate customer service agents, with approximately 5,000 cases reported between January and August 2026 accounting for 17% of all fraud during that period. Two primary methods were identified: one involving malware and NFC technology to remotely use victims' credit cards, and another using fake verification codes to authorize unauthorized bank transfers. In August alone, 1,680 impersonation cases resulted in over HK$220 million in losses, with nearly half of victims aged 31-50.
washco-md.net · 2026-10-03
Washington County, Maryland is warning residents and businesses of a phishing scam using fraudulent emails that falsely appear to be from the Planning & Zoning Department, requesting wire transfer payments for fake "Application Review and Approval Fees." The county clarified it does not request permit payments via email or wire transfer, and advised recipients not to respond or send money, while urging anyone who already paid to contact their bank and law enforcement immediately.
komonews.com · 2026-10-03
MyChart patient portals have experienced an uptick in phishing scams targeting approximately 190 million worldwide users, with fraudsters sending deceptive emails that direct patients to fake login pages to steal personal information and expose computers to malware. To combat this threat, LexisNexis Risk Solutions introduced Identity Proofing for MyChart, which uses additional security checks like one-time passwords and biometric verification, while advising patients to verify sender email addresses, avoid clicking suspicious links, and log into portals directly rather than through emails. Experts warn that compromised MyChart credentials combined with other stolen personal data can enable criminals to build fraudulent profiles and commit identity theft, including opening credit cards in victims' names
gbcode.rthk.hk · 2026-10-03
Hong Kong police warned of two new scam tactics used by fraudsters posing as customer service agents: one involving malware that enables remote credit card payments via NFC technology, and another using fake bank verification processes to authorize unauthorized transfers. Between January and August, approximately 5,000 impersonation scams were reported, with August alone seeing 1,680 cases resulting in over HK$220 million in losses, accounting for 17 percent of all fraud during the period. Police emphasized that while victims span all age groups, nearly half are aged 31 to 50, and urged residents to remain vigilant against these evolving scam methods.
aol.com · 2026-10-02
This article is a product review comparing identity theft protection services rather than reporting on actual fraud incidents. It does not contain information about specific scams, victims, or dollar amounts lost to fraud—instead, it lists seven identity theft protection services with their features, coverage limits, and pricing tiers designed to help consumers prevent identity theft and fraud.
sports.khan.co.kr · 2026-10-02
Romance scams targeting elderly individuals in South Korea are increasingly sophisticated, with international crime syndicates posing as romantic interests on social media to extract money from lonely seniors. Cases documented include a woman in her seventies who was nearly convinced to send $18,750 to a supposed boyfriend in Ukraine for shipping fees, and a man who remitted approximately $30,000 over five years to a woman claiming to be in a Nigerian refugee camp. Experts note that approximately 70.8% of people over 60 experience loneliness, making them vulnerable to scammers who exploit emotional vulnerability through fabricated romantic relationships.
straitstimes.com · 2026-10-02
Since July 2026, at least 246 people in Singapore have lost $1.4 million to phishing scams involving fraudulent social media advertisements offering cheap products. Victims were redirected to fake websites where they entered payment card details, banking credentials, and authorization codes, only discovering the fraud after unauthorized transactions appeared on their accounts. Police have noted a surge in these cases and recommend the public use security features, verify website authenticity, and report suspected scams to authorities.
straitstimes.com · 2026-10-02
Singapore's government technology unit OGP launched "Scam Vaccine," an AI-powered program that exposes residents to realistic simulated scams via phone calls and WhatsApp messages to build resistance to fraud tactics before encountering actual scams. The simulations replicate common scam types including government impersonation, e-commerce, investment, and romance scams, with over 700 residents signing up since the program opened in September 2026. Participants receive personalized debriefs identifying red flags they missed, with built-in safety features ensuring no financial loss or data exposure.
See all 8,635 articles →
← Back to Fraud Library
This site uses Atkinson Hyperlegible Next, a typeface designed by the Braille Institute for readers with low vision. Learn more