Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Phishing is a scam in which someone impersonates a person or organization you trust to trick you into sharing information, clicking a harmful link, opening an attachment, or sending money. It can arrive by email, text, phone call, or a fake website. The safest response to an unexpected request is to pause and verify it through a contact method you already know is genuine—not through the message itself.

What phishing is—and where it happens

The Federal Trade Commission (FTC) explains: “Scammers use email or text messages to trick you into giving them your personal and financial information.” Phishing is a form of social engineering: the sender uses impersonation or persuasion to get you to take an action that benefits them. The goal may be account credentials, financial details, a payment, or access to your device or workplace.

Phishing is not limited to email. The Cybersecurity and Infrastructure Security Agency (CISA) describes attempts through email or malicious websites and identifies several forms:

  • Email phishing: a message impersonates a company, service, or person.
  • Smishing: a phishing attempt sent by text message.
  • Vishing: a phishing attempt made by voice, such as a phone call.
  • Spearphishing: a message tailored to a particular person or organization.
  • Whaling: a targeted attempt aimed at a senior executive or other high-profile target.

A convincing logo, familiar name, or polished writing does not prove that a message is genuine. Likewise, a typo is a possible warning sign, not a reliable test: sophisticated scams may look professional.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to spot a possible phishing attempt

Look at the request and the circumstances together. Common lures include an alert about suspicious account activity, a payment or account problem, an unfamiliar invoice, a refund or prize, or a request to confirm personal or financial details. Scammers may add urgency and push you to click a link, open an attachment, or act before you can check the story.

  • Unexpected urgency: the message threatens account closure, claims a payment failed, or says you must act immediately.
  • A request for sensitive details or money: be cautious of unexpected requests for passwords, financial information, gift cards, transfers, or payment.
  • A link that does not fit: the visible text may differ from the destination, or the address may imitate a familiar organization. Do not click to find out.
  • An unusual sender or greeting: a suspicious sender address, generic greeting, or unexpected request from someone you know can be a clue.
  • An unexpected attachment: an invoice, document, or delivery notice you were not expecting may be used to prompt a download.

These are warning signs, not a checklist that can prove a message is fake or safe. A genuine-looking message can be fraudulent, and a legitimate message can be poorly written. The FTC suggests asking whether you have an account with the company named or know the person who contacted you. Even if you do, that does not authenticate the message. Verify separately before acting.

What to do when a message seems suspicious

  1. Stop before interacting. Do not click unexpected links, download attachments, reply with sensitive information, or call a phone number included in the message.
  2. Verify through a separate, trusted route. Type the organization’s known web address yourself, or use a phone number from a trusted record you already have. If the message appears to come from a friend or colleague, confirm through a separate conversation.
  3. Report the attempt. In the United States, forward phishing email to reportphishing@apwg.org. Forward phishing texts to SPAM (7726). You can also report the attempt to the FTC at ReportFraud.ftc.gov.
  4. Delete the message after reporting it. Do not keep interacting with it or use its contact details.

The FTC reported in April 2025 that email was the top method scammers used to contact people in 2024. That alert gives a ranking, not a percentage, so it does not establish what share of scam contacts came by email.

If you clicked, opened an attachment, or shared information

Choose your next steps based on what happened. A click alone is different from entering a password or sending money, but if you suspect a download or account exposure, act promptly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • If you shared Social Security information, bank details, or card information: use IdentityTheft.gov for recovery steps matched to the information exposed.
  • If you entered an account password: go to the real service through a known address or app, change the password, and review the account. If you reused that password elsewhere, change it on those accounts too.
  • If you clicked or opened a file and suspect harmful software: update your security software and run a scan. Avoid using the suspicious message’s links or prompts to download a “fix.”
  • If you sent money or payment information: contact your financial institution using a number or app you already trust and explain what happened.

How to reduce the risk of phishing damage

Protective measures work in layers. They can make account takeover or device compromise harder, but they do not authenticate every message or replace independent verification.

Layer Useful measures What it helps with
Message handling Pause; avoid unexpected links and attachments; verify through a known website or contact method. Reduces the chance of acting on an impersonation.
Account protection Use strong, unique passwords, a password manager, and multi-factor authentication (MFA). MFA can make account access harder for someone who has only your username and password.
Device protection Install automatic security-software and device updates; run a security scan if a download may be harmful. Helps keep protections current and supports a response to suspected malware.
Recovery readiness Back up important data and know how to report a suspected scam or exposed information. Helps you respond if a device or account is affected.

CISA recommends strong passwords, password managers, and MFA. A physical FIDO2 security key is one possible MFA factor, but check that the particular account supports the key. A security key helps protect account access; it is not a phishing-message detector. The FTC also recommends updates, MFA, and backups.

For small businesses: verify high-impact requests

For a business, a convincing impersonation can target payments or sensitive data. The FTC recommends calling back using a known number to validate payment or data requests, setting internal verification policies for wire transfers, training employees, maintaining backups, and giving customers and staff a clear way to report suspected spoofing. A number or callback instruction supplied in the suspicious message is not an independent verification channel.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

U.S. reporting and recovery resources

The reporting routes and identity-recovery guidance below are U.S.-specific. Readers elsewhere should use the relevant reporting and recovery services in their country.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.