Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A phishing message can include your real name, address, employer, a recent purchase, or the name of a company involved in a breach—and still be a scam. Personal details make a message more convincing; they do not authenticate the sender. Don’t use its links, QR code, attachments, or phone number. Check the request through the organization’s official app, website, or phone number found independently.

Why a phishing message may know personal details

After a data breach—unauthorized access to information held by an organization—criminals may use exposed details to tailor emails, texts, or calls. They might impersonate the affected organization or exploit news of a breach with a fake request to “verify” an account or address supposed fraud. A fraudulent site can imitate a real one and capture whatever you enter; some messages instead try to deliver malware.

Personalization does not establish that a breach exposed your information. Details may also be available from public sources, including social media. The UK National Cyber Security Centre (NCSC) explains: “Criminals use information about you that’s available online (including on social media sites) to make their phishing messages more convincing.” Its data-breach guidance, published November 26, 2021, and reviewed September 5, 2022, describes how stolen information can support convincing scams: NCSC guidance on data breaches.

How to assess a suspicious message

Focus on what the message wants you to do, not just how it looks. The NCSC lists urgency, threats, claims of authority, emotional pressure, and offers that create excitement or scarcity among common warning signs. Unexpected requests for passwords, banking or identity details, one-time codes, payment, or a sign-in deserve particular caution. Links, attachments, QR codes, and phone numbers supplied in a message can all be part of the scam. See the NCSC’s guidance on suspicious emails and messages.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Check the context: Did you expect this contact, and do you have an account with the named organization or know the person who supposedly contacted you? The FTC suggests asking, “Do I have an account with the company or know the person who contacted me?” A “yes” is a useful initial check, not proof of identity.
  • Notice pressure and sensitive requests: Treat demands to act immediately, threats of a penalty, or requests for credentials, financial information, identity details, or a one-time code as unverified until you check independently.
  • Don’t trust polish as proof: Spelling mistakes can be a clue, but they are not required. Correct writing, a familiar logo, and accurate personal information cannot establish that the message is genuine.
  • Break the message’s route to action: Don’t click or scan, open an attachment, reply, sign in through its link, or call a number it supplies to verify the request.

How to verify the sender safely

Start a fresh route to the organization instead of following the message’s path. The distinction is whether your contact details came from a source independent of the message.

  1. Open the organization’s app that you already use, or type its established web address yourself.
  2. If you need to call, use a number on a bank card or statement, or locate the organization’s official contact page independently. Don’t use a number from the suspicious message.
  3. Check whether the organization confirms the specific request or alert. If it cannot confirm it, treat the message as suspicious and do not provide information or payment through it.

An official app, established website, or independently found phone number is a safer verification route than any link or contact detail embedded in the message. The FTC’s guidance also advises checking whether you have an account with the company or know the person who contacted you; that check can help assess context but cannot authenticate the sender. FTC guidance on recognizing and avoiding phishing scams.

Rank #2
FEITIAN K9 USB A NFC - Two Factor Authenticator (2FA) - Multi-Factor Authentication (MFA) - Device Security Key + FIDO2 - Achieve Advanced Account Protection
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Secured by NXP semiconductors
  • Works in every browser and application without installing any drivers
  • Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

What to do if you haven’t interacted

  1. Do not click, scan, open, reply, or call using details in the message.
  2. Report it using your email or mobile service’s built-in reporting feature, then delete it.
  3. Use the relevant national reporting route if appropriate. In the UK, the NCSC asks users to forward suspicious emails to report@phishing.gov.uk; you can report an email even if you are unsure. Its reporting page lists 454.8k scam URLs removed as of July 2026. That is a cumulative operational figure, not a count of phishing messages or victims, and not a measure of your personal risk. NCSC reporting guidance.
  4. In the United States, the FTC recommends forwarding phishing texts to 7726 and reporting them at ReportFraud.ftc.gov. Its email guidance also lists the Anti-Phishing Working Group. Reporting routes differ by country; check your local official guidance.

What to do if you clicked, replied, or shared information

The next step depends on what happened. Use the organization’s official recovery route rather than any follow-up link in the suspicious message.

If you shared bank or payment details

Contact your bank promptly through its official app or a known phone number, such as the number on your card or statement. Follow its instructions for securing the account or payment method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FEITIAN K40 USB Security Key - Two Factor Authenticator - USB-C with NFC, FIDO2 - Help Prevent Account Takeovers
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
  • Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
  • Durable design made to last for a long time with everyday use. Water-resistant (IP67)
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

If you shared a password or one-time code

Change the exposed password through the service’s official website or app. If you reused it on other accounts, change it there too, choosing a unique password for each. Follow the service’s official account-recovery guidance if you cannot sign in or suspect someone has taken control. A one-time code can enable immediate access, so contact the affected service through a known route if you disclosed one.

If you opened a suspicious file or installed software

Use your device’s security tools and seek trusted technical support as appropriate. Avoid entering more passwords or sensitive information on a device you suspect may be compromised until you have addressed the issue.

Rank #4
Thales - SafeNet eToken FIDO - FIDO2 Certified Security Key - Passwordless Phishing-Resistant Authentication for Web Apps, Devices & Desktops - USB-C - Pack of 1
  • FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

If identity or financial information was exposed in the United States

The FTC directs people to IdentityTheft.gov for tailored identity-theft recovery steps. Other countries have different official recovery services.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reduce the risk if credentials were exposed

Unique passwords help prevent one exposed password from unlocking other accounts. A password manager can help create and store distinct passwords. Multi-factor authentication (MFA) adds a further sign-in check, but the available methods and account-recovery options vary by service. These protections reduce downstream account risk; they do not tell you whether a message is genuine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Swissbit iShield Key 2 FIDO2 USB-C Security Key with NFC – FIDO Certified, Passwordless Authentication, Passkey & U2F, Phishing-Resistant Security for Enterprise
  • SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
  • PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
  • COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
  • DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
  • USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.

Where an account supports it, prefer phishing-resistant sign-in such as FIDO-based authentication. CISA’s December 18, 2024 mobile communications guidance recommends hardware-based FIDO security keys where feasible and describes passkeys as an acceptable alternative. A key is a physical device that can authenticate to compatible accounts; compatibility and recovery arrangements depend on each service. Neither a key nor a passkey prevents every form of phishing or verifies a message’s sender. CISA mobile communications best-practice guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.